Quantitative cyber-risk analysis
Idraa turns expert judgment into loss distributions — so security leaders can budget, prioritize, and defend decisions in dollars, not colors.
Illustrative scenario. Control-driven reduction is modeled with explicit uncertainty — a range, not a precise figure.
The problem
Risk registers rank threats red, amber, green. The colors feel precise — but they don’t add up, don’t compare, and can’t answer the one question a board asks: how much could this cost us, and is it worth fixing?
Subjective. Non-additive. Un-budgetable. Two people rarely mean the same thing by “High.”
In dollars. Comparable across scenarios. You can put a budget — and an ROI — behind it.
You can’t put a budget behind a color.
The method — Open FAIR
You estimate each factor as a range, not a point — a 5th/95th percentile you’re comfortable defending. Uncertainty is modeled, not hidden.
The FAIR math composes frequency and magnitude into a single distribution of annual loss. Nothing is invented in the app layer.
Every metric Idraa shows maps back to a named FAIR node — so any number in a report is traceable to its source.
The engine — Monte Carlo
Each point answers: what’s the chance annual loss exceeds this dollar amount? Read down for the tail, across for the odds.
Annualized loss expectancy (ALE) — the number you carry into the budget.
1-in-20-year loss — the bad-year figure that sizes your reserves and cyber-insurance limits.
The shaded gap is the modeled reduction from a proposed control — estimated with explicit uncertainty, and the basis for comparing control ROI.
The workflow
A guided path a security team can actually run — no statistics degree required.
Define what could go wrong — threat, asset, method, effect. Start from the curated library or author your own.
Capture expert ranges through a guided wizard — calibrated, inherent (pre-control), and pooled across multiple estimators.
Run Monte-Carlo trials — up to 100K for standard scenarios, up to 1M for catastrophic tails — to build the full loss distribution.
Read the curve against your appetite, and rank control investments by the dollars of risk each one removes.
The platform
Model how controls reduce frequency and magnitude — each control's contribution shown as a range, with its uncertainty made explicit (FAIR-CAM).
Begin from calibrated, sector-tiered scenarios cross-walked to MITRE ATT&CK techniques.
Combine disagreeing estimates without averaging away the disagreement — a true opinion pool, not a blurred mean.
A purpose-built Monte-Carlo engine that keeps the full distribution — VaR, expected shortfall, exceedance. Trial caps scale with deployment (100K standard, 1M catastrophic).
Re-derive the engine's per-scenario sampling and ALE in an Excel workbook that mirrors the math — auditable line by line. Tail metrics (VaR, expected shortfall) stay engine-computed, not reproduced in the sheet.
A posture dashboard with a risk-vs-appetite verdict, control budget, and PDF / Excel exports.
Idraa turns FAIR analysis into decisions your board can act on — one scenario at a time.