Skip to content

Capability

Cyber Risk Quantification Software

Compare cyber investments by modeled annual loss, action cost, and budget. Inspect the evidence, missing inputs, and assumptions behind each recommendation.

Prepared by ValtyUpdated

Evaluate with a real question

What to look for in cyber risk quantification software.

Ask the vendor to carry one funding decision from evidence to a comparison, then show how approval and subsequent verification are recorded. In Valty’s supported evaluation, agree the company and available capabilities before using your own data.

Inspectable inputs

See which values are observed, prior-backed, or missing. Ask to inspect a source date, a coverage limitation, and the effect of a disputed assumption. Review the input checklist before connecting systems.

Comparable choices

Compare no optional action, required work, and priced alternatives under one budget and one loss objective. Check whether an option changes when the objective moves from mean annual loss to P95.

Governed follow-through

Inspect the approval owner, authorized scope, supported execution path, exceptions, and required verification. Confirm the exact integration and workflow in scope; a completed task is not proof of effective remediation.

A reviewable output

Ask for the assumptions, model version, loss units, alternatives, unresolved gaps, and next review. Use the board report template to assess whether the output supports an actual decision.

Valty is offered in a design-partner evaluation. Authentic application captures demonstrate individual interfaces with illustrative data; the synthetic decision memo is a separate, reproducible example. Neither is permissioned customer-outcome evidence or a guarantee of loss reduction.

Design partner

Carry the funding decision into approved work.

Review the proposed action, the person who can authorize it, and the evidence required to verify the result. Funding, execution status, and demonstrated risk reduction remain distinct.

Where the boundary sits

Modeled reduction is not observed savings or a guarantee. Exact metrics, integrations, uncertainty treatment, and execution capabilities depend on the agreed evaluation scope and available product configuration. The sample is not independently calibrated customer evidence.

Best next step for PE operating partner, CFO, board: choose “Request a platform demo” to review the workflow, evidence boundary, and fit for your environment.

Governed actions workspace product surface
Governed actions workspaceActual Valty application · illustrative data. Authorization, execution status, and items awaiting review are distinct. This capture does not establish a completed customer remediation.Open full-size product view ↗

Fictional worked example

Inspect the assumptions behind one funding decision.

This excerpt of the sample memo shows one fictional company's annual gross-loss distribution. Its mean, median, and P95 describe different modeled outcomes; they do not establish confidence in the input assumptions.

Fictional sample · 2026-09-05

Example Manufacturing Co.

Annual gross loss · baseline
$3,512,449

P95 annual loss · no insurance recovery modeled

Baseline from the fictional sample memo. Synthetic assumptions, separate from the actual application captures and not a customer forecast.

Mean $791,066P50 $124,681P95 $3,512,449

About 5% of modeled years exceed P95. It is an outcome percentile, not a worst case or a confidence interval. These synthetic inputs have not been externally calibrated.

Read the sample decision memo · Review the method

Fictional baseline assumptions

Reproduce the estimate.

Annual event frequency
0.8 events/year
Mean loss per event
$1,000,000
Loss variability
1.2 log-scale standard deviation
Simulation
50,000 modeled years

These are synthetic inputs, not measured company data. Changing frequency or severity changes the loss distribution and can change which investment is preferred.

Inspect the full assumptions and alternatives →

Inspectable CRQ

See what is measured, what is prior, and why the dollar moved.

Every entitled figure exposes its evidence mix, the next source that can tighten it, and the exact model snapshot behind the output. Reviewers can challenge a node instead of accepting a black-box score.

Coverage

Measured / prior / missing stays visible

The coverage meter names the evidence mix and the next connector that would replace a missing or prior-backed node.

Challenge

Pin a formula node and see the dollar delta

Every formula-tree node is labeled. Pinning a measured node to prior updates the displayed dollar and records a provenance row.

Replay

Recompute a published p95 from its snapshot

The evidence snapshot and model version replay the printed figure without requiring a live connector.

Sufficiency

Thin data widens the band and creates an uplift plan

Low input sufficiency changes the uncertainty treatment and ranks the next source to connect instead of hiding the gap.

Illustrative coverage mix

33% measured · 33% prior · 34% missing
Coverage gated

MFA enforcement

Okta API

Measured

EDR response time

Connect EDR

Prior

Cloud path state

Connect CSPM

Missing

Next evidence move: connect the source attached to the highest-impact missing node.

Availability

Design-partner workflow. Access, connected evidence, and the recorded model version determine what can be reviewed. Dollar outputs remain decision-support estimates.

Inspect the public method

One company. One funding question.

See the decision workflow in a platform demo.

In 30 minutes, review the loss model, compare funding choices, and inspect the approval and evidence trail using illustrative data. Agree your company scope, supported workflows, and evaluation terms before connecting your own evidence.