Skip to content

Methodology

How the dollar number is built, and what we will not claim.

Valty translates source evidence into EBITDA impact using FAIR-style factor analysis and Monte Carlo simulation. Every number carries its method, confidence, and source coverage. This page shows the full arc, plus the boundaries we apply before any output reaches a board.

Inspect the risk model
FAIRRisk ontology

Factor Analysis of Information Risk, the industry standard for translating threat frequency and impact magnitude into probabilistic dollar ranges.

Monte CarloSimulation engine

A seeded, compound collective-risk engine runs thousands of trials across the input distributions, with extreme-value tail fitting, copula correlation, and paired common-random-numbers available per model, to produce a P10 / base / P90 range with quantile standard errors, not a single fragile point estimate.

EBITDABridge language

Exposure is expressed as EBITDA impact so PE operating partners, CFOs, and boards can evaluate it in the same unit as every other business decision.

01

Source adapter → evidence object

Source evidence is collected with owner and freshness

Controls, findings, cloud signals, identity events, supplier assessments, and agent actions are normalized into evidence objects. Each object carries source system, collection timestamp, owner, and a staleness flag when the asset has not been refreshed within its defined window.

02

Evidence object → FAIR factor set

FAIR factors are derived from the evidence, not assumed

Threat Event Frequency (TEF), Vulnerability (V), Threat Capability (TCap), and Loss Magnitude (LM) sub-factors are populated from real telemetry where available. Where evidence is absent or stale, the confidence tier drops and the assumption is flagged, not silently filled with a market average.

03

FAIR factors → P10 / base / P90 range

Monte Carlo simulation produces a range, not a point

The FAIR factor set defines input distributions, and a seeded Monte Carlo engine runs thousands of trials across them. It is a compound, collective-risk model: event frequency and per-event severity are drawn separately and aggregated, so a modeled year is the sum of its incidents rather than one averaged loss. Where these engine capabilities are enabled for a given model, extreme-value (EVT/GPD) fitting shapes the tail beyond the observed data, a Student-t copula couples correlated losses so a bad year can strike several drivers at once, and paired common-random-numbers isolate the effect of a single control change from simulation noise. The output is a loss-exceedance curve, P10 (conservative), base (median), P90 (tail), reported with quantile standard errors, so the precision of the band itself stays visible. A wide band means thin evidence, not false confidence.

04

Loss range → EBITDA bridge

The range maps to EBITDA bridge line items

Five scenario families translate loss ranges into EBITDA impact: ransomware / no-source-material (RNSM), data breach response cost (DBRC), compliance-driven value drag (CMPL), operational interruption (INTR), and insurance premium and retention change (INSR). Each line item carries the scenario family, the FAIR driver, and the evidence coverage that supports it.

05

EBITDA bridge → board-ready proof

Proof leaves the platform with its evidence chain visible

Board packs, IC briefs, and proof cards export the claim alongside its source coverage, confidence tier, freshness timestamp, and simulation parameters. A blocked-claim ledger surfaces any line item whose evidence is stale, missing, or below the publication threshold, so the board sees what is supported, not a cleaned-up summary.

Design partner

Illustrative output

The output is a range, not a point.

The card below shows the structure of a real financial output: P10 (10th percentile, conservative), base (median), and P90 (90th percentile, tail exposure). The values shown are illustrative inputs used for design validation; actual tenant outputs are workspace-bound.

Illustrative values only. Real outputs require your source evidence and are generated inside an authenticated Valty workspace.

  • Range width reflects the explicit model inputs; evidence confidence is shown separately
  • Each driver is traceable to a FAIR factor and a source evidence object
  • Export is blocked if any line item falls below the publication confidence threshold

FinancialHeroCard pattern

Portfolio value at risk

Live proof grammar
$14.2M

Decision-support estimate. P10 is the conservative case; P90 is tail exposure. Method, confidence, and source coverage are visible before any number reaches a board or IC packet.

P10 $10.8MBase $14.2MP90 $17.6M
FAIR Risk Engine product surface
FAIR Risk EngineInspect how FAIR factors and input distributions produce the output range, with method and assumptions visible next to the number.

Method in the product

The math is visible inside the platform, not hidden behind a black box.

The FAIR Risk Engine surface shows input distributions, simulation parameters, and the output loss exceedance curve, so any number that reaches a board can be traced back to its assumptions and challenged.

The EBITDA Sensitivity surface maps each scenario family to its EBITDA impact with adjustable assumption levers, so operating partners and CFOs can stress-test the model before it becomes a board action.

Because the model is seeded and its parameters are recorded, a run is reproducible and can be replayed against held-out history: Valty supports backtesting and model validation, so the method can be checked against what actually happened rather than only asserted. These are engine capabilities applied where the evidence supports them, and every output stays a decision-support estimate, never an actuarial or insurance valuation.

  • Distributions are shown, not hidden
  • Sensitivity levers are accessible before export
  • Blocked line items surface in the output, not after publication
EBITDA Sensitivity product surface
EBITDA SensitivityScenario families mapped to EBITDA impact with sensitivity levers, so assumptions can be adjusted and the output recalculated before it reaches a board.

FrameworkModeStack

Evidence-mode coverage

Automated
62
Assisted
24
Manual
14

Coverage and confidence

Evidence mode determines how much of the model is inferred vs. real.

Automated or API-verified evidence raises source confidence and makes more claims eligible for publication. Gaps in coverage lower the confidence tier and can block affected line items. V1 keeps that sufficiency decision separate from the PERT inputs used by the Monte Carlo model rather than automatically rewriting their range.

The framework mode bar shows the split between automated evidence (Tier 1–2), assisted evidence (Tier 3), and manual attestation for a representative control domain. Actual coverage depends on the connectors active in a tenant workspace.

Coverage percentages above are design-partner illustrative defaults. Tenant coverage is shown inside the authenticated workspace after source connectors are configured.

Proof matrix

EBITDA bridge: scenario families, FAIR factors, and confidence

Each scenario family maps to a FAIR factor set, the telemetry that populates it, the confidence band it produces, and the freshness requirement before a line item can be published.

ClaimSourceConfidenceFreshness
RNSM: Ransomware / no-source-materialEndpoint coverage, backup verification, IR-plan test date, EDR signal freshnessHigh when EDR + backup evidence is current; degrades to "inferred" when endpoint blind-spots existRequires re-run when coverage changes by >10% or after any IR plan revision
DBRC: Data breach response costData classification coverage, DLP signal, access-control evidence, incident-response cost benchmarks (Ponemon, latest published edition; illustrative)Moderate. Cost benchmarks are sector-adjusted illustrative inputs; actual cost depends on data volume and regulatory exposureBenchmark refreshed annually; tenant inputs refreshed on classification or access-control change
CMPL: Compliance-driven value dragGRC framework coverage, control-gap ledger, regulatory-deadline calendar, deal-pipeline exposureDesign-partner calibrated; confidence scales with GRC evidence freshness and completeness of the control ledgerRe-run on each framework update, control-gap change, or deal-stage transition
INTR: Operational interruptionCritical-asset dependency map, RTO/RPO evidence, availability telemetry, supplier-chain exposureDepends heavily on asset-inventory completeness; gaps are flagged rather than gap-filledRequires fresh availability telemetry; stale dependency maps degrade to lower-confidence tier
INSR: Insurance premium and retention changeCurrent policy limits, retention, renewal date, control evidence required by underwriter questionnaireDirectional. Premium impact is modelled from coverage posture, not from underwriter commitmentRefreshed at each renewal cycle or when material control evidence changes

Proof matrix

Evidence confidence tiers: how input quality flows into output confidence

FAIR factor inputs retain their explicit modeled ranges while evidence quality controls confidence labels and publication readiness. Lower-tier evidence can block a line item; it does not automatically rewrite the PERT inputs in V1.

ClaimSourceConfidenceFreshness
Tier 1: Hardware / agent attestedDirect agent telemetry, hardware-rooted signal, or API-verified control stateHighest. Used as primary input to FAIR factors without adjustmentFlagged stale after defined window (typically 24 h for agent signals)
Tier 2: Software / API verifiedConnector-pulled API state, cloud-config evidence, or scanner outputStrong. Carries source timestamp; confidence may degrade if scanner cadence lapsesFlagged stale after defined window (typically 48 – 96 h depending on source cadence)
Tier 3: Assisted / assessedQuestionnaire response, control assertion, or analyst-reviewed artifactModerate. Human-in-the-loop evidence is labeled and may require reviewer approval before publicationRequires re-attestation on schedule or on material product / process change
Tier 4: Inferred / benchmarkSector benchmark, FAIR default distribution, or gap-fill where tenant evidence is absentLow. Inferred inputs are flagged in output; publication of line items at this tier requires reviewer sign-offBenchmarks reviewed annually; any inferred input is superseded as soon as real evidence arrives

Artifact anatomy

Each output carries source, confidence, freshness, and a publication gate.

Scenario output
Source
FAIR simulation; inputs traceable to tenant evidence objects
Confidence
Tier determined by weakest input in the factor set
Freshness
Re-run required after any material evidence change
EBITDA bridge line item
Source
Scenario family + FAIR driver + EBITDA impact range
Confidence
Confidence tier carried from the underlying scenario
Freshness
Blocked for export if source evidence is stale
Board pack claim
Source
Approved line items only; blocked claims excluded automatically
Confidence
Reviewer sign-off required before publication
Freshness
Freshness timestamp visible in every exported artifact
Blocked claim
Source
Evidence below threshold, stale, or inferred without sign-off
Confidence
Not publishable in current state
Freshness
Requires owner action on source evidence before export

In plain language

How Valty Models Risk: The Methodology in Full

This page documents the mathematics behind Valty financial outputs: FAIR-aligned decomposition, explicit input distributions, Monte Carlo simulation, output bands, evidence sufficiency, and current implementation limits.

The FAIR decomposition: frequency times magnitude

Valty follows the Factor Analysis of Information Risk (FAIR) taxonomy. Annualized financial risk combines how often a loss event occurs (Loss Event Frequency) with how much it costs (Loss Magnitude). Loss Magnitude separates direct primary loss, such as response and restoration, from stakeholder-dependent secondary loss, such as fines, litigation, and churn. This keeps the output decomposable rather than presenting one opaque number.

From inputs to distributions, not point estimates

Each modeled factor uses an explicit distribution rather than a single guessed value. Bounded factors typically use minimum, most-likely, and maximum inputs represented by PERT/BetaPERT; frequency may use other treatments depending on the scenario. The range is a modeling input that must be sourced and reviewed. Hard data can justify changing that input, but evidence presence by itself does not automatically rewrite it.

The Monte Carlo: 10,000 independent draws

Each Monte Carlo iteration samples the configured frequency and magnitude distributions to produce one plausible annual-loss outcome. Valty repeats that process 10,000 times and reports the resulting distribution. A new evidence object can trigger review or recomputation, but the simulation still runs from the explicit factor inputs supplied to it.

Reading P10, base case, and P90

The simulated outcomes are ordered and summarized as P10, base, and P90. P10 represents a favorable modeled outcome, while P90 represents severe but credible tail exposure under the configured assumptions. Band width reflects the factor distributions used in that run and should be interrogated alongside source confidence and evidence sufficiency.

Evidence sufficiency and model ranges are separate in V1

Valty records source, freshness, confidence tier, and evidence gaps next to modeled figures. Insufficient evidence lowers publication readiness and can block a claim. V1 does not automatically widen or narrow PERT inputs solely because connector coverage changes. A reviewer may replace an inferred assumption with a better-sourced range, after which the model can be rerun; that explicit input change, not the mere arrival of evidence, changes the simulated distribution.

Explicit limitations and calibration discipline

These outputs are decision-support estimates, not actuarial, legal, insurance, or investment advice. Distributions are assumptions about shape, not facts, and poor inputs can still produce misleading precision. Reviewers should trace every band to its factor inputs and evidence, treat missing evidence as a publication and confidence issue, and change model ranges only when a defensible input update supports the change.

Claim boundary

What Valty does not claim.

Every method carries a boundary. These are ours, stated plainly because trust is built by making the limits visible, not by omitting them.

Not a warranty

Financial outputs are decision-support estimates, not contractual guarantees.

EBITDA impact ranges are model outputs derived from available evidence. They reflect the method, confidence, and limitations of the inputs, not a financial commitment or an insurance valuation. The number should be challenged, not blindly approved.

Not complete without your evidence

The model is only as good as the evidence that feeds it.

Valty does not hide missing tenant evidence. Where a FAIR factor lacks real source coverage, the confidence tier drops and the affected line items are flagged or blocked. V1 does not automatically widen PERT inputs based only on evidence coverage; the modeled range continues to reflect its explicit input assumptions.

Not a rip-and-replace

Valty works alongside your stack. It does not require you to replace it.

Your source systems (EDR, SIEM, GRC, cloud security posture, identity, scanners) stay the authoritative record. Valty reads and normalises that evidence into financial language, and can run its own passive external reconnaissance, certificate-transparency plus public breach, ransomware, and sanctions intelligence, to fill gaps. It works alongside your enforcement and detection layer rather than forcing a rip-and-replace.

Not a regulatory opinion

Compliance line items are exposure estimates, not legal or regulatory advice.

The CMPL scenario family models value drag from compliance gaps based on control evidence and regulatory timelines. It is not a legal opinion, audit assertion, or regulatory safe harbour. Organisations should apply qualified legal and compliance counsel to regulatory obligations.

Next step

Inspect the method, then decide whether the proof is ready for your board.

The financial risk review is scoped to your source systems. You bring the evidence; Valty shows how the model populates and where the confidence gaps are.