Factor Analysis of Information Risk, the industry standard for translating threat frequency and impact magnitude into probabilistic dollar ranges.
Methodology
How the dollar number is built, and what we will not claim.
Valty translates source evidence into EBITDA impact using FAIR-style factor analysis and Monte Carlo simulation. Every number carries its method, confidence, and source coverage. This page shows the full arc, plus the boundaries we apply before any output reaches a board.
Inspect the risk modelA seeded, compound collective-risk engine runs thousands of trials across the input distributions, with extreme-value tail fitting, copula correlation, and paired common-random-numbers available per model, to produce a P10 / base / P90 range with quantile standard errors, not a single fragile point estimate.
Exposure is expressed as EBITDA impact so PE operating partners, CFOs, and boards can evaluate it in the same unit as every other business decision.
Source evidence is collected with owner and freshness
Controls, findings, cloud signals, identity events, supplier assessments, and agent actions are normalized into evidence objects. Each object carries source system, collection timestamp, owner, and a staleness flag when the asset has not been refreshed within its defined window.
FAIR factors are derived from the evidence, not assumed
Threat Event Frequency (TEF), Vulnerability (V), Threat Capability (TCap), and Loss Magnitude (LM) sub-factors are populated from real telemetry where available. Where evidence is absent or stale, the confidence tier drops and the assumption is flagged, not silently filled with a market average.
Monte Carlo simulation produces a range, not a point
The FAIR factor set defines input distributions, and a seeded Monte Carlo engine runs thousands of trials across them. It is a compound, collective-risk model: event frequency and per-event severity are drawn separately and aggregated, so a modeled year is the sum of its incidents rather than one averaged loss. Where these engine capabilities are enabled for a given model, extreme-value (EVT/GPD) fitting shapes the tail beyond the observed data, a Student-t copula couples correlated losses so a bad year can strike several drivers at once, and paired common-random-numbers isolate the effect of a single control change from simulation noise. The output is a loss-exceedance curve, P10 (conservative), base (median), P90 (tail), reported with quantile standard errors, so the precision of the band itself stays visible. A wide band means thin evidence, not false confidence.
The range maps to EBITDA bridge line items
Five scenario families translate loss ranges into EBITDA impact: ransomware / no-source-material (RNSM), data breach response cost (DBRC), compliance-driven value drag (CMPL), operational interruption (INTR), and insurance premium and retention change (INSR). Each line item carries the scenario family, the FAIR driver, and the evidence coverage that supports it.
Proof leaves the platform with its evidence chain visible
Board packs, IC briefs, and proof cards export the claim alongside its source coverage, confidence tier, freshness timestamp, and simulation parameters. A blocked-claim ledger surfaces any line item whose evidence is stale, missing, or below the publication threshold, so the board sees what is supported, not a cleaned-up summary.
Illustrative output
The output is a range, not a point.
The card below shows the structure of a real financial output: P10 (10th percentile, conservative), base (median), and P90 (90th percentile, tail exposure). The values shown are illustrative inputs used for design validation; actual tenant outputs are workspace-bound.
Illustrative values only. Real outputs require your source evidence and are generated inside an authenticated Valty workspace.
- Range width reflects the explicit model inputs; evidence confidence is shown separately
- Each driver is traceable to a FAIR factor and a source evidence object
- Export is blocked if any line item falls below the publication confidence threshold
FinancialHeroCard pattern
Portfolio value at risk
Decision-support estimate. P10 is the conservative case; P90 is tail exposure. Method, confidence, and source coverage are visible before any number reaches a board or IC packet.

Method in the product
The math is visible inside the platform, not hidden behind a black box.
The FAIR Risk Engine surface shows input distributions, simulation parameters, and the output loss exceedance curve, so any number that reaches a board can be traced back to its assumptions and challenged.
The EBITDA Sensitivity surface maps each scenario family to its EBITDA impact with adjustable assumption levers, so operating partners and CFOs can stress-test the model before it becomes a board action.
Because the model is seeded and its parameters are recorded, a run is reproducible and can be replayed against held-out history: Valty supports backtesting and model validation, so the method can be checked against what actually happened rather than only asserted. These are engine capabilities applied where the evidence supports them, and every output stays a decision-support estimate, never an actuarial or insurance valuation.
- Distributions are shown, not hidden
- Sensitivity levers are accessible before export
- Blocked line items surface in the output, not after publication

FrameworkModeStack
Evidence-mode coverage
- Automated
- 62
- Assisted
- 24
- Manual
- 14
Coverage and confidence
Evidence mode determines how much of the model is inferred vs. real.
Automated or API-verified evidence raises source confidence and makes more claims eligible for publication. Gaps in coverage lower the confidence tier and can block affected line items. V1 keeps that sufficiency decision separate from the PERT inputs used by the Monte Carlo model rather than automatically rewriting their range.
The framework mode bar shows the split between automated evidence (Tier 1–2), assisted evidence (Tier 3), and manual attestation for a representative control domain. Actual coverage depends on the connectors active in a tenant workspace.
Coverage percentages above are design-partner illustrative defaults. Tenant coverage is shown inside the authenticated workspace after source connectors are configured.
Proof matrix
EBITDA bridge: scenario families, FAIR factors, and confidence
Each scenario family maps to a FAIR factor set, the telemetry that populates it, the confidence band it produces, and the freshness requirement before a line item can be published.
Proof matrix
Evidence confidence tiers: how input quality flows into output confidence
FAIR factor inputs retain their explicit modeled ranges while evidence quality controls confidence labels and publication readiness. Lower-tier evidence can block a line item; it does not automatically rewrite the PERT inputs in V1.
Artifact anatomy
Each output carries source, confidence, freshness, and a publication gate.
- Source
- FAIR simulation; inputs traceable to tenant evidence objects
- Confidence
- Tier determined by weakest input in the factor set
- Freshness
- Re-run required after any material evidence change
- Source
- Scenario family + FAIR driver + EBITDA impact range
- Confidence
- Confidence tier carried from the underlying scenario
- Freshness
- Blocked for export if source evidence is stale
- Source
- Approved line items only; blocked claims excluded automatically
- Confidence
- Reviewer sign-off required before publication
- Freshness
- Freshness timestamp visible in every exported artifact
- Source
- Evidence below threshold, stale, or inferred without sign-off
- Confidence
- Not publishable in current state
- Freshness
- Requires owner action on source evidence before export
In plain language
How Valty Models Risk: The Methodology in Full
This page documents the mathematics behind Valty financial outputs: FAIR-aligned decomposition, explicit input distributions, Monte Carlo simulation, output bands, evidence sufficiency, and current implementation limits.
The FAIR decomposition: frequency times magnitude
Valty follows the Factor Analysis of Information Risk (FAIR) taxonomy. Annualized financial risk combines how often a loss event occurs (Loss Event Frequency) with how much it costs (Loss Magnitude). Loss Magnitude separates direct primary loss, such as response and restoration, from stakeholder-dependent secondary loss, such as fines, litigation, and churn. This keeps the output decomposable rather than presenting one opaque number.
From inputs to distributions, not point estimates
Each modeled factor uses an explicit distribution rather than a single guessed value. Bounded factors typically use minimum, most-likely, and maximum inputs represented by PERT/BetaPERT; frequency may use other treatments depending on the scenario. The range is a modeling input that must be sourced and reviewed. Hard data can justify changing that input, but evidence presence by itself does not automatically rewrite it.
The Monte Carlo: 10,000 independent draws
Each Monte Carlo iteration samples the configured frequency and magnitude distributions to produce one plausible annual-loss outcome. Valty repeats that process 10,000 times and reports the resulting distribution. A new evidence object can trigger review or recomputation, but the simulation still runs from the explicit factor inputs supplied to it.
Reading P10, base case, and P90
The simulated outcomes are ordered and summarized as P10, base, and P90. P10 represents a favorable modeled outcome, while P90 represents severe but credible tail exposure under the configured assumptions. Band width reflects the factor distributions used in that run and should be interrogated alongside source confidence and evidence sufficiency.
Evidence sufficiency and model ranges are separate in V1
Valty records source, freshness, confidence tier, and evidence gaps next to modeled figures. Insufficient evidence lowers publication readiness and can block a claim. V1 does not automatically widen or narrow PERT inputs solely because connector coverage changes. A reviewer may replace an inferred assumption with a better-sourced range, after which the model can be rerun; that explicit input change, not the mere arrival of evidence, changes the simulated distribution.
Explicit limitations and calibration discipline
These outputs are decision-support estimates, not actuarial, legal, insurance, or investment advice. Distributions are assumptions about shape, not facts, and poor inputs can still produce misleading precision. Reviewers should trace every band to its factor inputs and evidence, treat missing evidence as a publication and confidence issue, and change model ranges only when a defensible input update supports the change.
Claim boundary
What Valty does not claim.
Every method carries a boundary. These are ours, stated plainly because trust is built by making the limits visible, not by omitting them.
Not a warranty
Financial outputs are decision-support estimates, not contractual guarantees.
EBITDA impact ranges are model outputs derived from available evidence. They reflect the method, confidence, and limitations of the inputs, not a financial commitment or an insurance valuation. The number should be challenged, not blindly approved.
Not complete without your evidence
The model is only as good as the evidence that feeds it.
Valty does not hide missing tenant evidence. Where a FAIR factor lacks real source coverage, the confidence tier drops and the affected line items are flagged or blocked. V1 does not automatically widen PERT inputs based only on evidence coverage; the modeled range continues to reflect its explicit input assumptions.
Not a rip-and-replace
Valty works alongside your stack. It does not require you to replace it.
Your source systems (EDR, SIEM, GRC, cloud security posture, identity, scanners) stay the authoritative record. Valty reads and normalises that evidence into financial language, and can run its own passive external reconnaissance, certificate-transparency plus public breach, ransomware, and sanctions intelligence, to fill gaps. It works alongside your enforcement and detection layer rather than forcing a rip-and-replace.
Not a regulatory opinion
Compliance line items are exposure estimates, not legal or regulatory advice.
The CMPL scenario family models value drag from compliance gaps based on control evidence and regulatory timelines. It is not a legal opinion, audit assertion, or regulatory safe harbour. Organisations should apply qualified legal and compliance counsel to regulatory obligations.
Next step
Inspect the method, then decide whether the proof is ready for your board.
The financial risk review is scoped to your source systems. You bring the evidence; Valty shows how the model populates and where the confidence gaps are.