Mandatory tabletop + recovery capability
- Cost
- $90,000
- Tail loss (P95)
- $1,908,058
- Average annual loss (mean)
- $513,439
Worked example · Example Manufacturing Co. (fictional)
Compare two cyber investments under a $100,000 cap. Fictional company and inputs; modeled gross annual loss from Valty’s simulation engine.
Sample decision memo · illustrative
Recommended funding decision
Mandatory tabletop + recovery capability — $90,000Governing objectiveLowest modeled P95 within budget
First-year budget cap
$100,000Cost assumption, not a loss estimate. Gross loss; no insurance recovery modeled.
Required in this example
$15,000Sponsor-required tabletop. No loss reduction is claimed or modeled for this action.
Proposed amount
$90,000Mandatory tabletop + recovery capability, within the $100,000 cap.
Illustrative worked example. Company, decision, and all input assumptions are fictional. Not a customer outcome. Post-close first-100-days cyber budget decision at one portfolio company (illustrative). The frequency, severity, cost, and budget figures below are invented for this demonstration — not observed customer rates and not calibrated control effectiveness.
Download this memo (PDF)Illustrative · ungated · this page is the accessible HTML equivalent
Excluded, not zero
Network segmentation (evidence-held): Held: evidence missing. Owner: Portfolio-company security lead (fictional).
Return to this funding decision once a cost quote and a tested-coverage report exist; until then this option is held, not costed at $0 or assumed to have zero effect.
Swipe across the table to compare every column. With a keyboard, focus the table and use the arrow keys. →
| Option | Cost | Mean annual loss | P95 annual loss | Zero-loss-year share | Decision |
|---|---|---|---|---|---|
| No optional action (mandatory tabletop only) | $15,000 | $791,066 | $3,512,449 | 45.3% | Deferred: not P95-minimizing within budget |
| Mandatory tabletop + access hardening | $70,000 | $402,566 | $2,092,283 | 67.4% | Deferred: not P95-minimizing within budget |
| Mandatory tabletop + recovery capability | $90,000 | $513,439 | $1,908,058 | 45.3% | Proposed |
| Mandatory tabletop + both optional actions | $145,000 | $257,921 | $1,285,222 | 67.4% | Deferred: budget |
Mean (expected annual loss) and P95 (a large-loss year) are different decision bases, shown side by side. They are never added, and the combined-action row is a fresh engine run at both actions’ assumptions together, not the sum of two independent deltas.
Why a $0 median doesn’t mean no risk
45.3% of simulated years have zero loss events, so the median year is a modeled loss of $124,681 — not zero, and not negligible against a $100,000 budget decision, though well below the mean ($791,066) and P95 ($3,512,449).
At this lower assumed frequency, 67.4% of simulated years have zero events, so the median year is exactly $0. The mean is still $402,566: a $0 median describes the typical year, not the exposure a budget decision should be sized against, and it does not mean this or any low-frequency option is risk-free.
The recovery-capability action actually raises the median (from $124,681 to $275,501) while lowering the mean and P95. That is a consequence of the assumed severity distribution becoming narrower (lower log-sigma), not a measured effect — see the disclosure below and the methodology page for the full explanation.
Sensitivity: does the recommendation actually change?
| If weaker | P95 winner (vs. base) | Ranking changes? |
|---|---|---|
| If access hardening only reduces frequency to 0.6/yr (vs. the 0.4/yr assumed above) | Mandatory tabletop + recovery capability | No |
| If recovery capability only reduces mean severity to $800,000 (vs. $650,000 assumed above) | Mandatory tabletop + access hardening | Yes |
Both rows are real reruns of the engine at one changed assumption, not an assertion. If the recovery-capability action only reaches a $800K mean severity (vs. the $650K assumed), the P95-minimizing choice actually flips to mandatory tabletop + access hardening. This is why the memo shows the tradeoff, not a single locked answer. The paired random streams behind these reruns make the scenarios numerically comparable; they are not evidence that either action would work this way on a real company.
Statistical object: Annual aggregate gross loss S = sum_{k=1..N} X_k, N ~ Poisson(lambda) (event count), X_k ~ Lognormal(muLogUsd, sigmaLog) iid per-event severity (FAIR 2e / HTMA-Cyber compound collective-risk model). No insurance recovery modeled (gross loss only).
| Scenario | Frequency λ (events/yr) | Severity mean | Severity σ (log) |
|---|---|---|---|
| No optional action (mandatory tabletop only) | 0.8 | $1,000,000 | 1.2 |
| Mandatory tabletop + access hardening | 0.4 | $1,000,000 | 1.2 |
| Mandatory tabletop + recovery capability | 0.8 | $650,000 | 0.6 |
| Mandatory tabletop + both optional actions | 0.4 | $650,000 | 0.6 |
Engine source: pinned product revision 5c6ffc07c8af773a2944fe7ed22c4c8a2035d485, vendored byte-identical (see repo scripts/financial-fixture/provenance.json). The only hand-edited line replaces one product-internal import with a local adapter that throws if called; every engine call in the generator passes explicit options so that adapter is never reached. Every scenario run is also checked for per-iteration event-count truncation before this fixture can be written.
Analytic check (closed-form vs. engine, at generation time): mean relative error and zero-loss-year absolute error for every scenario stayed within the generator’s stated tolerance (5% relative on mean, 1 percentage point on zero-loss-year share) — see decisionFixture.analyticChecks for the exact recorded values.
Independence and three distinct kinds of variation: each simulated year draws an event count and each event’s severity independently, so the annual loss is a sum of independent, identically distributed draws — the resulting mean-to-P95 spread is real modeled year-to-year outcome variability, not an error. Separately, the analytic checks above measure finite-sample (Monte Carlo) simulation error — specifically how closely the mean and zero-loss-year share track their closed-form values at 50,000 trials, not every percentile. Separately again, whether the entered frequency and severity assumptions themselves are realistic (parameter uncertainty) is not quantified anywhere on this page.
Read the full statistical definitions (mean vs. median vs. tail, event vs. annual, gross vs. net of insurance, joint recomputation, and the recovery-action median/mean shape effect) on the methodology page.
Illustrative demo scenario. Not customer data, a customer artifact, or a customer outcome. All loss figures are decision-support estimates from invented assumptions run through a real simulation engine — not actuarial, legal, or investment advice, and not a guarantee of any modeled reduction.
Next step
A free 30-minute platform demo uses illustrative data to walk through the supported workflow. Company scope, evidence handling, access, onboarding, and commercial terms are agreed before an evaluation begins. Every figure above is fictional; a company-specific decision requires that company’s evidence and assumptions.