What is the QRM methodology?
QRM (Quantified Risk Model) is our proprietary methodology that combines NIST 800-30, Hubbard calibration methods, and Monte Carlo simulation. It decomposes every risk into five measurable factors: Threat Probability (TP), Realization Rate (RR), Impact Severity (IS), Cascading Impact (CI), and Impact Multiplier (IM). These factors are combined to calculate Annual Loss Expectancy (ALE)—a defensible dollar amount your board can act on.
What are the five QRM factors?
The five QRM factors are: (1) Threat Probability (TP) — how often attackers attempt an attack; (2) Realization Rate (RR) — how often those attempts succeed; (3) Impact Severity (IS) — direct costs when an attack succeeds; (4) Cascading Impact (CI) — secondary costs like regulatory fines, lawsuits, or reputation damage; and (5) Impact Multiplier (IM) — the probability that those secondary impacts occur. The formula is: ALE = (TP × RR) × (IS + (CI × IM)).
How does QRM align with NIST 800-30?
QRM explicitly maps to NIST Special Publication 800-30 Rev. 1, the federal standard for conducting risk assessments. This provides regulatory alignment for federal contractors and regulated industries, audit defensibility with documented methodology, and compatibility with NIST Cybersecurity Framework (CSF) and NIST 800-53 controls.
What is calibration training and why is it mandatory?
Calibration training helps you give accurate probability estimates. Research by Douglas Hubbard shows that when people give 90% confidence intervals, they typically contain the true answer only 50-60% of the time. This overconfidence makes risk calculations unreliable. RisqRadar requires calibration training before you create risk assessments because garbage in = garbage out. Our goal is to ensure that when you say 90% confident, you're actually right 90% of the time.
What cognitive biases does calibration training address?
Our AI Calibration Coach detects and helps correct several cognitive biases including: anchoring (over-relying on the first number you hear), overconfidence (confidence intervals that are too narrow), availability bias (overweighting recent or memorable events), and the planning fallacy (underestimating time and costs). The coach provides personalized exercises targeting your specific bias patterns.
How does Monte Carlo simulation work?
Monte Carlo simulation runs thousands of scenarios (typically 10,000) using your input probability distributions. For each scenario, it randomly samples values for all five QRM factors, then calculates the resulting loss. The output is a probability distribution showing the range of possible outcomes—including expected loss, 90th percentile loss, and the probability of exceeding various thresholds. This properly propagates uncertainty through the calculation.
What if I don't have precise data for my estimates?
That's exactly why we use probability distributions instead of point estimates. You provide a range (minimum, most likely, maximum) that captures your uncertainty. The AI Estimation Assistant helps by providing industry benchmarks from sources like Verizon DBIR, IBM Ponemon, and Coveware. Even rough estimates, when properly calibrated, produce useful results—and you can use Value of Information analysis to identify which estimates are worth refining.
What AI features does RisqRadar include?
RisqRadar includes five AI-powered features: (1) AI Calibration Coach — analyzes your performance and detects cognitive biases; (2) AI Estimation Assistant — provides industry benchmarks and validation on every input; (3) AI Scenario Generator — recommends relevant risk scenarios for your organization; (4) AI Report Narrator — generates board-ready talking points and Q&A preparation; (5) AI Question Generator — creates fresh calibration questions for ongoing certification.
Does the AI make decisions for me?
No. The AI guides but never replaces your judgment. It provides industry benchmarks, flags estimates that seem too narrow or wide, and helps decompose complex estimates into simpler parts. But it never gives you a single "correct" answer. You remain in control of all risk assessments and final decisions.
What industry benchmarks does the AI use?
The AI Estimation Assistant references authoritative sources including: Verizon Data Breach Investigations Report (DBIR), IBM/Ponemon Cost of a Data Breach Report, Coveware Ransomware Reports, Mandiant M-Trends, and the HHS HIPAA Penalty Database. These provide evidence-based starting points for your estimates.
How is this better than a risk matrix or heat map?
Risk matrices can't tell you actual exposure in dollars, can't be mathematically combined (you can't add "high" + "medium"), and often produce inconsistent rankings. QRM gives you numbers you can use: expected annual loss, value at risk percentiles, and return on security investment. Instead of "high risk," you can tell your board "$2.4M expected annual loss with 10% chance of exceeding $8M."
How does RisqRadar compare to enterprise CRQ tools?
Most cyber risk quantification tools stop at quantification — you still buy separate systems for audit readiness, policy governance, and vulnerability management, then reconcile them by hand. RisqRadar runs all of that on one connected graph, with calibration training built in and quick onboarding rather than a multi-month consulting engagement. Pricing is contract-based and tailored to your organization — contact us and we'll scope it with you.
Can I use RisqRadar for compliance and audit purposes?
Yes. QRM's explicit alignment with NIST 800-30 provides a defensible approach to risk assessment recognized by regulators and auditors. Your quantitative analysis, with documented assumptions, calibrated estimators, and transparent methodology, provides much stronger audit evidence than subjective heat maps. Many organizations use RisqRadar to support SOC 2, HIPAA, and federal compliance requirements.
How do I calculate ROI on security controls?
Run simulations with and without a proposed control to see the expected loss reduction. RisqRadar's control analysis shows exactly how each control affects the five QRM factors. Compare the annual loss reduction against the control's cost. If a $100K control reduces expected annual loss by $500K, you have a clear ROI case for leadership.
What types of risks can I analyze?
RisqRadar can model any cyber risk scenario including ransomware attacks, data breaches, insider threats, DDoS attacks, business email compromise, third-party/supply chain breaches, system outages, regulatory penalties, and more. The AI Scenario Generator can recommend relevant scenarios based on your industry, size, and technology profile.
How much does RisqRadar cost?
Pricing is contract-based and tailored to your organization — its size, the modules you use, and how many people are involved. There's no public price list. Tell us about your program through the contact form and we'll put together a proposal that fits.
What's included?
A RisqRadar engagement spans the whole platform: the quantified risk register with calibration and certification, the Audit Readiness module (NIST CSF, ISO 27001, ISO 42001), policy governance and the document library, and vulnerability management with scanner and ticketing integrations — plus the AI assistants throughout. We'll scope which pieces matter most for you during onboarding.
How do I get started?
Reach out through the contact form for a demo on your own risks. From there we set up your organization, and guided onboarding walks your team through calibration and your first assessments so you reach a defensible number quickly rather than after a months-long implementation.
What support options are available?
Every engagement includes onboarding support and access to comprehensive documentation and guides. Larger deployments get dedicated onboarding and a named point of contact. Tell us what your team needs and we'll build it into the engagement.
Is there a certification program?
Yes. Professional and Enterprise plans include access to our calibration certification program. You can earn certification by demonstrating calibrated estimation skills (90% accuracy at the 90% confidence level). Certifications require annual recertification to ensure skills remain sharp—the AI Question Generator creates fresh questions so you never see the same one twice.