Quickstart: your first scenario
Model, simulate, and rate your first cyber risk scenario in about ten minutes.
Last updated
Model, simulate, and rate your first cyber risk scenario in about ten minutes.
New installs come seeded with a sample workspace, Acme Corp, containing a dozen example scenarios (ransomware, data breach, wire fraud, DDoS, and more). Browse those for inspiration, then build your own.
The Loss Event Frequency (LEF) card asks: how often per year does this loss event actually occur? If you have a feel for it, estimate it directly with a range (for example a PERT distribution with minimum 0.1, most likely 0.5, maximum 2 events per year). If not, decompose it into Threat Event Frequency x Vulnerability and estimate those instead.
Use the Analyst notes box on the card to record your assumptions and sources.
The Loss Magnitude (LM) card asks: when the event happens, how much does one occurrence cost? Estimate a single distribution, or split it into Primary Loss plus Secondary Risk, and further into the six FAIR forms of loss if you want that granularity.
A lognormal defined by its 10th and 90th percentiles is a common starting point: "I'd be surprised if it cost less than $200k or more than $5M."
Save the scenario and select it in the scenario table. The simulation runs automatically and the Results dock at the bottom fills in:
Summary tiles: Expected Annual Loss, Median, P90, 95% VaR, P99, and the probability of any loss in a year
A Loss Exceedance curve and Histogram
A risk rating (Low, Moderate, High, or Critical) against your risk appetite
Not ready to finish? Save draft parks an incomplete scenario. Drafts are excluded from simulations and reports until you complete them.
Last updated