# Welcome to the SecureMetrics!

## Overview

SecureMetrics creates PowerBI templates and apps for security teams to better analyze, communicate, and report on their security data. Here you can find documentation across our products.

## Quick links

{% content-ref url="/pages/74UxrYLxf9RoBGjgoTQX" %}
[SecureMetrics Risk Register](/securemetrics-risk-register/setup-guide)
{% endcontent-ref %}

{% content-ref url="/pages/v6NLQRXYx2YHIfuZ2oBD" %}
[NIST CSF 2.0 User Guide](/nist-csf-2.0/nist-csf-2.0-user-guide)
{% endcontent-ref %}

{% content-ref url="/pages/PM3TUSLWpxG3mRXGZu8O" %}
[Attack Surface Discovery User Guide](/attack-surface-discovery/attack-surface-discovery-user-guide)
{% endcontent-ref %}


# Setup Guide

{% columns %}
{% column %}

<figure><img src="/files/2sjkSx5O0w2e4EWBfV35" alt=""><figcaption></figcaption></figure>
{% endcolumn %}

{% column %}

<figure><img src="/files/BnYIckWcd54Nyj0IjKg8" alt=""><figcaption></figcaption></figure>
{% endcolumn %}
{% endcolumns %}

## Contents

The Security Metrics Toolkit contains two files:

1. Security Metrics Excel Template (.xlxs)
2. Security Metrics PowerBI Template (.pbit)

The Security Metrics Excel Template comes preloaded with demo data, meaning you can hook it up to the PowerBI template right away. Keep in mind, you will need to replace the content of the Excel file to load in your data.&#x20;

{% hint style="info" %}
Note: This quick start guide assumes you already have Microsoft PowerBI Desktop installed. If you do not, you can download it free from Microsoft.
{% endhint %}

## 1) Host the Excel Template in Cloud Storage

{% hint style="warning" %}
You will need to fill out the Excel Template: [Documentation](/security-metrics-toolkit/excel-template)
{% endhint %}

Upload the Excel Template to one of the following cloud storage solutions:

* Microsoft Teams
* Microsoft SharePoint
* Microsoft OneDrive&#x20;

### File Path

{% hint style="warning" %}
The file path is not the URL or link to the file
{% endhint %}

After, note the path to reach the file. [The easiest way to find this is by opening the Excel Template in the desktop application.](/security-metrics-toolkit/excel-template#excel-workbook-path) Ensure you are opening the file from the cloud storage location and not the local device.&#x20;

{% embed url="<https://www.loom.com/share/40df0093875748a489ced69dd7ea0a96>" %}

Then, in the Excel desktop application, go to "File" > "Recent" > Right click on the file > "Copy path to clipboard."

Paste the copied path into a text editor and remove the suffix "?web=1" so that the path ends with the file extension.&#x20;

{% embed url="<https://www.loom.com/share/4ba40a32be6a4ccaa808bdcc0c98a88e>" %}

## 2) Open the PowerBI Template

{% hint style="warning" %}
Ensure you removed the suffix "?web=1" from the path before entering it into PowerBI.&#x20;
{% endhint %}

Navigate to the PowerBI Template file (.pbit) and open it in Microsoft PowerBI Desktop. After opening, PowerBI will prompt you for the filepath we gathered in step 1. Paste the filepath and click okay. PowerBI will then load in and transform the data.&#x20;

{% embed url="<https://www.loom.com/share/cd6064ce3c464bf6bc56c6a5eab7e4ec>" %}

## 3) Save the PowerBI Report

Go to "file" > "save as" and save the PowerBI report. This will save it as a .pbix file. If you want to setup another security metrics report, simply repeat the first two steps.&#x20;


# Excel Template

The Security Metrics Toolkit Excel Template is the heart of your security metrics program. It has two tabs: Metrics Inventory and Log.&#x20;

You will define your metrics in the **Metric Inventory.** \
You will log your measurements in the **Log.**&#x20;

<table data-view="cards"><thead><tr><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td>Metric Inventory Sheet</td><td><a href="/pages/dCDtChMYWe0eIJEYTEbm">/pages/dCDtChMYWe0eIJEYTEbm</a></td></tr><tr><td>Log Sheet</td><td><a href="/pages/hNJfHYTKnZLrnWznpWsc">/pages/hNJfHYTKnZLrnWznpWsc</a></td></tr></tbody></table>

<br>


# Metric Inventory Sheet

{% hint style="info" %}
The required column denotes columns that are required for the PowerBI Template to function. Although not all columns are required, it is good practice to document all of the following details for your metrics.
{% endhint %}

It is critical that the metrics you measure are defined and inventoried. In addition, this data is used in the PowerBI Template. The metric inventory sheet has the following columns for each metric:

<table><thead><tr><th>Column</th><th>Description</th><th>Example</th><th data-type="checkbox">Required</th></tr></thead><tbody><tr><td>Metric ID</td><td>A unique identifier for the metric. </td><td>M-01</td><td>true</td></tr><tr><td>Active</td><td>Yes/No indicating if the metric is actively part of the metrics program. Setting this to "No" hides the metric from most views.</td><td>Yes</td><td>true</td></tr><tr><td>Date Added</td><td>This is the date the metric was added to the inventory</td><td>08/26/2025</td><td>false</td></tr><tr><td>Date Last Updated</td><td>This is the date of the most recent update to the metric in the metric inventory. <strong>This is not</strong> the last time a measurement was recorded in the log.</td><td>08/31/2025</td><td>false</td></tr><tr><td>Type</td><td>This is the type of metric, aligned to the NIST 800-55 guidance. Options are "Implementation", "Efficiency", "Effectiveness", or "Impact"</td><td>Implementation</td><td>false</td></tr><tr><td>Metric Title</td><td>The title of the metric in a human-readable format. It's recommended this field is a full metric statement.</td><td>Percent of workstations covered by endpoint detection and response (EDR)</td><td>true</td></tr><tr><td>Group</td><td>The group the metric belongs to. This can be any string, and can be used to group metrics in various views.</td><td>Endpoint Security</td><td>false</td></tr><tr><td>Purpose</td><td>This is the purpose of the metric. </td><td>Implementation of EDR</td><td>false</td></tr><tr><td>Calculation</td><td>This is the calculation to derive the metric.</td><td>Number of workstations covered by EDR / Total workstations</td><td>false</td></tr><tr><td>Target</td><td>The target for the metric. Ensure you do not format this field. Use decimal format for percentages. </td><td>0.95</td><td>true</td></tr><tr><td>Measurement Frequency (Days)</td><td>The frequency or cadence, in days, measurements are taken. </td><td>14</td><td>true</td></tr><tr><td>Owner</td><td>The owner of the metric.</td><td>Mitchell Telatnik</td><td>false</td></tr><tr><td>Data Source(s)</td><td>The data source(s) the metric is calculated from</td><td>CrowdStrike, CMDB</td><td>false</td></tr><tr><td>Format</td><td>The format of the metric. Options include "Percentage", "Numeric", or "Currency" </td><td>Percentage</td><td>true</td></tr><tr><td>Direction</td><td>Indicates if a higher or lower value is better. </td><td>Higher</td><td>true</td></tr><tr><td>Retirement Date</td><td>The date the metric was retired from the metrics program.</td><td>02/15/2026</td><td>false</td></tr><tr><td>Retirement Reason</td><td>The reason the metric was retired from the metrics program.</td><td>Not driving actionable value</td><td>false</td></tr></tbody></table>

### Adding Metrics

When adding a new metric, create a new row in the Metric Inventory Sheet. Some items to keep in mind include:

1. Ensure the metric has a unique Metric ID. It's recommended, but not required to use a consistent schema, such as "M-XX".&#x20;
2. If you don't want the metric to appear in the report yet (no measurements, etc) set "Active" to no.&#x20;
3. Ensure the target field is unformatted. Percentages should be in decimal format.
4. Ensure you set the correct format of the metric.&#x20;
5. Ensure you set the correct direction.
6. A metric can only be assigned to one group.
7. Guidance on metric types (Implementation, Efficiency, Effectiveness, Impact) can be found in NIST SP 800-55.

Once a metric is added to the Metric Inventory Sheet, it will be pulled into the PowerBI Report upon refresh. If Active is set to "true", the metric will appear in the Metrics Matrix, Metric Inventory, as well as be configurable on cards. If Active is set to "false" the metric will only appear in Metric Inventory.

Once measurements are added to the Log Sheet, data will appear for the metric in the PowerBI report.

### Retiring Metrics

While a key tenant of a successful metrics program is measuring the same metric over time, there will be times that metrics need to be retired from the program. Reasons can vary, but some common reasons include:

* Change in Security Program's goals and objectives
* Metric is no longer useful
* Level of effort to calculate is too high
* Superseeded by a new metric

In order to keep a record of historical metrics, instead of deleting the metric you can retire it. To retire a metric, set Active to "No", enter a date for the field "Retirement Date" and a reason for the field "Retirement Reason".&#x20;

Upon refresh, the metric will no longer appear in the Metrics Matrix. Cards that were configured for the metric will need to be deleted or reconfigured for another metric. The metric will remain visible in the Metrics Inventory.


# Log Sheet

After defining your metrics in the Metrics Inventory sheet, you will log the measurements in the log sheet. The log sheet has the following columns:

<table><thead><tr><th>Column</th><th>Description</th><th>Example</th><th data-type="checkbox">Required</th></tr></thead><tbody><tr><td>Metric ID</td><td>The unique identifier of the metric. This must match to the Metric ID defined in the Metric Inventory.</td><td>M-01</td><td>true</td></tr><tr><td>Value</td><td>The value of the measurement being reported. Do not format this column. Use decimal format for percentages.</td><td>0.8</td><td>true</td></tr><tr><td>Measurement Date</td><td>The date of the measurement.</td><td>08/31/2025</td><td>true</td></tr><tr><td>Notes</td><td>Any notes associated with the measurement.</td><td>We’ve seen a slight dip in coverage this month, primarily due to delays in onboarding new contractor workstations. A remediation plan is in place.</td><td>false</td></tr></tbody></table>

## Recording Measurements

Once a metric has been added to the Metric Inventory Sheet, you will need to record measurements in the Log Sheet. A measurement is a single value for a metric tied to a measurement date. Metrics may have different measurement cadences: some may be measured quarterly, others weekly or even daily.&#x20;

All measurements must be added to the log. To add a measurement, add the Metric ID the measurement is for, the measured value, the date of the measurement, and optionally add notes for added context.

Some things to keep in mind:

* The Metric ID must match the ID from the Metric Inventory Sheet.
* The value must be unformatted. Percentages should be in decimal format.


# PowerBI Template

After setting up the PowerBI Template, you will notice the following pages:

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td>Metrics Matrix™</td><td><a href="/pages/F8rTbqmxPlH2lq9pmNDv">/pages/F8rTbqmxPlH2lq9pmNDv</a></td><td><a href="/files/2sjkSx5O0w2e4EWBfV35">/files/2sjkSx5O0w2e4EWBfV35</a></td><td><a href="/pages/F8rTbqmxPlH2lq9pmNDv">/pages/F8rTbqmxPlH2lq9pmNDv</a></td></tr><tr><td>Metric Cards</td><td><a href="/pages/S8zeqZ8bXH99SndInmjP">/pages/S8zeqZ8bXH99SndInmjP</a></td><td><a href="/files/BnYIckWcd54Nyj0IjKg8">/files/BnYIckWcd54Nyj0IjKg8</a></td><td><a href="/pages/S8zeqZ8bXH99SndInmjP">/pages/S8zeqZ8bXH99SndInmjP</a></td></tr><tr><td>Variance Cards</td><td><a href="/pages/jM2xdpbWvEh7ojfQV5yZ">/pages/jM2xdpbWvEh7ojfQV5yZ</a></td><td></td><td><a href="/pages/jM2xdpbWvEh7ojfQV5yZ">/pages/jM2xdpbWvEh7ojfQV5yZ</a></td></tr><tr><td>Metric Inventory</td><td><a href="/pages/KHSd7WEEQ8KiYZxTOdJb">/pages/KHSd7WEEQ8KiYZxTOdJb</a></td><td></td><td><a href="/pages/KHSd7WEEQ8KiYZxTOdJb">/pages/KHSd7WEEQ8KiYZxTOdJb</a></td></tr></tbody></table>

The Metrics Matrix™ and Metric Inventory page require no configuration. However, the Metrics Cards and Variance cards require some basic setup.&#x20;


# Metrics Matrix™

The Metrics Matrix™ page is a compact layout designed to present the entire security metrics program at a glance.

<figure><img src="/files/2sjkSx5O0w2e4EWBfV35" alt=""><figcaption></figcaption></figure>

### Action Dots

The Metrics Matrix uses action dots in multiple sections of the page. Action dots are red "dots" that signal attention. These dots help guide the user's attention to areas that may need their attention, reducing cognitive load.&#x20;

Whenever you see an action dot on the Metrics Matrix, that means that the latest measurement for a metric (actual) does not meet or exceed the set target. Action dots take into consideration if a metric should be higher or lower than the target.&#x20;

<figure><img src="/files/hJsRoLyWJaTvBzvwFrxC" alt=""><figcaption></figcaption></figure>

### Components

The Metrics Matrix Page has 4 main components: Metric Type Table, Metric Group Table, Metrics Matrix, and Group by dropdown.&#x20;

<figure><img src="/files/2eEmmTKyFcfoXN3hBCN8" alt=""><figcaption></figcaption></figure>

### Metrics Matrix

The Metrics Matrix lists all active metrics. Metrics that are not set as active are not shown. The following fields are provided: Metric ID, Metric, Actual, Target, Delta, Owner, and Last Measured.&#x20;

Metrics are grouped based on the Group-by Dropdown. You can expand and collapse groups by clicking on the icon next to the grouping.&#x20;

Hovering over a metric will show the latest notes provided.&#x20;

{% embed url="<https://www.loom.com/share/ddc5620bb9794be7a2af33d1edbc5cd1>" %}

### Metric Type Table

The metric type table lists the four types of metrics (Implementation, Efficiency, Effectiveness, and Impact) and the number of metrics in those categories.&#x20;

You can click on a metric type to filter the Metrics Matrix by that type. Action dots denote metric types that have at least one metric that does not meet or exceed the target.&#x20;

{% embed url="<https://www.loom.com/share/83dd2a8a6f7045c6a5ed1b272a4e72f6>" %}

### Metric Group Table

The metric group table lists the group names and number of metrics in those groups. A metric can only be assigned to one group. You can create any grouping you want by setting the group for a metric in the Excel Template.&#x20;

You can click on a metric group to filter the Metrics Matrix by that group. Action dots denote metric groups that have at least one metric that does not meet or exceed the target.&#x20;

{% embed url="<https://www.loom.com/share/5028a7c2165940219124a03a69ba3f24>" %}

### Group-by Dropdown

The group-by dropdown allows you to change the grouping of metrics in the Metrics Matrix. You can select to group metrics by group, type, or owner.&#x20;

{% embed url="<https://www.loom.com/share/0d92cae8c7f6409a909324a0ab6bce5f>" %}

&#x20;


# Configuring Metric Cards

The Metric Cards page has a sample layout for displaying different security metrics.

<figure><img src="/files/4pmgiGrQ8RgO0poB7Bkh" alt=""><figcaption></figcaption></figure>

## Card anatomy

Each metric card is broken into two primary sections: details (orange box) and chart (blue box). \
![](/files/sgJDRYYtbPVY4YCVmsD9)

The details section displays the metric id, metric name, current value, target value, change in current value from the prior measurement, and an indicator if the current value is on or off target. The color and arrow direction will be determined based on how you have the direction configured in the Excel Template.

The chart section displays the percent of target achieved from the last six measurements. Note that this chart does not display the actual measurement value. This is because multiple types of metrics with different y-axis are displayed on a single page. Plotting the actual values makes comparison difficult and can be difficult to read.&#x20;

## Configuring Metric Cards

You will need to select the metric you want to display on each card. Select the metric for both the details and chart sections by selecting the section and navigating to Filter Pane > "Filters on this visual" > "Metric ID" > Select metric. Ensure you are only selecting one metric, and that both the details and chart sections have the same metric selected.

{% embed url="<https://www.loom.com/share/451f9d185a6547a58cb89048179fb0b9>" %}

## Adding More Data Points

By default, the chart displays the most recent 6 measurements for the metric. You can configure this on a per-card basis by going to "filters" > "measurement date" and changing the "Top N" to the number of data points you want to display.&#x20;

{% embed url="<https://www.loom.com/share/2c910b687e604ac6873a4caea2b9fea5>" %}

## Resizing cards

Each card displays information for a single metric. The page has space for 8 metric cards. While you can resize the cards, it's recommended to use this layout for two primary reasons:

1. Size of cards often denotes importance. If you have some cards larger than others, they should either be more important, or the smaller cards should be breakdowns of the larger metric.
2. Smaller cards than the template size struggle to include enough information. For viewing more metrics on a single page, it's recommended to use the Metrics Matrix™.&#x20;

## Creating more pages

While there is only one Metric Cards page in the template, you will most likely want to create cards for more than eight metrics. In order to create more Metric Card pages, right click on the page tab at the bottom of the screen, click "duplicate". You can then rename the page. Note that the page will now appear in the top navigation.&#x20;

{% embed url="<https://www.loom.com/share/a8c1d6a96ad1453682241e8edadaed81>" %}

### Change Page Title and Subtitle

If you would like to replace the page title and subtitle text, click on the text box and in the format pane, select "General" > "Title" > "Text" and "General" > "Subtitle" > "Text".&#x20;

{% embed url="<https://www.loom.com/share/405b26f5dfda4d0fb8c228a654657de6>" %}


# Configuring Target Deviation Cards

The Target Deviation Cards page has a sample layout for displaying different security metrics.

<figure><img src="/files/AAjiRgjLtIjkPc6Rd19C" alt=""><figcaption></figcaption></figure>

## Card anatomy

Each variance card is broken into two primary sections: details (orange box) and chart (blue box). <br>

<figure><img src="/files/wZqyJitRALu0SKRaW9VD" alt=""><figcaption></figcaption></figure>

The details section displays the metric id, metric name, current value, target value, change in current value from the prior measurement, and an indicator if the current value is on or off target. The color and arrow direction will be determined based on how you have the direction configured in the Excel Template.

The chart section displays a target deviation chart which plots the metric's deviation from the target. Note that this chart does not display the actual measurement value, but the amount the measurement is above or below the target. The bar color is determined based on how the direction is configured in the Excel Template.

## Configuring Target Deviation Cards

You will need to select the metric you want to display on each card. Select the metric for both the details and chart sections by selecting the section and navigating to Filter Pane > "Filters on this visual" > "Metric ID" > Select metric. Ensure you are only selecting one metric, and that both the details and chart sections have the same metric selected.

{% embed url="<https://www.loom.com/share/3306d65eaf46435898a28db7a787af3b>" %}

## Resizing cards

Each card displays information for a single metric. The page has space for 8 metric cards. While you can resize the cards, it's recommended to use this layout for two primary reasons:

1. Size of cards often denotes importance. If you have some cards larger than others, they should either be more important, or the smaller cards should be breakdowns of the larger metric.
2. Smaller cards than the template size struggle to include enough information. For viewing more metrics on a single page, it's recommended to use the Metrics Matrix™.&#x20;

## Creating more pages

While there is only one Target Deviation Cards page in the template, you will most likely want to create cards for more than eight metrics. In order to create more Metric Card pages, right click on the page tab at the bottom of the screen, click "duplicate". You can then rename the page. Note that the page will now appear in the top navigation.&#x20;

{% embed url="<https://www.loom.com/share/95cb4068fec74b859c0408783f5b1b0a>" %}

### Change Page Title and Subtitle

If you would like to replace the page title and subtitle text, click on the text box and in the format pane, select "General" > "Title" > "Text" and "General" > "Subtitle" > "Text".&#x20;

{% embed url="<https://www.loom.com/share/f01560a9d6f24295929bce54db845202>" %}


# Metric Inventory

The Metrics Inventory page is a compact layout designed to present the entire security metrics inventory at a glance. This page includes both active, innactive, and retired metrics.

<figure><img src="/files/CRh06KVOS96IsMFltwh3" alt=""><figcaption></figcaption></figure>

### Filters

The Metric Inventory can be filtered by the following fields:

1. Active (Yes/No)
2. Metric Type
3. Metric Group

<figure><img src="/files/TEJX67BTDL89dJelZIcY" alt=""><figcaption></figcaption></figure>

### Metric Inventory Table

The metric inventory table has the following fields:

Metric ID, Active, Date Added, Metric, Purpose, Owner, Date Retired, Retirement Reason, Number of Measurements.&#x20;

Metrics are grouped based on the selected grouping in the "Group by" dropdown.&#x20;

<figure><img src="/files/ajjcFDLY8whfY2yj8TIa" alt=""><figcaption></figcaption></figure>


# Automation

While the Security Metrics Toolkit is designed for measurements to be manually updated in the Excel Template, the architecture of the toolkit allows for automating measurements as the program matures.&#x20;

## Data Format

Metric measurements must be in the same format as the Log sheet. *Metric ID, Value, and Measurement Date* are required fields, while *Notes* is optional. Below is an example of the format:

| Metric ID | Value | Measurement Date | Notes        |
| --------- | ----- | ---------------- | ------------ |
| M-01      | 0.8   | 1/1/2025         | Sample notes |
| M-01      | 0.85  | 2/1/2025         | Sample notes |
| M-02      | 2300  | 1/15/2025        | Sample notes |

## Metric Inventory Sheet

A metric must have both a record in the Metric Inventory as well as the Log. Ensure any Metric ID you are automating log measurements for has a corresponding record in the [Metric Inventory Sheet](/security-metrics-toolkit/powerbi-template/metric-inventory) of the Excel Template.

## Common Data Connectors

Data can be ingested into PowerBI from a variety of datasources. For the full list, see the [Microsoft Power Query Connector Documentation.](https://learn.microsoft.com/en-us/power-query/connectors/)  Below are some of the most common:

* Web APIs
  * [Connector: Web](https://learn.microsoft.com/en-us/power-query/connectors/web/web)
* Databases
  * SQL Server
  * Oracle
  * MySQL
  * PostgreSQL
  * Google BigQuery
  * Snowflake
  * Amazon Athena
* Azure
  * Azure Blob Storage
  * Azure Table Storage
  * Azure Cosmos DB
  * Azure Datalake Storage Gen2
  * Azure Databricks
* OData
* ODBC
* Micrososft Fabric
* Flat files
  * CSV
  * JSON
  * XML
  * Parquet

## Ingesting Data

It's recommended to build the above data format in the source system wherever possible, such as a database or data lake.&#x20;

To ingest new data into the PowerBI template, click "Get Data" and select the data connector you wish the use.&#x20;

{% embed url="<https://www.loom.com/share/91a1b7e6b169409781fbe25d85b57417>" %}

## Extract, Transform, & Load (ETL)

After connecting to your data source, click "transform" to use Power Query to format the data. Ensure the column names are properly named and you have the required columns.&#x20;

1\) If the table did not automatically set your headers, do so by clicking "Use First Row as Headers".

{% embed url="<https://www.loom.com/share/bf7137abd3bd402284efa2615430f33e>" %}

2\) If the table did not automatically set the Measurement Date to type Date, do so by right-clicking on the column > "Change Type" > "Date".&#x20;

{% embed url="<https://www.loom.com/share/2cd2643f2ce34f7788814a85bb09b3cd>" %}

3\) If the table did not automatically set the Value to type Decimal, do so by right-clicking on the column > "Change Type" > "Decimal Number".

{% embed url="<https://www.loom.com/share/db9c73849b244cd2abb7e12538338f70>" %}

4\) Set the name of the query.

{% embed url="<https://www.loom.com/share/12113b5e5e714c04afae45027ee73d28>" %}

We can now see we have 3 data queries and a parameter.

<figure><img src="/files/2IhkUbevuQGzOSsE6c5B" alt=""><figcaption></figcaption></figure>

You can ingest measurement log data from multiple systems in different queries. In order to integrate the new queries into the data model, we need to append the data into the Log table.&#x20;

5\) Click on the "Log" query, and then click "Append Queries" > "Append Queries". Do not append the data as a new query.&#x20;

Select the tables to append to the Log table, depending on how many queries you are pulling in.&#x20;

{% embed url="<https://www.loom.com/share/e5ce686ba6844cdc94b4bb7e53ec7437>" %}

6\) Click on "Close and Apply"

{% embed url="<https://www.loom.com/share/e9797d78908b4cccad8ebe413d458962>" %}


# NIST CSF 2.0 User Guide

SecureMetrics' NIST CSF 2.0 PowerBI Template allows security teams or consultants to report on the maturity of an organization against the NIST Cybersecurity Framework (CSF) version 2.0.

{% hint style="info" %}
Note: there are two license versions for the NIST CSF 2.0 Template: **Internal & Consultant**. There is **no difference between the template**, only the licensing terms.
{% endhint %}

## Getting Started

When you purchase the NIST CSF 2.0 PowerBI Template, you will receive a download with the following items:

1. PowerBI template file (.pbit)
2. Excel assessment input template (.xlsx)
3. Sample input Excel files (.xlsx)

The PowerBI template will use the Excel assessment input files to load assessment data into the dashboards. The PowerBI template will accept multiple assessment input files stored in a folder on the filesystem for continuous monitoring over time.

### Step 1 - Setting up the assessment input folder

You'll need to store all the assessment input files (.xlsx) that you wish to import into the dashboard in a single folder on the file system.&#x20;

1. Create a new folder on your computer in a convenient place such as "Documents"
2. Note the full filepath of the folder, as you'll be prompted for this when we load the PowerBI dashboard

{% embed url="<https://www.loom.com/share/60f5f595184a444c9ea2e55243a99c02?sid=db0365fb-cc68-4c9f-8f02-ed828eb20fb4>" %}
Setting up the assessment input folder
{% endembed %}

### Step 2 - Filling out the assessment input files

Each assessment date will utilize it's own excel input file. All input files stored in the folder you created will be ingested into the PowerBI dashboard. If you are just getting started, you may only have one assessment completed. However, over time you'll be able to monitor for changes over time as you add additional assessment files.

{% hint style="info" %}
Note: three sample assessment input files are included. You can move these to your assessment input folder if you would like to test functionality without creating assessment input files
{% endhint %}

1. Open the Excel assessment input file (.xlsx)
2. Fill out the required columns
3. Save the file into the assessment input folder

{% embed url="<https://www.loom.com/share/a9a9c2223dc74e6b915088255ea4eb24?sid=8d17aafe-a5ce-4bca-afa3-d761570fe472>" %}
Filling out the Excel assessment input file (.xlsx)
{% endembed %}

{% embed url="<https://www.loom.com/share/2f5fded2ad8f44eba9714775c10d9a5d?sid=7defadfc-bcd7-4d3d-85d6-06318a2081d5>" %}
Storing assessment files in the folder
{% endembed %}

### Step 3 - Loading the PowerBI Template

{% hint style="info" %}
Note: Three parameters are prompted for when opening the template. The first parameter is the full filepath of the data import folder. The remaining parameters, "Ignore" and "Also Ignore" should not be changed.
{% endhint %}

1. Open the PowerBI template file (.pbit)
2. You will be prompted to input the full filepath of the folder from step 1
3. Dashboards & datamodel will be populated with data
4. Save the file as a .pbix file to save the report

{% embed url="<https://www.loom.com/share/90c70f0b52474bbda77526f8833a3450?sid=0cbf3942-d674-405d-8c07-4dcd7a5cef75>" %}
Loading assessment data into PowerBI
{% endembed %}

That's it!&#x20;

You can now either use the dashboard locally in PowerBI Desktop, or publish to the PowerBI Service to host in the cloud.&#x20;


# Attack Surface Discovery User Guide

SecureMetrics' Attack Surface Discovery PowerBI Template allows security teams or consultants to report on their external-facing attack surface discovered using the [open-source tool OWASP Amass.](https://github.com/owasp-amass/amass)

{% hint style="info" %}
Note: there are two license versions for the Attack Surface Discovery Template: **Internal & Consultant**. There is **no difference between the template**, only the licensing terms.
{% endhint %}

## Getting Started

When you purchase the Attack Surface Discovery PowerBI Template, you will receive a download with the following items:

1. PowerBI template file (.pbit)
2. Sample database file (.sqlite)

The PowerBI template will connect to a local sqlite database to load data into the dashboards. This database is auto-generated by the discovery engine, Amass. Your purchase also includes a sample database for testing connectivity.

### Step 1 - Install and run Amass from OWASP

In order to use this template, you will need to install and run the open-source attack surface discovery tool Amass, by OWASP. Because the dashboards connect directly to the Amass database, there are few requirements on how you operate the tool.

You can install Amass in a variety of methods, as [described in their documentation.](https://github.com/owasp-amass/amass/blob/master/doc/install.md)

{% embed url="<https://www.loom.com/share/ede6375c6dc64fae951466c596709b27?sid=97898f29-cf8c-4da7-97df-0074b58a41e3>" %}

In order to populate the database, you'll need to run a discovery using Amass. Because the PowerBI template is pulling directly from the Amass Sqlite database, you can run multiple discoveries over time for continuous reporting.

There are many options to get the most out of Amass. However, the easiest way to get started is to run the following command:

```
amass enum -dir ./your-output-directory -d example.com
```

{% hint style="info" %}
Note: Make sure you use the -dir flag to denote the output directory for ease of management. You can choose to keep one central database, or create a new database for each discovery (such as different clients). If a database is already present in the output directory, Amass will append the results to it. If no database is present in the output directory, it will create a new one.
{% endhint %}

{% embed url="<https://www.loom.com/share/1e0531a7a9564deb9830cd435155934e?sid=6645f98d-a851-4434-a303-8bdba3dbfea3>" %}

### Step 2 - Install a SQlite ODBC driver on your device

Unfortunately, you cannot connect to a SQLite database by default in PowerBI. In order to accomplish this, you will need to download and install a SQLite ODBC driver such as this open-source one: <http://www.ch-werner.de/sqliteodbc/>&#x20;

### Step 3 - Copy the SQLite database file as path to clipboard

Locate the SQLite database file generated by Amass. It will be located in the output directory and defaults to the filename amass.sqlite.

{% embed url="<https://www.loom.com/share/b2234b2e7b59495183eea8a08a657a06?sid=a84de8bc-0a7e-4f25-8e39-e74e44436cdb>" %}
Copy the path to the generated SQLite database file
{% endembed %}

### Step 4 - Open the PowerBI Template and provide the SQLite database filepath when prompted

Whenever you open the PowerBI template file (.pbit), you will be prompted for the location of the SQLite database file. Paste the path, removing the quotations (") if present.&#x20;

{% embed url="<https://www.loom.com/share/afb65804cfc7422381520642907836fc?sid=d947b402-9d9e-4d5a-93d6-520dc80c53d7>" %}
Load data
{% endembed %}

That's it!&#x20;

You can now either use the dashboard locally in PowerBI Desktop, or publish to the PowerBI Service to host in the cloud.&#x20;


# Setup Guide

{% columns %}
{% column %}

<figure><img src="/files/0nxXc3WuX6nBrKff1LyP" alt=""><figcaption></figcaption></figure>
{% endcolumn %}

{% column %}

<figure><img src="/files/4ljDtwEShIqoUkDnUPe9" alt=""><figcaption></figcaption></figure>
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column %}

<figure><img src="/files/hYKzWDDfpN27eSz36cs7" alt=""><figcaption></figcaption></figure>
{% endcolumn %}

{% column %}

<figure><img src="/files/ZbWj7CrCaw01bAdABhq3" alt=""><figcaption></figcaption></figure>
{% endcolumn %}
{% endcolumns %}

## Contents

The Risk Register Template contains two files:

1. Risk Register Excel Template (.xlxs)
2. Risk Register PowerBI Template (.pbit)

The Risk Register Template comes preloaded with demo data, meaning you can hook it up to the PowerBI template right away. Keep in mind, you will need to replace the content of the Excel file to load in your actual data.&#x20;

{% hint style="info" %}
Note: This quick start guide assumes you already have Microsoft PowerBI Desktop installed. If you do not, you can download it free from Microsoft.
{% endhint %}

## 1) Host the Excel Template in Cloud Storage

{% hint style="warning" %}
You will need to fill out the Excel Template: [Documentation](/security-metrics-toolkit/excel-template)
{% endhint %}

Upload the Excel Template to one of the following cloud storage solutions:

* Microsoft Teams
* Microsoft SharePoint
* Microsoft OneDrive&#x20;

### File Path

{% hint style="warning" %}
The file path is not the URL or link to the file
{% endhint %}

After, note the path to reach the file. [The easiest way to find this is by opening the Excel Template in the desktop application.](/security-metrics-toolkit/excel-template#excel-workbook-path) Ensure you are opening the file from the cloud storage location and not the local device.&#x20;

{% embed url="<https://www.loom.com/share/40df0093875748a489ced69dd7ea0a96>" %}

Then, in the Excel desktop application, go to "File" > "Recent" > Right click on the file > "Copy path to clipboard."

Paste the copied path into a text editor and remove the suffix "?web=1" so that the path ends with the file extension.&#x20;

{% embed url="<https://www.loom.com/share/4ba40a32be6a4ccaa808bdcc0c98a88e>" %}

## 2) Open the PowerBI Template

{% hint style="warning" %}
Ensure you removed the suffix "?web=1" from the path before entering it into PowerBI.&#x20;
{% endhint %}

Navigate to the PowerBI Template file (.pbit) and open it in Microsoft PowerBI Desktop. After opening, PowerBI will prompt you for the filepath we gathered in step 1. Paste the filepath and click okay. PowerBI will then load in and transform the data.&#x20;

{% embed url="<https://www.loom.com/share/cd6064ce3c464bf6bc56c6a5eab7e4ec>" %}

## 3) Save the PowerBI Report

Go to "file" > "save as" and save the PowerBI report. This will save it as a .pbix file. If you want to setup another security metrics report, simply repeat the first two steps.&#x20;


# Excel Template

The data for the Risk Register Power BI Report is pulled from the Risk Register Excel Template. The Excel template is stored in a cloud location for easy automated refresh and to act as a collaborative source-of-truth. The Excel template has the following columns:

<table><thead><tr><th>Column</th><th>Description</th><th>Example</th><th data-type="checkbox">Required</th></tr></thead><tbody><tr><td>Risk ID</td><td>Unique identifier for the risk row.</td><td>M-01</td><td>true</td></tr><tr><td>Risk Description</td><td>Plain-language description of the risk.</td><td>Yes</td><td>true</td></tr><tr><td>Risk Category</td><td>Category, e.g. Endpoint Security, Cloud Security, Compliance.</td><td>08/26/2025</td><td>false</td></tr><tr><td>Date Opened</td><td>When the risk was first recorded.</td><td>08/31/2025</td><td>false</td></tr><tr><td>Risk Decision Date</td><td>When a treatment decision was made.</td><td>Implementation</td><td>false</td></tr><tr><td>Date Last Updated</td><td>Most recent modification date.</td><td>Percent of workstations covered by endpoint detection and response (EDR)</td><td>true</td></tr><tr><td>Risk Owner (Individual)</td><td>Name of the person accountable for the risk.</td><td>Endpoint Security</td><td>false</td></tr><tr><td>Inherent Risk Probability</td><td>1–5 scale text, e.g. <code>4 - Likely</code> (see Section 7).</td><td>Implementation of EDR</td><td>false</td></tr><tr><td>Inherent Risk Impact</td><td>1–5 scale text, e.g. <code>5 - Severe</code> (see Section 7).</td><td>Number of workstations covered by EDR / Total workstations</td><td>false</td></tr><tr><td>Target Risk Probability</td><td>1–5 scale text. Probability after planned controls.</td><td>0.95</td><td>true</td></tr><tr><td>Target Risk Impact</td><td>1–5 scale text. Impact after planned controls.</td><td>14</td><td>true</td></tr><tr><td>Risk Response Type</td><td>One of: <code>Mitigate</code>, <code>Accept</code>, <code>Transfer</code>, <code>Avoid</code>.</td><td>Mitchell Telatnik</td><td>false</td></tr><tr><td>Risk Response Controls</td><td>Free-text description of the planned controls.</td><td>CrowdStrike, CMDB</td><td>false</td></tr><tr><td>Risk Response Due Date</td><td>Deadline for the response action.</td><td>Percentage</td><td>true</td></tr><tr><td>Cost of Mitigations</td><td>Estimated cost in your currency unit.</td><td>Higher</td><td>true</td></tr><tr><td>Compensating Controls</td><td>One of: <code>Full</code>, <code>Partial</code>, <code>None</code>.</td><td>02/15/2026</td><td>false</td></tr><tr><td>Residual Risk Probability</td><td>1–5 scale text. Actual probability after controls.</td><td>Not driving actionable value</td><td>false</td></tr><tr><td>Residual Risk Impact</td><td>1–5 scale text. Actual impact after controls.</td><td></td><td>false</td></tr><tr><td>Risk Status</td><td>One of: <code>Open</code>, <code>Closed</code>.</td><td></td><td>false</td></tr><tr><td>Notes</td><td>Free-text additional notes.</td><td></td><td>false</td></tr></tbody></table>

### Adding Columns

You can additional columns to the end of the table to capture additional details related to risks. When loaded into the Power BI Template, these columns will carry through into the data model for you to use, however they will not appear as a filter or in visuals out of the box and must be customized.


# Power BI Template

After setting up the Power BI Template, you will notice the following pages:

<table data-card-size="large" data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden></th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/I1V0RgMafROf6b44HPM2">/pages/I1V0RgMafROf6b44HPM2</a></td><td>Dashboard</td><td><a href="/files/0nxXc3WuX6nBrKff1LyP">/files/0nxXc3WuX6nBrKff1LyP</a></td><td><a href="/pages/F8rTbqmxPlH2lq9pmNDv">/pages/F8rTbqmxPlH2lq9pmNDv</a></td></tr><tr><td><a href="/pages/8X1ybLSayrWbOzGpQ162">/pages/8X1ybLSayrWbOzGpQ162</a></td><td>Risk Response</td><td><a href="/files/4ljDtwEShIqoUkDnUPe9">/files/4ljDtwEShIqoUkDnUPe9</a></td><td><a href="/pages/S8zeqZ8bXH99SndInmjP">/pages/S8zeqZ8bXH99SndInmjP</a></td></tr><tr><td><a href="/pages/FYKsZ9KbUObgJ8HKXEBA">/pages/FYKsZ9KbUObgJ8HKXEBA</a></td><td>Cumulative Risk</td><td><a href="/files/hYKzWDDfpN27eSz36cs7">/files/hYKzWDDfpN27eSz36cs7</a></td><td><a href="/pages/jM2xdpbWvEh7ojfQV5yZ">/pages/jM2xdpbWvEh7ojfQV5yZ</a></td></tr><tr><td><a href="/pages/M78kqHHEJgTUAo0ajjRY">/pages/M78kqHHEJgTUAo0ajjRY</a></td><td>Risk Register</td><td><a href="/files/ZbWj7CrCaw01bAdABhq3">/files/ZbWj7CrCaw01bAdABhq3</a></td><td><a href="/pages/KHSd7WEEQ8KiYZxTOdJb">/pages/KHSd7WEEQ8KiYZxTOdJb</a></td></tr></tbody></table>


# Dashboard

The Dashboard page is a high-level overview of your risk register.&#x20;

<figure><img src="/files/0nxXc3WuX6nBrKff1LyP" alt=""><figcaption></figcaption></figure>

### Risk Matrix

The Risk Matrix is a traditional qualitative risk matrix, plotting Impact on the x-axis and probability on the y-axis.

<figure><img src="/files/MT91SDwiBfxAH5FDEGcw" alt=""><figcaption></figcaption></figure>

The following options can be customized on the Risk Matrix:

* Matrix size (3x3, 5x5, etc)
* Axis titles (Impact, Probability)
* Legend titles (Minimal, Marginal, Significant, etc)
* Risk Banding (Number of risk levels and thresholds)
* Risk colors
* Axis labels (1, 2, 3, etc.)

The Risk Matrix will display the count of risks that fall into each cell of the matrix. Clicking on a cell will cross-filter the entire dashboard to only the risks within that cell.&#x20;

The three buttons above the Risk Matrix enable you to switch between plotting risks by their inherent, residual, or target risk.

### Total Risk Priority Bar Chart

The total risk priority bar chart plots the total inherent, residual, and target risk by a categorical field.&#x20;

<figure><img src="/files/bNNBWGEeyPpMhTz4nMog" alt=""><figcaption></figcaption></figure>

The category being plotted by (the y-axis) can be changed using the drop down in the top right of the visual. The bar chart can be plotted by the following fields:

* Risk Status
* Risk Response Type
* Risk Category
* Risk Owner (Individual)
* Compensating Controls

<figure><img src="/files/678SLuug7QxRjW9swkGx" alt=""><figcaption></figcaption></figure>

### Count of Risks Donut Chart

The count of risks donut chart plots the number of risks by a categorical field.&#x20;

<figure><img src="/files/huvJgV5yxkhuPOXJnOoH" alt=""><figcaption></figcaption></figure>

The category being plotted by can be changed using the drop down in the top right of the visual. The donut chart can be plotted by the following fields:

* Compensating Controls
* Risk Response Type
* Risk Status

<figure><img src="/files/exhO8vKDhuNwiNdlXjma" alt=""><figcaption></figcaption></figure>

&#x20;


# Risk Response

The Risk Response page shows the distribution of risk by the selected risk response types.

<figure><img src="/files/4ljDtwEShIqoUkDnUPe9" alt=""><figcaption></figcaption></figure>

## Risk Response Sankey Diagram

The Risk Response Sankey Diagram is the primary visual for this page. It plots a categorical field on the left and the risk response categories on the right, connecting each with streams. The size of the stream represents the total risk priority from each category.&#x20;

<figure><img src="/files/kVoyB5HZQbU0bsgSSccB" alt=""><figcaption></figcaption></figure>

The categorical field plotted by (left-hand side) can be changed using the drop down in the top right of the visual. The following categories can be selected:

* Risk Category
* Risk Owner (Individual)
* Compensating Controls
* Risk Status
* Inherent Risk Impact
* Inherent Risk Probability
* Residual Risk Impact
* Residual Risk Probability
* Target Risk Impact
* Target Risk Probability

<figure><img src="/files/MlT5NpA0gpFAK9YdVDXB" alt=""><figcaption></figcaption></figure>


# Cumulative Risk

The Cumulative Risk page shows the cumulative (total) risk over time by various date fields.

<figure><img src="/files/hYKzWDDfpN27eSz36cs7" alt=""><figcaption></figcaption></figure>

## Cumulative Risk Step Chart

{% hint style="info" %}
A step chart plots values that stay constant between changes and "step" up or down only when an event occurs, making it ideal for showing running totals or state changes over time.
{% endhint %}

The cumulative risk step chart plots the cumulative (running total) risk priority over time based on various dates.&#x20;

<figure><img src="/files/cxpLNKVbkVyld47aiVtq" alt=""><figcaption></figcaption></figure>

The date field plotted by (x-axis) can be changed using the drop down in the top right of the visual. The following dates can be selected:

* Date Last Updated
* Date Opened
* Risk Decision Date

<figure><img src="/files/xMBw4EZ2GAFRyFgNYJjk" alt=""><figcaption></figcaption></figure>


# Risk Register

The risk register page shows the detailed risk register as a table.&#x20;

<figure><img src="/files/0Y0mTlmP8dCS3AY7WxqF" alt=""><figcaption></figcaption></figure>

### Risk Register Table

The risk register table is a detailed, tabular layout for viewing the risk register.   &#x20;

<figure><img src="/files/81cMtowcFnkGxJSUxolD" alt=""><figcaption></figcaption></figure>

The Risk Register table has the following columns:

* Risk ID
* Date Opened
* Date Last Updated
* Risk Status
* Risk Description
* Risk Category
* Risk Owner
* Inherent Risk Probability
* Inherent Risk Impact
* Inherent Risk Priority
* Target Risk Probability
* Target Risk Impact
* Target Risk Priority
* Risk Response Type
* Risk Response Controls
* Risk Response Due Date
* Cost of Mitigations
* Compensating Controls
* Residual Risk Probability
* Redisual Risk Impact
* Residual Risk Priority
* Notes


# Welcome to Astra

Large-Scale Network Graph Visualization in PowerBI

{% embed url="<https://www.youtube.com/watch?v=p6Lg-cu0mYk>" %}

Astra is a Power BI visual built to transform your network data into interactive, insightful graphs.&#x20;

Astra enables you to:

* **Visualize Complex Networks:** Seamlessly render thousands of nodes and edges.
* **Interact in Real-Time:** Zoom, pan, and dive deep into your network to uncover hidden patterns.
* **Customize Your View:** Tailor visual properties and interactivity to suit your unique needs.
* **Integrate Effortlessly:** Embed directly within your Power BI reports for a unified analytical experience.

## Getting Started

Follow these simple steps to begin using Astra in your Power BI projects:

1. **Import into Power BI:**
   * Open Power BI Desktop or a report in the PowerBI Service
   * In the **Visualizations** pane, click the ellipsis (…) and select **Get more visuals**.
   * Download & load Astra to your PowerBI report
2. **Configure Your Data:**
   * Drag the Astra visual onto your report canvas.
   * Map your dataset fields to the corresponding properties in the visual’s settings panel.
3. **Customize Your Visualization:**
   * Use the customization options to adjust the appearance and interactivity of your network graph.
   * Explore advanced settings to fine-tune performance and visual details.
4. **Explore & Analyze:**
   * Interact with your network graph to uncover insights and patterns that drive data-driven decisions.

## Mapping Data

Data passed into Astra should be in a tabular edge list format:

| Data Field   | Description                   | Required | Data Type |
| ------------ | ----------------------------- | -------- | --------- |
| Source Node  | The starting node of the edge | Yes      | Text      |
| Target Node  | The ending node of the edge   | Yes      | Text      |
| Source Color | Category node property        | No       | Text      |
| Target Color | Category node property        | No       | Text      |
| Link Color   | Category edge property        | No       | Text      |
| Source X     | X coordinate for source node  | No       | Integer   |
| Source Y     | Y coordinate for source node  | No       | Integer   |
| Target X     | X coordinate for target node  | No       | Integer   |
| Target Y     | Y coordinate for target node  | No       | Integer   |
| Source Label | Label text for source node    | No       | Text      |
| Target Label | Label text for target node    | No       | Text      |

## Support Requests

Email support is available by reaching out to: **<astra@securemetrics.io>**


# Release Notes

Release notes for updates to Astra PowerBI Plugin

## Astra Version 1.0.1.0

#### Release Date: February 12, 2025&#x20;

{% hint style="info" %}
Astra may take up to 2 weeks after release to update in your instance of PowerBI. This timeline is out of our control and up to Microsoft: [Microsoft Publishing Timelines](https://learn.microsoft.com/en-us/power-bi/developer/visuals/power-bi-custom-visuals-certified#publication-timeline)
{% endhint %}

**Synopsis:** Fixed licensing API and label settings.

| Bug Fixes                                                                                 |
| ----------------------------------------------------------------------------------------- |
| Fixed bug in license API where visual would be blocked despite having purchased a license |
| Fixed bug where label settings in the formatting pane would not apply to the visual       |

| New Features |
| ------------ |
| None         |


# PowerBI Visual Architecture and Data Security

Astra is a Power BI visual plugin that runs **100% locally** in your Power BI environment. It does **not transmit, upload, or sync data** to any external servers. This design allows Astra to be safely deployed in sensitive or air-gapped environments.

## How Astra Works

* **Runs inside Power BI**: Astra executes entirely within Power BI’s built-in sandbox for custom visuals. No separate application or service is involved.
* **Receives data from Power BI only**: It visualizes data passed to it from the Power BI semantic model—nothing else.
* **In-memory rendering**: All data transformations and graph rendering happen in memory and are never written to disk or sent over the network.

## Network Communication

Astra makes **no network calls**. This includes:

| Activity                    | Status                                 |
| --------------------------- | -------------------------------------- |
| API requests (`fetch`, XHR) | ❌ Not used                             |
| WebSocket connections       | ❌ Not used                             |
| Telemetry or analytics      | ❌ Not used                             |
| CDN-hosted scripts          | ❌ Not used (all libraries are bundled) |
| File or disk storage        | ❌ Not used                             |

## Architecture Diagram

The diagram below illustrates Astra’s local execution model within the Power BI environment.

<figure><img src="/files/ttMwtVdNayoAhTu74jEF" alt=""><figcaption></figcaption></figure>


# Multi Cloud CIS Benchmarks with Prowler

Report on compliance maturity against the CIS Benchmarks across AWS, Azure, GCP, and Kubernetes.

{% hint style="info" %}
This template requires either Prowler Cloud or the open source Prowler CLI
{% endhint %}

![Prowler Report](https://github.com/user-attachments/assets/560f7f83-1616-4836-811a-16963223c72f)

### Getting Started

1. Install Microsoft PowerBI Desktop

   This report requires the Microsoft PowerBI Desktop software which can be downloaded for free from Microsoft.
2. Run compliance scans in Prowler

   The report uses compliance csv outputs from Prowler. Compliance scans be run using either [Prowler CLI](https://docs.prowler.com/projects/prowler-open-source/en/latest/#prowler-cli) or [Prowler Cloud/App](https://cloud.prowler.com/sign-in)

   1. Prowler CLI -> Run a Prowler scan using the --compliance option
   2. Prowler Cloud/App -> Navigate to the compliance section to download csv outputs![Download Compliance Scan](https://github.com/user-attachments/assets/42c11a60-8ce8-4c60-a663-2371199c052b)

   The template supports the following CIS Benchmarks only:

   | Compliance Framework                           | Version |
   | ---------------------------------------------- | ------- |
   | CIS Amazon Web Services Foundations Benchmark  | v4.0.1  |
   | CIS Google Cloud Platform Foundation Benchmark | v3.0.0  |
   | CIS Microsoft Azure Foundations Benchmark      | v3.0.0  |
   | CIS Kubernetes Benchmark                       | v1.10.0 |

   Ensure you run or download the correct benchmark versions.
3. Create a local directory to store Prowler csvoutputs

   Once downloaded, place your csv outputs in a directory on your local machine. If you rename the files, they must maintain the provider in the filename.

   To use time-series capabilities such as "compliance percent over time" you'll need scans from multiple dates.
4. Download and run the PowerBI template file (.pbit)

   Running the .pbit file will open PowerBI Desktop and prompt you for the full filepath to the local directory
5. Enter the full filepath to the directory created in step 3

   Provide the full filepath from the root directory.

   Ensure that the filepath is not wrapped in quotation marks (""). If you use Window's "copy as path" feature, it will automatically include quotation marks.
6. Save the report as a PowerBI file (.pbix)

   Once the filepath is entered, the template will automatically ingest and populate the report. You can then save this file as a new PowerBI report. If you'd like to generate another report, simply re-run the template file (.pbit) from step 4.

### Validation

After setting up your dashboard, you may want to validate the Prowler csv files were ingested correctly. To do this, navigate to the "Configuration" tab.

The "loaded CIS Benchmarks" table shows the supported benchmarks and versions. This is defined by the template file and not editable by the user. All benchmarks will be loaded regardless of which providers you provided csv outputs for.

The "Prowler CSV Folder" shows the path to the local directory you provided.

The "Loaded Prowler Exports" table shows the ingested csv files from the local directory. It will mark files that are treated as the latest assessment with a green checkmark.

![Prowler Validation](https://github.com/user-attachments/assets/a543ca9b-6cbe-4ad1-b32a-d4ac2163d447)

### Report Sections

The PowerBI Report is broken into three main report pages

| Report Page | Description                                                                         |
| ----------- | ----------------------------------------------------------------------------------- |
| Overview    | Provides general CIS Benchmark overview across both AWS, Azure, GCP, and Kubernetes |
| Benchmark   | Provides overview of a single CIS Benchmark                                         |
| Requirement | Drill-through page to view details of a single requirement                          |

#### Overview Page

The overview page is a general CIS Benchmark overview across both AWS, Azure, GCP, and Kubernetes.

![image](https://github.com/user-attachments/assets/94164fa9-36a4-4bb9-890d-e9a9a63a3e7d)

The page has the following components:

| Component                                | Description                                                              |
| ---------------------------------------- | ------------------------------------------------------------------------ |
| CIS Benchmark Overview                   | Table with benchmark name, Version, and overall compliance percentage    |
| Provider by Requirement Status           | Bar chart showing benchmark requirements by status by provider           |
| Compliance Percent Heatmap               | Heatmap showing compliance percent by benchmark and profile level        |
| Profile level by Requirement Status      | Bar chart showing requirements by status and profile level               |
| Compliance Percent Over Time by Provider | Line chart showing overall compliance perecentage over time by provider. |

#### Benchmark Page

The benchmark page provides an overview of a single CIS Benchmark. You can select the benchmark from the dropdown as well as scope down to specific profile levels or regions.

![image](https://github.com/user-attachments/assets/34498ee8-317b-4b81-b241-c561451d8def)

The page has the following components:

| Component                               | Description                                                                                                                                |
| --------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
| Compliance Percent Heatmap              | Heatmap showing compliance percent by region and profile level                                                                             |
| Benchmark Section by Requirement Status | Bar chart showing benchmark requirements by bennchmark section and status                                                                  |
| Compliance percent Over Time by Region  | Line chart showing overall compliance percentage over time by region                                                                       |
| Benchmark Requirements                  | Table showing requirement section, requirement number, reuqirement title, number of resources tested, status, and number of failing checks |

#### Requirement Page

The requirement page is a drill-through page to view details of a single requirement. To populate the requirement page right click on a requiement from the "Benchmark Requirements" table on the benchmark page and select "Drill through" -> "Requirement".

![image](https://github.com/user-attachments/assets/5c9172d9-56fe-4514-b341-7e708863fad6)

The requirement page has the following components:

| Component                                  | Description                                                                       |
| ------------------------------------------ | --------------------------------------------------------------------------------- |
| Title                                      | Title of the requirement                                                          |
| Rationale                                  | Rationale of the requirement                                                      |
| Remediation                                | Remedation guidance for the requirement                                           |
| Region by Check Status                     | Bar chart showing Prowler checks by region and status                             |
| Resource Checks for Benchmark Requirements | Table showing Resource ID, Resource Name, Status, Description, and Prowler Checkl |

### Walkthrough Video

[![image](https://github.com/user-attachments/assets/866642c6-43ac-4aac-83d3-bb625002da0b)](https://www.youtube.com/watch?v=lfKFkTqBxjU)


# Getting Started

The journey to streamlining your CIS Critical Security Controls assessments with\
SecureMetrics starts here. This section is your roadmap to getting the CIS Critical Security\
Controls PowerBI Template up and running. Whether you are a novice at PowerBI or a\
seasoned expert, we have made sure that the setup process is as straightforward as\
possible.

Our aim is to get you operational with minimal fuss, so you can focus on what you do\
best—providing top-notch cybersecurity assessments. Let's get started!

## System Requirements

To use the CIS Critical Security Controls PowerBI Template effectively, you'll need:

* PowerBI Desktop
  * Download PowerBI Desktop here
* Windows Operating System
  * PowerBI Desktop is only compatible with Windows. Mac users will need to virtualize Windows.
* Microsoft Excel
  * Used to manage the data import file
  * If you do not have access to Microsoft Excel, you can use software such as Google Sheets that can export .xlsx files

## Template Setup

{% hint style="info" %}
The CIS Controls Reporting Suite contains both a PowerBI Dashboard Template as well as a PowerBI Slide Deck Template. The process for both of these templates is identical.&#x20;
{% endhint %}

### Step 1: Install PowerBI Desktop

If you haven't already, you'll need to download and install PowerBI Desktop to use this\
template. Download PowerBI Desktop here.

### Step 2: Prepare the Excel Import File

Before opening the PowerBI template, make sure you've filled out the accompanying Excel\
import file with the assessment data. This data will be used to populate the dashboard or slide deck.

### Step 3: Open the PowerBI Template

Locate the PowerBI template file (.pbit) that you received from Securemetrics.\
Double-click to open it with PowerBI Desktop.

### Step 4:&#x20;

Upon opening the template, you will be prompted to enter the full file path to the Excel\
import file. This is the location where your filled-out Excel file is saved on your computer.

For example:

```
C:\Users\YourName\Documents\SecureMetrics CIS Critical Security Controls Data
Import.xlsx
```

### Step 5: Data Loading and Report Population

After providing the path to the Excel import file, PowerBI will automatically load the data.\
Your dashboard will populate based on this data.

### Step 6: Save Your Assessment

To save this specific assessment, go to File > Save As in PowerBI Desktop and save the file\
as a PowerBI Desktop report file (.pbix).

### Step 7: Celebrate

Congratulations, your CIS Critical Security Controls PowerBI Template is now set up and\
ready to use!


# Assessment & Data Import File

The data you collect and input into the Excel data import file serves as the foundation for&#x20;your CIS Critical Security Controls assessment in PowerBI.&#x20;

The Excel data import file will serve as the data source for the PowerBI dashboard. Ensure that you update the pre-populated demo data in the *Policy Defined, Control&#x20;Implemented, Control Automated or Technically Enforced, Control Reported to Business*, and&#x20;*Target Score* columns based on your actual assessment before importing the data into&#x20;PowerBI.

The&#x20;Excel sheet has the following columns, some of which are pre-populated:

| Column                                    | Description                                                 | Type                          |
| ----------------------------------------- | ----------------------------------------------------------- | ----------------------------- |
| Control Number                            | The number of the CIS Control                               | Pre-populated (Do not change) |
| Control Name                              | The name of the CIS Control                                 | Pre-populated (Do not change) |
| ID                                        | The ID of the safeguard                                     | Pre-populated (Do not change) |
| CIS Control Detail                        | The detail of the safeguard                                 | Pre-populated (Do not change) |
| Implementation Group                      | The lowest implementation group of the safeguard            | Pre-populated (Do not change) |
| Policy Defined                            | Assessed policy compliance status                           | Single-select                 |
| Control Implemented                       | Assessed implementation status                              | Single-select                 |
| Control Automated or Technically Enforced | Assessed automation and enforcement status                  | Single-select                 |
| Control Reported to Business              | Assessed control reporting status                           | Single-select                 |
| Target Score                              | Target score for the safeguard                              | Numeric (0-4)                 |
| In-scope                                  | Whether or not the safeguard is in scope for the assessment | Yes/No                        |

## Scoring

The assessment's scoring is based on the selected values for *Policy Defined, Control Implemented, Control Automated or Technically Enforced,* and *Control Reported to Business.*

### Policy Defined

Pre-populated with demo data, this column is where you'll indicate the&#x20;assessed policy compliance status for the associated sub-control. Each status maps to a 0-4&#x20;numeric score for that category.&#x20;

**Choose from the following single-select options:**

* Approved Written Policy (4)
* Written Policy (3)
* Partial Written Policy (2)
* Informal Policy (1)
* No Policy (0)

### Control Implemented

Pre-populated with demo data, this column is where you'll indicate&#x20;the implementation status for the associated safeguard. Each status maps to a 0-4&#x20;numeric score for that category.&#x20;

**Choose from the following single-select options:**&#x20;

* Implemented on All Systems (4)
* Implemented on Most Systems (3)
* Implemented on Some Systems (2)
* Parts of Policy Implemented (1)
* Not Implemented (0)

### Control Automated or Technically Enforced

Pre-populated with demo data, this column&#x20;is where you'll indicate if the safeguard is enforced technically or otherwise automated.&#x20;Each status maps to a 0-4 numeric score for that category.&#x20;

**Choose from the following&#x20;single-select options:**

* Automated on All Systems (4)
* Automated on Most Systems (3)
* Automated on Some Systems (2)
* Parts of Policy Automated (1)
* Not Automated (0)

Some safeguards cannot be automated or technically enforced. These controls have been\
marked as “Not Applicable” and should not be changed.

### Control Reported to Business

Pre-populated with demo data, this column is where you'll&#x20;indicate if the safeguard is reported back to the business. Each status maps to a 0-4&#x20;numeric score for that category.&#x20;

**Choose from the following single-select options:**

* Reported on All Systems (4)
* Reported on Most Systems (3)
* Reported on Some Systems (2)
* Parts of Policy Reported (1)
* Not Reported (0)

Some safeguards cannot be automated or technically enforced. These controls have been\
marked as “Not Applicable” and should not be changed.

### Target Score

Pre-populated with demo data, this is a numeric field where you can set the&#x20;target score for that safeguard on a 0-4 scale. This will be used to compare the assessed&#x20;score for each sub-control against what the organization is looking to achieve.

### Importing the Data into PowerBI

After filing out the Excel sheet:

1. Save the Excel file in a location you can easily access
2. Open the PowerBI template
3. When prompted, enter the full filepath to the saved Excel file
4. Your PowerBI dashboard will automatically populate based on the data


# PowerBI Slide Template

Included in the CIS Controls Reporting Suite is the PowerBI Slide Template. This template is designed to be used as a presentation slide deck, and not a dashboard or "live" report.&#x20;

To setup the PowerBI Slide Template, follow the process in the "Getting Started" section.&#x20;

## Editing the slides

The Slide Template comes with 40 pre-made slides for you to use in your presentation.

The slides are fully editable and include space for you to include text such as descriptions, observations or recommendations.&#x20;

### Edit titles and subtitles

Some text on the slides use the "title" and "subtitle" feature in PowerBI. To edit these, click on the text  and then navigate to "format shape" > "general" > "title".

<figure><img src="/files/4c6tkKxHJBB8rZDff0wn" alt=""><figcaption></figcaption></figure>

### Edit body text

Some text on the slides, such as Recommendations, use body text. To edit this text, double click in the text error to bring up the rich text editor.&#x20;

<figure><img src="/files/QOaJteGU8vGEpuOZIjqb" alt=""><figcaption></figcaption></figure>

### Edit logo

The slides come with the Securemetrics logo. To add your own, click on "Insert" > "Image". You can position the logo on slide and then copy - paste to avoid repositioning it on every slide.&#x20;

### Edit Charts

All charts on the slides are editable. Simply click on the chart to change properties, chart type, and fields.

<figure><img src="/files/fBQ3GGLzM6XmiXrIimtr" alt=""><figcaption></figcaption></figure>

## Save your slide deck

It's highly recommended to save the slide deck as a .pbix file by going to "File" > "Save". This will allow you to reopen the PowerBI file and will save any changes you make.&#x20;

## Save an edited template

If you make changes to the slides, such as updating the logo, you may want to apply these changes to the template file so they persist across all generated slide decks. To do this, go to "Export" > "PowerBI Template" to save a new template file.&#x20;

## Export to PDF

{% hint style="info" %}
PowerBI adds white borders to exported PDF files. This behavior cannot be changed.
{% endhint %}

To export your slides to PDF, go to "Export" > "PDF". PowerBI will take a moment to render each page and then open a PDF file in your default browser. Make sure to download the PDF file from within the Browser.&#x20;

You can also export to PDF when hosted in the PowerBI SaaS service, known as the "PowerBI Service".&#x20;

## Embed in Microsoft PowerPoint

Alternatively, you can embed a live version of the slides to Microsoft PowerPoint.&#x20;

This requires the slides be hosted in the PowerBI SaaS service, known as the "PowerBI Service":

1. Click on "Home" > "Publish" and select a workspace.&#x20;
2. Open the slides in the PowerBI Service
3. Click on "Export" > "PowerPoint"

<figure><img src="/files/xK6KQmf3I51BtVkMays2" alt=""><figcaption></figcaption></figure>

You can either embed as live data or images. Exporting as live data will only export the current selected slide. Exporting as images gives you the option to export the entire slide deck.&#x20;

#### Embed from within PowerPoint

You can also embed a slide from within Microsoft PowerPoint by clicking on "Insert" > "PowerBI".&#x20;

{% embed url="<https://www.loom.com/share/735b155fbbea406aadd272de20a930ba?sid=54474aa9-4008-45eb-a869-10bb4987a99b>" %}


# Welcome to CRQ Community

A free, single-scenario FAIR modeling template built by Securemetrics.

<figure><img src="/files/XzGoUy7lQ0SdKs35l8aB" alt=""><figcaption></figcaption></figure>

## Why this exists

Quantifying cyber risk is hard. The Securemetrics CRQ Community Edition makes it easier by giving individuals, learners, and curious teams a clean, structured starting point.

Whether you're exploring FAIR for the first time or building out internal skills before investing in a full solution, this edition is designed to help you **model one scenario at a time** using clear inputs, strong visuals, and transparent assumptions.

## What you'll find in this documentation

**How to use the template**\
Step-by-step instructions for entering parameters and interpreting results.

**Common questions & troubleshooting**\
Fix errors, adjust inputs, or explore how to extend the model.

## Licensing

This Community Edition is licensed for **personal and educational use only**.\
Commercial or client-facing use requires a Pro license.


# Using the Template

## One-Time Setup (Required)

{% hint style="warning" %}
The template requires a Windows Operating System with PowerBI Desktop, Python, and the pyfair Python library installed
{% endhint %}

1. **Download Microsoft PowerBI Desktop**

If you don't already have it, you'll need to download the [free Microsoft PowerBI Desktop application.](https://www.microsoft.com/en-us/power-platform/products/power-bi/downloads)

2. **Install the Python Programing Language**

The template runs Python code to perform the risk analysis. You'll need to install Python if you don't already have it.&#x20;

You can download Python from the [Python website.](https://www.python.org/)

3. **Install python libraries**

You'll need the following Python libraries installed. It's recommended to use the pip installer to easily install them.

* [Pandas](https://pandas.pydata.org/) is a software library for data manipulation and analysis. Pandas offers data structures and operations for manipulating numerical tables and time series. To import into Power BI, Python data must be in a [pandas data frame](https://www.tutorialspoint.com/python_pandas/python_pandas_dataframe.htm). A data frame is a two-dimensional data structure, such as a table with rows and columns.
* [Pyfair](https://github.com/Hive-Systems/pyfair) is a software library for computing FAIR monte carlo simulations. This is the core library performing the computations for the risk modeling.

```
pip install pandas
pip install pyfair
```

4. Enable Python Scripting

You'll need to enable python scripting in the PowerBI Desktop Application before using the template.&#x20;

Go to File > Options and settings > Options > Python scripting.&#x20;

<figure><img src="/files/sq7zLZ4px44pJ1X7L0o4" alt=""><figcaption></figcaption></figure>

Ensure you have the correct home directory selected and select "ok".

For troubleshooting and additional information see[ "Run Python scripts" in the Microsoft Documentation.](https://learn.microsoft.com/en-us/power-bi/connect-data/desktop-python-scripts)

## 2. Entering Your Scenario Inputs

When you open the Power BI template, you’ll see a **parameter popup** prompting you to enter values for your scenario. These inputs will populate the report and drive the risk simulation.

Here’s a breakdown of each input and how to format it:

### 1. Threat Event Frequency (TEF)

*Represents how often a threat event is expected to occur annually.*

* Format: **Low, Most Likely (Mid), High**
* Example: `1, 10, 20`&#x20;

### 2. Vulnerability

*The probability that a threat event results in loss.*

* Format: **Decimal (0 to 1)**
* Example: `0.35` (represents 35%)

### 3. Primary Loss Magnitude

*The expected loss directly resulting from the threat event.*

* Format: **Low, Most Likely (Mid), High**
* Example: `25000, 100000, 500000`&#x20;

### 4. Secondary Loss Event Frequency (SLEF)

*How often a secondary loss is expected to occur annually.*

* Format: **Low, Most Likely (Mid), High**
* Example: `1, 10, 20`&#x20;

### 5. Secondary Loss Magnitude (SLEM)

*The estimated magnitude of secondary losses (e.g., regulatory fines, reputational damage).*

* Format: **Low, Mid, High**
* Example: `10000, 50000, 150000`&#x20;

## After Entering Inputs

Once you've entered your parameters and loaded the template:

* The model will automatically simulate outcomes using **10,000 iterations**.
* The outputs will be visualized in the report pages

<figure><img src="/files/tFryQN0CkJwnVvF5bvem" alt=""><figcaption></figcaption></figure>

## Troubleshooting

### Query references other queries or steps, so it may not directly access a datasource

When loading your model inputs, you may receive multiple errors stating the query references other queries or steps. This error is due to the privacy levels of the sources and query references in order to reduce duplicative python code.&#x20;

<figure><img src="/files/sliTKWdSCAfqMLGUuNxG" alt=""><figcaption></figcaption></figure>

To address it, click on "close". Then navigate to File > Options > Current File > Privacy > Ignore the Privacy Levels > OK.&#x20;

<figure><img src="/files/huYzspFXCScoVoQo0MbJ" alt=""><figcaption></figcaption></figure>

Then click on "refresh" under the "Home ribbon".&#x20;

<figure><img src="/files/7PGfysxkWqQcr4245xNC" alt=""><figcaption></figcaption></figure>


# Understanding FAIR Inputs

The FAIR model (Factor Analysis of Information Risk) breaks down cyber risk into measurable components, using structured inputs to estimate probable loss exposure. Below is an overview of each input, its meaning, and how it influences the simulation.

## 1. Threat Event Frequency (TEF)

**What it means:**\
The number of times a threat actor is expected to act against an asset in a year.

**Why it matters:**\
Higher frequency increases the chance of loss events occurring. TEF helps establish *how often* you're exposed to risk.

**How it’s modeled:**\
As a **BetaPERT distribution**, using:

* **Low** (minimum plausible frequency)
* **Most Likely** (expected frequency)
* **High** (maximum plausible frequency)

## 2. Vulnerability

**What it means:**\
The likelihood that a threat event will result in a loss — i.e., the asset is *susceptible* to the threat.

**Why it matters:**\
This is the conditional probability that TEF leads to a realized incident.

**How it’s modeled:**\
As a **constant** value between 0 and 1 (e.g., `0.4` = 40% chance).\
Even if threat events are frequent, a low vulnerability reduces overall risk.

## 3. Primary Loss Magnitude (PLM)

**What it means:**\
The direct financial impact of a successful threat event (e.g., data breach response, recovery costs).

**Why it matters:**\
This determines the *severity* of a single realized loss.

**How it’s modeled:**\
As a **BetaPERT distribution**, using:

* **Low** (minimum plausible loss)
* **Most Likely**
* **High** (worst-case direct loss)

## 4. Secondary Loss Event Frequency (SLEF)

**What it means:**\
The chance that secondary losses (like fines, lawsuits, or reputational fallout) occur **after** a primary event.

**Why it matters:**\
Not every incident results in secondary effects — but when they do, they can be costly.

**How it’s modeled:**\
As a **BetaPERT distribution**, reflecting how often secondary effects are expected.

## 5. Secondary Loss Magnitude (SLEM)

**What it means:**\
The financial cost of the secondary effects that occur.

**Why it matters:**\
This completes the picture of *total risk* by adding indirect or follow-on loss exposure.

**How it’s modeled:**

As a **BetaPERT distribution**, using:

* **Low** (minimum plausible loss)
* **Most Likely**
* **High** (worst-case direct loss)

## Summary

Together, these five input types allow the simulation to estimate a **probabilistic distribution** of annual loss exposure — not just a single number. This supports better-informed decisions, trade-offs, and risk prioritization.


# Welcome to CRQ Pro

FAIR-Based Cyber Risk Quantification in Microsoft Excel and PowerBI

<figure><img src="/files/IdMiGeG2yLZW74J1weYU" alt=""><figcaption></figcaption></figure>

Securemetrics CRQ Pro is a FAIR-based Cyber Risk Quantification Toolkit built in Microsoft Excel and PowerBI.&#x20;

### Why CRQ Pro?

> * Run 20,000+ Monte Carlo simulations natively in Excel with no add‑ins or Python installs.
> * Generate transparent, defensible FAIR models.
> * Publish interactive dashboards and live‑data PowerPoint slides with one click.

### Core principals

> 1. **Simplicity at scale.** Risk modeling shouldn’t be complex.
> 2. **Transparency by design.** Every assumption is visible.
> 3. **Low‑friction deployment.** No expensive SaaS. Excel & Power BI are all you need.

### Python-powered Monte Carlo in Excel

* Native Excel models typically max out at \~10,000 iterations.
* CRQ Pro uses Microsoft’s Python in Excel to run 20,000+ simulations with no environment setup required.
* No more expensive add‑ins ($1,500–$3,000/user/year) or SaaS lock‑in.

<table data-view="cards"><thead><tr><th></th><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td>CRQ Pro Excel Model</td><td><a href="/pages/tLQ0wuHhKwpXBSOzvClX">/pages/tLQ0wuHhKwpXBSOzvClX</a></td><td><a href="/files/iO3RPrmXEFkSdDKY8v9R">/files/iO3RPrmXEFkSdDKY8v9R</a></td></tr></tbody></table>

### One-click PowerBI Reporting

* Run locally in PowerBI Desktop or share reports across the org.
* Connect your Excel workbook in seconds with no Power BI modeling required.
* Export charts (live or static) directly into PowerPoint for board‑ready slides.

<table data-view="cards"><thead><tr><th></th><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td>PowerBI Model Report</td><td><a href="/pages/ZKF3AwXxigmv26j9i9te">/pages/ZKF3AwXxigmv26j9i9te</a></td><td><a href="/files/Khk2QLd8Jo29kormyNI9">/files/Khk2QLd8Jo29kormyNI9</a></td></tr><tr><td>PowerPoint Charts</td><td><a href="/pages/AjErMNqxRDThtVGk4gTi">/pages/AjErMNqxRDThtVGk4gTi</a></td><td><a href="/files/V8qSdbBOW51Az80Crl1j">/files/V8qSdbBOW51Az80Crl1j</a></td></tr></tbody></table>


# Excel Model

{% hint style="warning" %}
The CRQ Pro Excel Model requires Python in Excel. The model does NOT require the paid version (known as the add-in). The standard version included in all M365 subscriptions is sufficient.&#x20;
{% endhint %}

<figure><img src="/files/iO3RPrmXEFkSdDKY8v9R" alt=""><figcaption></figcaption></figure>

## Locked Sheets

{% hint style="info" %}
There is no password on the locked sheets and workbook
{% endhint %}

The CRQ Pro Excel Model's workbook structure and sheets are locked to minimize the liklihood of introducing errors when loading into PowerBI. The PowerBI reporting requires specific output structures.&#x20;

This is not to lock you out of editing or reviewing these sheets. You can unlock the sheets, but please note that changing the output or input structure can break both the Python code and PowerBI reporting.&#x20;

## Workbook Structure

| Sheet Name      | Purpose                                                              | Hidden |
| --------------- | -------------------------------------------------------------------- | ------ |
| Model           | Model input including scenario information and FAIR model variables  |        |
| Output          | Quick statistical output to quickly validate model inputs            |        |
| Results         | Python code that runs Monte Carlo simulations                        | ✅      |
| LEC             | Python code that generates exceedence curve data                     | ✅      |
| Statistics      | Python code that generates statistical measure table                 | ✅      |
| Statistics Flat | Python code that generates statistical measures in single row format | ✅      |
| Notes           | Structured output for notes and assumptions                          | ✅      |

## Model Sheet

The model sheet is where you will enter your model inputs and meta data. The cells requiring data input are highlighted in blue:

| Input                          | Description                                                                                             | Example                         | Required |
| ------------------------------ | ------------------------------------------------------------------------------------------------------- | ------------------------------- | -------- |
| Scenario                       | Name/description of the risk scenario being modeled                                                     | Inappropriate access privileges |          |
| Analyst                        | Name, email, or other identifier of the analyst                                                         | Mitchell Telatnik               |          |
| Date                           | Date the model was performed                                                                            | 01/01/2025                      |          |
| Model Name                     | Name of the model. This acts as a unique identifier. Recommended to use an organization-defined schema. | Model-01                        |          |
| Asset at Risk                  |                                                                                                         | Customer PII                    |          |
| Threat Community               |                                                                                                         | Cyber criminals                 |          |
| Threat Type                    |                                                                                                         | Malicious                       |          |
| Effect                         |                                                                                                         | Confidentiality                 |          |
| Threat Event Frequency         |                                                                                                         | 0.5 ; 15                        | ✅        |
| Vulnerability                  |                                                                                                         | 5%                              | ✅        |
| Secondary Loss Event Frequency |                                                                                                         | 80%                             | ✅        |
| Loss Magnitude Variables       |                                                                                                         | 20,000                          | ✅        |


# PowerBI Model Report

{% embed url="<https://www.loom.com/share/039b2f54d54844cb97c64b78733acb8b?sid=2dd13201-ef5d-4a01-b19c-c8873bcb87ef>" %}

## Setting Up the PowerBI Report

### Step one: Download PowerBI Desktop

The CRQ PowerBI model report is a Microsoft PowerBI Template File (.pbit). To open the file you will need the [free Microsoft PowerBI Desktop App.](https://www.microsoft.com/en-us/download/details.aspx?id=58494)&#x20;

### Step two: Copy the full filepath to the Excel Model File

Make sure to fill out the Excel Model file before setting up the model report. Once setup, you can update the Excel model file and refresh the report to update it.&#x20;

### Step three: Open the Model Report Template File

Double click on the PowerBI Model Report Template File (.pbit) to open it in Microsoft PowerBI

### Step four: Paste the full filepath to the Excel Model File

Make sure to remove any quotation marks (") from the beginning and end of the filepath

### Step five: Save your file as a PowerBI file (.pbix)

That's it!


# PowerPoint Charts Template

{% embed url="<https://www.loom.com/share/c3d98aa22bc545d6bb0a9b433a60e406?sid=92866360-f47f-4e21-bc1b-a382e9e85273>" %}

## Setting Up the PowerBI Template

### Step one: Download PowerBI Desktop

The CRQ PowerBI model report is a Microsoft PowerBI Template File (.pbit). To open the file you will need the [free Microsoft PowerBI Desktop App.](https://www.microsoft.com/en-us/download/details.aspx?id=58494)&#x20;

### Step two: Copy the full filepath to the Excel Model File

Make sure to fill out the Excel Model file before setting up the model report. Once setup, you can update the Excel model file and refresh the report to update it.&#x20;

### Step three: Open the Model Report Template File

Double click on the PowerBI PowerPoint Template File (.pbit) to open it in Microsoft PowerBI

### Step four: Paste the full filepath to the Excel Model File

Make sure to remove any quotation marks (") from the beginning and end of the filepath

### Step five: Save your file as a PowerBI file (.pbix)

This is required in order to publish to the PowerBI Service

### Step six: Publish the file to the PowerBI Service

If you do not have a PowerBI license, you can use a free license to publish to "My workspace"

### Step seven: Open Microsoft PowerPoint

In Microsoft PowerPoint, go to "Insert" > "PowerBI" to pull in charts


# Welcome to CRQ Pro

Quantify cyber risk in dollars with FAIR-based Monte Carlo simulation, right on your desktop.

CRQ Pro is a desktop application for **cyber risk quantification (CRQ)**. It helps risk analysts and security teams express cyber risk in financial terms using the **Open FAIR** model and **Monte Carlo simulation**, so you can answer questions like:

* What is our expected annual loss from ransomware?
* What is the 1-in-20-year loss for our top scenarios combined?
* Which scenarios drive the most tail risk in our portfolio?
* Does this exposure exceed our risk appetite?

Everything runs locally on your machine. Your risk data is encrypted at rest and never leaves your computer.

## How it works

{% stepper %}
{% step %}

### Model a scenario

Describe a loss event (for example, "Ransomware outbreak across corporate domain") and estimate its **Loss Event Frequency** and **Loss Magnitude** using ranges, not single guesses. Decompose factors further using the FAIR taxonomy when you have the data to support it.
{% endstep %}

{% step %}

### Simulate

CRQ Pro runs tens of thousands of simulated years in seconds and builds a full annual loss distribution for the scenario, or for a whole portfolio of scenarios at once.
{% endstep %}

{% step %}

### Rate and report

Results are rated Low, Moderate, High, or Critical against your risk appetite, and you can generate board-ready Word reports and Excel workbooks in a couple of clicks.
{% endstep %}
{% endstepper %}

## Key features

* **FAIR-based modeling**: estimate factors directly or decompose them (TEF x Vulnerability, Primary + Secondary loss, the six forms of loss, and more).
* **Fast Monte Carlo engine**: 10,000 to 250,000 iterations per run, with reproducible results.
* **Portfolios**: aggregate scenarios into a combined loss distribution and see which scenarios contribute most.
* **Reusable components**: build a library of shared estimates (threat frequencies, loss tables) and link them into scenarios.
* **Risk appetite ratings**: rate results against dollar thresholds you define, per workspace or per scenario.
* **Reports and exports**: Word risk reports, Excel workbooks, risk register exports, CSV and PNG chart exports.
* **Local and encrypted**: all data is stored on your machine, sealed with AES-256-GCM.

## Where to go next

<table data-view="cards"><thead><tr><th>Title</th><th data-card-target data-type="content-ref">Target</th></tr></thead><tbody><tr><td>Install and activate CRQ Pro</td><td><a href="/pages/9e8hVpxJO2FTRoCQS4tw">/pages/9e8hVpxJO2FTRoCQS4tw</a></td></tr><tr><td>Build your first scenario</td><td><a href="/pages/DjIvBIVJXo0DmpIkdwt5">/pages/DjIvBIVJXo0DmpIkdwt5</a></td></tr><tr><td>Understand the model</td><td><a href="/pages/reAXsPT7g2bNnngKkbsj">/pages/reAXsPT7g2bNnngKkbsj</a></td></tr></tbody></table>


# Installation and activation

Install CRQ Pro, start a free trial or activate a license key, and keep the app up to date.

## Install

CRQ Pro is a desktop application. Download the installer for your platform and run it. Windows builds are code-signed.

## Activate

CRQ Pro requires an active license. The first time you launch the app you will see the **Get started with CRQ Pro** screen with two options:

{% tabs %}
{% tab title="Start a free trial" %}
Click **Start 14-day free trial**. This opens a checkout page in your browser.

{% hint style="info" %}
Card required. Cancel anytime before day 14 for no charge.
{% endhint %}

After checkout you will receive a license key by email. Enter it in the app to activate.
{% endtab %}

{% tab title="Activate a license key" %}
Paste your key into the license field (format `XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX`) and click **Activate**.
{% endtab %}
{% endtabs %}

### One device per key

Each license key can be active on one device at a time. To move to a new machine, remove the license on the old one first: **Settings > Application > License > Remove**. This releases the seat immediately.

### Working offline

CRQ Pro verifies your subscription online at launch. If the license server cannot be reached, the app keeps working for a **14-day offline grace period** from the last successful check. While offline you will see a small badge: "Offline. Verified access for N more days." After the grace period expires, reconnect to the internet and relaunch to verify.

### Managing your subscription

Go to **Settings > Application > License** to:

* See your license status and the last 4 characters of your key
* **Manage license**: opens your billing portal in the browser
* **Change key**: activate a different key on this device
* **Remove**: release this device's seat

## Updates

CRQ Pro checks for updates on launch.

* With **Automatic updates** on (the default), new versions install on launch and the app relaunches.
* With it off, a notification appears when an update is available and you choose when to install.

Change this under **Settings > Application > Updates**, where you can also see your current version and run **Check for updates** manually.


# Quickstart: your first scenario

Model, simulate, and rate your first cyber risk scenario in about ten minutes.

New installs come seeded with a sample workspace, **Acme Corp**, containing a dozen example scenarios (ransomware, data breach, wire fraud, DDoS, and more). Browse those for inspiration, then build your own.

{% stepper %}
{% step %}

### Create a scenario

Click the **+** button at the top of the left icon rail and choose **New scenario**. Give it a name that describes the loss event, for example "Ransomware outbreak across corporate domain". Optionally set a **Stakeholder**, write up the **Loss event scenario** description, and add **Tags**.
{% endstep %}

{% step %}

### Estimate Loss Event Frequency

The **Loss Event Frequency (LEF)** card asks: how often per year does this loss event actually occur? If you have a feel for it, estimate it directly with a range (for example a PERT distribution with minimum 0.1, most likely 0.5, maximum 2 events per year). If not, decompose it into **Threat Event Frequency x Vulnerability** and estimate those instead.

Use the **Analyst notes** box on the card to record your assumptions and sources.
{% endstep %}

{% step %}

### Estimate Loss Magnitude

The **Loss Magnitude (LM)** card asks: when the event happens, how much does one occurrence cost? Estimate a single distribution, or split it into **Primary Loss** plus **Secondary Risk**, and further into the six FAIR forms of loss if you want that granularity.

A lognormal defined by its 10th and 90th percentiles is a common starting point: "I'd be surprised if it cost less than $200k or more than $5M."
{% endstep %}

{% step %}

### Save and review results

Save the scenario and select it in the scenario table. The simulation runs automatically and the **Results dock** at the bottom fills in:

* Summary tiles: **Expected Annual Loss**, **Median**, **P90**, **95% VaR**, **P99**, and the probability of any loss in a year
* A **Loss Exceedance** curve and **Histogram**
* A **risk rating** (Low, Moderate, High, or Critical) against your risk appetite
  {% endstep %}

{% step %}

### Iterate

Adjust your estimates and watch the results update. Simulations re-run automatically as you change inputs. When your scenario is solid, add it to a [portfolio](/crq-pro/core-concepts/portfolios) or generate a [report](/crq-pro/guides/reports).
{% endstep %}
{% endstepper %}

{% hint style="success" %}
Not ready to finish? **Save draft** parks an incomplete scenario. Drafts are excluded from simulations and reports until you complete them.
{% endhint %}


# The FAIR model

How CRQ Pro structures risk with the Open FAIR taxonomy, and the distributions you can use at each leaf.

CRQ Pro quantifies risk with the **Open FAIR** approach:

> **Risk = Loss Event Frequency (LEF) x Loss Magnitude (LM)**

Every scenario has these two factors. Each factor can be **estimated directly** as a distribution, or **decomposed** into its FAIR sub-factors when you have better data one level down. You choose the depth per factor, per scenario.

## The taxonomy

| Factor                           | Estimate directly, or decompose into                      |
| -------------------------------- | --------------------------------------------------------- |
| **Loss Event Frequency (LEF)**   | Threat Event Frequency x Vulnerability                    |
| **Threat Event Frequency (TEF)** | Contact Frequency x Probability of Action                 |
| **Vulnerability**                | Derived from Threat Capability vs Resistance Strength     |
| **Loss Magnitude (LM)**          | Primary Loss + Secondary Risk                             |
| **Secondary Risk**               | Secondary Loss Event Frequency x Secondary Loss Magnitude |

* **LEF**: how many times per year the loss event occurs.
* **TEF**: how many times per year a threat agent acts against the asset. Multiplied by **Vulnerability** (the probability a threat event becomes a loss event) to get LEF.
* **Vulnerability**: set it as a probability directly, or derive it from **Threat Capability** vs **Resistance Strength**, both on the FAIR 0-100 scale. Vulnerability is then the probability that the threat's capability exceeds your resistance.
* **Loss Magnitude**: the cost of one loss event. **Primary Loss** is the direct cost; **Secondary Risk** covers follow-on losses (for example regulatory action or customer churn) that only happen some of the time.
* **Forms of loss**: any loss amount can be split across the six FAIR forms: productivity, response, replacement, fines, competitive advantage, and reputation. The simulation sums them per event.

## Distributions

Every leaf estimate is a distribution, not a point value (though a Point option exists when you truly have a fixed number). Available distributions depend on what you are estimating:

{% tabs %}
{% tab title="Frequency" %}

| Distribution | Use when                                                                         |
| ------------ | -------------------------------------------------------------------------------- |
| **PERT**     | You can give min, most likely, and max. The default choice for expert estimates. |
| **Poisson**  | You know the average annual rate.                                                |
| **Gamma**    | You want a skewed rate with a long right tail.                                   |
| {% endtab %} |                                                                                  |

{% tab title="Magnitude" %}

| Distribution                 | Use when                                                                                 |
| ---------------------------- | ---------------------------------------------------------------------------------------- |
| **PERT**                     | Min, most likely, max cost per event.                                                    |
| **Lognormal (p10/p90)**      | You can bound the cost: "90% chance it is between X and Y." A natural fit for loss data. |
| **Triangle**                 | Like PERT but with more weight on the extremes.                                          |
| **Modified PERT**            | PERT with a confidence parameter (gamma) to sharpen or flatten the peak.                 |
| **Uniform**                  | Any value in the range is equally likely.                                                |
| **Point**                    | A fixed cost.                                                                            |
| **Generalized Pareto (GPD)** | Heavy-tailed losses where extreme outcomes matter.                                       |
| {% endtab %}                 |                                                                                          |

{% tab title="Probability" %}

| Distribution | Use when                                                              |
| ------------ | --------------------------------------------------------------------- |
| **PERT**     | Min, most likely, max probability.                                    |
| **Point**    | A fixed probability.                                                  |
| **Beta**     | You want to express uncertainty from observed successes and failures. |
| {% endtab %} |                                                                       |

{% tab title="Capability (0-100)" %}

| Distribution  | Use when                                  |
| ------------- | ----------------------------------------- |
| **PERT**      | Min, most likely, max on the 0-100 scale. |
| **Triangle**  | Same inputs, heavier extremes.            |
| **Uniform**   | Any value in the range is equally likely. |
| {% endtab %}  |                                           |
| {% endtabs %} |                                           |

{% hint style="info" %}
**How deep should you decompose?** Only as deep as your data supports. A well-reasoned direct LEF estimate beats a four-level decomposition built on guesses. Decompose when the sub-factors are genuinely easier to estimate, for example when you have log data for contact frequency or control assessments for resistance strength.
{% endhint %}

## How the simulation uses your model

For each simulated year, CRQ Pro samples an annual event rate from your LEF model, draws the number of loss events from a Poisson distribution with that rate, samples a Loss Magnitude for each event, and sums them into an annual loss. Repeated tens of thousands of times, this produces the full annual loss distribution you see in the [Results dock](/crq-pro/guides/simulation-results).


# Scenarios

Scenarios are the unit of analysis in CRQ Pro. Create, organize, edit, and manage them.

A **scenario** models one loss event: a specific bad thing that can happen, with an estimated frequency and cost. "Ransomware outbreak across corporate domain", "Payment fraud via compromised email", "Cloud storage misconfiguration exposes customer data" are all scenarios.

## Creating a scenario

Click **+** in the icon rail and choose **New scenario**, or use the button on the Scenarios page. The editor has two halves: metadata on the left, the FAIR model on the right.

### Metadata fields

| Field                   | Purpose                                                                                                   |
| ----------------------- | --------------------------------------------------------------------------------------------------------- |
| **Scenario name**       | Short, descriptive name of the loss event.                                                                |
| **Folder**              | Where it lives in the sidebar tree. Create folders inline with **+ New folder**.                          |
| **Stakeholder**         | Who owns or cares about this risk (for example "SecOps").                                                 |
| **Loss event scenario** | Long-form description of the event, scope, and boundaries.                                                |
| **Tags**                | Free-form labels with autocomplete, used for filtering and reporting.                                     |
| **Risk appetite**       | **Inherit** the workspace appetite, or set **Custom** dollar thresholds for Moderate, High, and Critical. |
| **Portfolios**          | Toggle which portfolios include this scenario.                                                            |

### The model

The right side holds the **Loss Event Frequency** and **Loss Magnitude** factor cards. Estimate each directly or decompose it; see [The FAIR model](/crq-pro/core-concepts/fair-model). Each card has a collapsible **Analyst notes** box for assumptions and rationale, which also appears in generated reports.

You can also link a [component](/crq-pro/core-concepts/components) into a factor slot instead of entering values by hand.

## Drafts

**Save draft** stores a scenario that is incomplete or invalid. Drafts are excluded from simulations and reports until finished. Leaving the editor with unsaved edits prompts you before discarding.

## Organizing and finding scenarios

* **Folders**: nest and drag-reorder folders in the sidebar tree. "All scenarios" shows everything.
* **Search**: the search box matches name, ID, stakeholder, and tags.
* **Tag filters**: filter the table by one or more tags.
* **Drag and drop**: drag a scenario from the table onto a portfolio in the sidebar to add it.

## Managing scenarios

From the table or tree you can **Edit**, **Duplicate** (creates a "(copy)"), **Rename**, **Move**, and **Delete**. Deleting moves the scenario to the [Trash](/crq-pro/guides/import-export#trash-and-recovery), where it can be restored. A mistaken change or deletion can also be reversed with **Ctrl+Z** (undo); see [Undo and redo](/crq-pro/guides/import-export#undo-and-redo).

Selecting a scenario simulates it automatically and shows its results in the Results dock. See [Reading simulation results](/crq-pro/guides/simulation-results).


# Portfolios

Aggregate scenarios into portfolios to see combined exposure and top contributors.

A **portfolio** is a named collection of scenarios simulated together. Where a scenario answers "what does this one risk cost us?", a portfolio answers "what do these risks cost us combined?"

When a portfolio is simulated, each member scenario's annual losses are summed within each simulated year, producing a single aggregate loss distribution. Because each year's losses are added before the statistics are computed, the portfolio correctly reflects years where several events hit at once, which is exactly where tail risk lives.

## Creating and filling a portfolio

* Click **+** in the icon rail and choose **New portfolio**, then pick member scenarios in the include picker.
* Or drag scenarios from the table onto a portfolio in the sidebar ("Drop to add").
* Or toggle portfolio membership from within the scenario editor.

A scenario can belong to any number of portfolios, so you can slice the same scenario library by business unit, by threat type, or for a board view without duplicating anything.

## Portfolio results

Select a portfolio in the sidebar to simulate it. The Results dock shows the same statistics and charts as a single scenario, plus the **Contributors** tab, which ranks member scenarios by their share of the mean loss and their share of tail losses. A scenario can be a modest contributor on average but dominate the tail; Contributors makes that visible.

## Managing portfolios

Portfolios live in the sidebar tree with their own folders. They support **Rename**, **Duplicate**, **Move**, **Delete** (to Trash), tags, and drag-reordering, the same as scenarios.


# Components

Build reusable model pieces once and link them into many scenarios.

A **component** is a reusable piece of a FAIR model: a threat event frequency you have researched, a standard loss table, a vulnerability estimate for a shared control environment. Define it once, link it into any number of scenarios, and update it in one place.

## Component kinds

A component can stand in for any slot in the taxonomy:

* **Loss Event Frequency**
* **Threat Event Frequency**
* **Vulnerability**
* **Loss Magnitude**
* **Loss Amount**
* **Secondary Risk**
* Leaf estimates: **Frequency**, **Probability**, **Magnitude**, **Capability**

## Two libraries

| Library       | Scope                                         |
| ------------- | --------------------------------------------- |
| **Workspace** | Available only inside the current workspace.  |
| **Global**    | Shared across all workspaces on this machine. |

Both are managed on the **Components** page, with folders, search, tags, and the same organize/duplicate/rename/delete actions as scenarios.

## Linking a component into a scenario

In the scenario editor, a factor slot can reference a component instead of holding inline values. The link is **live**: when you edit the component, every scenario using it picks up the change on its next simulation.

{% hint style="warning" %}
Because links are live, editing a widely used component changes the results of every scenario that references it. Check where a component is used before making material changes, or duplicate it and edit the copy.
{% endhint %}

## Import and export

Individual components, component folders, or the whole library can be exported to a `.cqx` bundle and imported elsewhere, for example to share a calibrated threat library with a colleague. See [Import, export and backup](/crq-pro/guides/import-export).


# Workspaces

Workspaces are self-contained risk libraries. Use them to separate clients, business units, or experiments.

A **workspace** is a self-contained library: its own scenarios, portfolios, folders, workspace components, cached results, risk appetite, and display currency. The app can hold several workspaces; one is active at a time.

Typical uses:

* One workspace per client (for consultancies)
* One per business unit or subsidiary
* A sandbox workspace for experiments, separate from the official register

New installs start with a sample workspace named **Acme Corp**, pre-loaded with example scenarios you can explore or delete.

## Switching and managing

The **workspace switcher** appears in the top bar and in Settings, Reports, and Components. From it you can:

* **Switch** the active workspace
* **Create** a new one (starts as "Untitled workspace")
* **Rename** or **Delete** (the last remaining workspace cannot be deleted)
* **Export** or **Import** a workspace as a `.cqx` bundle

Switching workspaces clears the current selection; nothing is lost, results are cached per workspace.

## What is shared vs. scoped

| Scoped to each workspace           | Shared across all workspaces                                               |
| ---------------------------------- | -------------------------------------------------------------------------- |
| Scenarios, portfolios, folders     | **Global component library**                                               |
| Workspace component library        | Application settings (iterations, currency default, analyst name, updates) |
| Risk appetite and display currency | License                                                                    |
| Cached simulation results          | Trash (shows deleted items from all workspaces)                            |

## Workspace settings

**Settings > Workspace** holds the per-workspace configuration:

* **Display currency**: inherit the application default or override it for this workspace. Values are labels only; CRQ Pro never converts between currencies.
* **Risk appetite**: the statistic and dollar thresholds used to rate results. See [Risk appetite and ratings](/crq-pro/guides/risk-appetite).


# Reading simulation results

What the Results dock shows and how to read each statistic, chart, and tab.

Select a scenario or portfolio and CRQ Pro simulates it automatically, filling the **Results dock** at the bottom of the Scenarios page. Results re-run on their own whenever you change inputs, appetite, or the iteration setting (you will briefly see "Updating…"), and there is a **Re-run** button for manual runs.

Simulations use a fixed random seed, so the same inputs always produce the same results.

## Summary statistics

| Statistic                      | Meaning                                                                                                        |
| ------------------------------ | -------------------------------------------------------------------------------------------------------------- |
| **Expected Annual Loss (ALE)** | The mean of the annual loss distribution. The long-run average yearly cost.                                    |
| **Median (P50)**               | Half of simulated years lose less than this, half lose more. Often far below the mean for skewed cyber losses. |
| **P90**                        | A 1-in-10-year loss level.                                                                                     |
| **95% VaR**                    | A 1-in-20-year loss level (95th percentile).                                                                   |
| **P99**                        | A 1-in-100-year loss level.                                                                                    |
| **Max simulated**              | The single worst year in the run. Indicative only; it moves with iteration count.                              |
| **P(any loss / yr)**           | The share of simulated years with at least one loss event.                                                     |

A **risk rating badge** (Low, Moderate, High, or Critical) shows how the rated statistic compares to your [risk appetite](/crq-pro/guides/risk-appetite).

## Tabs

* **Scenario**: details of the selected item.
* **Taxonomy**: factor sensitivity for a single scenario, showing which parts of the model drive the result.
* **Stats**: expected values per factor for a single scenario.
* **Loss Exceedance**: the LEC plots, for each loss amount, the probability that annual losses exceed it. Read it as "there is a 5% chance of losing more than X in a year." Exportable as CSV or PNG.
* **Histogram**: the shape of the annual loss distribution. Exportable as CSV or PNG.
* **Simulations**: the raw per-run table, one row per simulated year, sortable, with per-run exceedance percent. Drilling into a single scenario also shows the realized event count (LEF) and per-event loss. The full table can be exported to CSV.
* **Contributors** (portfolios): ranks member scenarios by contribution to the mean and to the tail.

## Iteration count

**Settings > Application > Simulation > Default iterations** sets the trials per simulation: 10,000, 50,000 (default), 100,000, or 250,000. Higher is more precise, especially in the tail (P99 and beyond), but slower. 50,000 is a good working default; bump it for final numbers going into a report.


# Risk appetite and ratings

Define dollar thresholds and choose the statistic that turns simulation output into Low, Moderate, High, or Critical ratings.

Simulation output is a distribution; decision makers want a rating. The **risk appetite** bridges the two: you choose a statistic to rate against and dollar thresholds, and every result gets a **Low**, **Moderate**, **High**, or **Critical** badge.

## Configuring the workspace appetite

Go to **Settings > Workspace > Risk appetite**.

### Rate against

Choose which statistic is compared to the thresholds:

* **Expected annual loss (mean)**
* **P90 loss (1 in 10 year)**
* **P95 loss (1 in 20 year)** (default)
* **P99 loss (1 in 100 year)**

Rating against a tail percentile (the default P95) expresses "we care about bad years", while rating against the mean expresses "we care about the long-run average". Pick the one that matches how your organization talks about appetite.

### Thresholds

Set the dollar levels where the rating steps up:

| Rating                   | Default threshold |
| ------------------------ | ----------------- |
| Low                      | below Moderate    |
| **Moderate at or above** | $250,000          |
| **High at or above**     | $2,500,000        |
| **Critical at or above** | $25,000,000       |

A live preview scale shows the bands as you type, and validation keeps the thresholds in order.

## Per-scenario overrides

Some scenarios warrant their own appetite, for example a scenario scoped to a small subsidiary. In the scenario editor, switch **Risk appetite** from **Inherit** to **Custom** and enter Moderate, High, and Critical thresholds for that scenario alone.

{% hint style="info" %}
Ratings appear on the results badge, in the scenario table, and in generated reports, so aligning thresholds with your organization's actual appetite statement pays off everywhere at once.
{% endhint %}


# Generating reports

Generate Word risk reports, Excel workbooks, and risk register exports from your scenarios and portfolios.

The **Reports** page turns simulations into deliverables. Pick a scope on the left (one or more scenarios, or a portfolio), pick a report type from the catalog, review the "Included in this report" panel, and click **Generate**. Single files open a Save As dialog; multi-file runs ask for a destination folder.

Reports show a **Prepared by** line taken from **Settings > Application > Reports > Analyst name**. Set it once before your first report.

## Report catalog

| Report                          | Format        | Scope                  | Contents                                                                                                                                                                                                          |
| ------------------------------- | ------------- | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Single Scenario Risk Report** | Word (.docx)  | Each selected scenario | A full standalone FAIR analysis of one scenario: model, assumptions, statistics, charts. One document per scenario.                                                                                               |
| **Scenario Analysis Workbook**  | Excel (.xlsx) | Each selected scenario | Per-iteration factor draws, summary statistics, and a loss exceedance table for deeper offline analysis. One workbook per scenario.                                                                               |
| **Portfolio Risk Report**       | Word (.docx)  | Exactly one portfolio  | Aggregate exposure with per-scenario contribution.                                                                                                                                                                |
| **Treatment Comparison Report** | Word (.docx)  | 2+ scenarios           | Compares a baseline against named treatment options: risk-reduction deltas and overlaid loss curves. Model each treatment as its own scenario (duplicate the baseline, adjust the factors the treatment changes). |
| **Executive Summary**           | Word (.docx)  | 2+ scenarios           | Board-level briefing of top risks.                                                                                                                                                                                |
| **Risk Register Export**        | Excel (.xlsx) | Selected scenarios     | One row per scenario: ID, name, folder, stakeholder, tags, rating, expected LEF and LM, ALE, P50, P90, 95% VaR, P99, probability of any loss, and description. Column selection is configurable before export.    |

## Chart and data exports

Outside the Reports page, the Results dock exports directly:

* **Loss Exceedance** curve: CSV or PNG
* **Histogram**: CSV or PNG
* **Simulations** table: full per-run CSV (every iteration; includes realized event counts and per-event losses for a single scenario)

These are handy for dropping a chart into your own deck or running your own analysis on the raw draws.


# Import, export and backup

Move work between machines and colleagues with bundles, keep full backups, and recover deleted items from the Trash.

CRQ Pro has two distinct file types, for two different jobs:

* **Bundles (`.cqx`)** move *parts* of your work (a scenario, a component library, a whole workspace) between workspaces, machines, or colleagues.
* **Backups (`.cqbackup`)** capture *everything* in one file, for disaster recovery and moving to a new machine.

## Bundles (.cqx)

CRQ Pro exports and imports work as **`.cqx`** files. You can bundle:

* A single scenario, a scenario folder, or the whole scenario library
* A single component, a component folder, or a component library
* A portfolio, or all portfolios
* An **entire workspace**

Export options live on the sidebar tree items, the Components page, and the workspace switcher. A bundle carries everything the items depend on, so any components a scenario links to travel with it.

**Import behavior:**

* A **workspace bundle** imports as a **new workspace**, leaving existing ones untouched.
* All other bundles **merge into the active workspace as copies**; they never overwrite existing items.

CRQ Pro asks you to confirm before importing, showing what the bundle contains and where it will land.

## Full backups (.cqbackup)

A **backup** is a single `.cqbackup` file holding your entire library: every workspace, the global component library, and the Trash. Unlike the encrypted store on disk, a backup is portable and not tied to this machine, so it is the copy that survives an operating system reinstall, a lost machine, or a damaged encryption key (see [Data storage and security](/crq-pro/reference/data-security)).

Manage backups under **Settings > Application > Backup**.

### Automatic backups

Turn on **Automatic backups** and choose a folder. CRQ Pro then writes a full backup to that folder on launch and about once a day while the app is open, keeping the ten most recent.

{% hint style="success" %}
Point the backup folder at a synced location (OneDrive, Dropbox, a network drive) and your backups are copied offsite automatically, with no extra steps.
{% endhint %}

The Backup panel shows the current folder and when the last backup ran. If automatic backups are off and nothing has been saved in 30 days, CRQ Pro reminds you.

### Manual backup and restore

* **Export backup** writes a `.cqbackup` to a location you pick, on demand.
* **Restore** replaces everything currently in the app with the contents of a backup file.

{% hint style="danger" %}
**Restore replaces all of your current data** (every workspace, component, and the Trash). Export a backup of your current state first if you might want it back. CRQ Pro asks you to confirm before restoring.
{% endhint %}

### Moving to a new machine

Export a backup on the old machine, install CRQ Pro on the new one, activate your license (remove it from the old machine first, see [Installation and activation](/crq-pro/getting-started/installation#one-device-per-key)), then **Restore** the backup.

## Undo and redo

Most edits, including creating, editing, moving, and deleting items, can be reversed with **Ctrl+Z** (undo) and **Ctrl+Shift+Z** or **Ctrl+Y** (redo). Undo covers your recent changes to the library, so a mistaken edit or deletion is usually one keystroke away. It does not reverse a completed **Restore** of a backup or an **Empty trash**.

## Trash and recovery

Deleting a scenario, portfolio, or component is a **soft delete**: the item moves to the **Trash** (bottom of the icon rail), which collects deleted items across all workspaces.

From the Trash you can:

* **Restore** an item to where it came from
* **Permanently delete** a single item
* **Empty trash** to permanently delete everything

{% hint style="danger" %}
Permanent deletion and **Empty trash** cannot be undone. If in doubt, export a bundle or a backup first.
{% endhint %}


# Settings reference

Every setting in CRQ Pro, what it does, and where it applies.

Open **Settings** from the bottom of the left icon rail. Settings are split across two tabs.

## Application tab

Device-level settings that apply to every workspace.

| Setting                             | What it does                                                                                                                                                                        |
| ----------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **License**                         | License status, masked key, **Manage license**, **Change key**, **Remove** (releases this device's seat). See [Installation and activation](/crq-pro/getting-started/installation). |
| **Updates > Automatic updates**     | On (default): new versions install on launch. Off: you are notified and choose when to install.                                                                                     |
| **Updates > Version**               | Shows the running version, with a **Check for updates** button.                                                                                                                     |
| **Simulation > Default iterations** | Trials per simulation: 10,000 / 50,000 (default) / 100,000 / 250,000. Higher is more precise but slower.                                                                            |
| **Backup > Automatic backups**      | Off by default. On: writes a full backup to your chosen folder on launch and daily, keeping the ten most recent.                                                                    |
| **Backup > Backup folder**          | The folder automatic backups are written to. Choosing a folder turns automatic backups on; point it at a synced folder for an offsite copy.                                         |
| **Backup > Export backup**          | Writes a full `.cqbackup` (all workspaces, components, Trash) to a location you pick, on demand.                                                                                    |
| **Backup > Restore**                | Replaces all current data with a backup file's contents (asks you to confirm).                                                                                                      |
| **Currency > Default currency**     | The display currency (ISO 4217, USD default). Values are never converted between currencies; this is a label.                                                                       |
| **Reports > Analyst name**          | Shown as "Prepared by" on generated reports.                                                                                                                                        |

## Workspace tab

Per-workspace settings, with a workspace switcher alongside so you can configure any workspace.

| Setting                          | What it does                                                                                                                                           |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Currency > Display currency**  | Inherit the application default, or override for this workspace.                                                                                       |
| **Risk appetite > Rate against** | The statistic ratings are computed from: mean, P90, P95 (default), or P99.                                                                             |
| **Risk appetite > Thresholds**   | Dollar levels for **Moderate at or above**, **High at or above**, **Critical at or above** (defaults $250k / $2.5M / $25M), with a live preview scale. |

See [Risk appetite and ratings](/crq-pro/guides/risk-appetite) for guidance on choosing these.


# Data storage and security

Where your data lives, how it is encrypted, and what leaves your machine.

CRQ Pro is built local-first. Your risk data stays on your machine.

## Storage and encryption

* All workspaces, scenarios, portfolios, components, and results are stored in a single encrypted file in your operating system's application data directory.
* The file is sealed with **AES-256-GCM**. The encryption key is generated randomly and stored in your OS credential store: **Windows Credential Manager**, **macOS Keychain**, or **libsecret** on Linux. The encrypted file on disk is useless without an authenticated session as your OS user.
* Writes are atomic (written to a temporary file, then swapped in), so a crash mid-save cannot corrupt your data.

## What leaves your machine

| Traffic            | Purpose                                                                                      |
| ------------------ | -------------------------------------------------------------------------------------------- |
| License validation | Verifies your subscription at launch. If unreachable, a 14-day offline grace period applies. |
| Update check       | Checks for new app versions at launch (and on manual **Check for updates**).                 |

Your scenario data, simulation results, and reports are never transmitted anywhere. There is no telemetry on your risk data and no cloud sync.

## Backups

Because the store is encrypted with a key held only in your OS credential store, losing that key, by reinstalling the operating system, moving to a new machine, or a corrupted credential store, makes the on-disk file unrecoverable. A **`.cqbackup`** file is plain, portable, and not tied to the machine, so it is your safety net.

Turn on **automatic backups** (Settings > Application > Backup) and point them at a synced folder for an offsite copy, or export a backup manually. If backups are not configured and nothing has been saved in 30 days, CRQ Pro reminds you. See [Import, export and backup](/crq-pro/guides/import-export).


# FAQ

Common questions about licensing, results, and day-to-day use.

<details>

<summary>Why do my results change slightly after I edit an input?</summary>

They should not change between identical runs: CRQ Pro uses a fixed random seed, so the same inputs always give the same results. If numbers moved, an input actually changed (possibly a linked component edited elsewhere) or the iteration count was changed in Settings.

</details>

<details>

<summary>Why is the mean (Expected Annual Loss) so much higher than the median?</summary>

Cyber loss distributions are heavily right-skewed: most years are quiet, a few are catastrophic. Rare huge losses pull the mean up while the median stays low. That gap is real information; it is why CRQ Pro reports both, plus tail percentiles.

</details>

<details>

<summary>How many iterations should I use?</summary>

50,000 (the default) is fine for day-to-day modeling. Use 100,000 or 250,000 when tail percentiles (P99) matter, for example for final report numbers. Use 10,000 only for quick rough drafts.

</details>

<details>

<summary>Can I use CRQ Pro on two computers?</summary>

One device per license key at a time. To move, go to **Settings > Application > License > Remove** on the old machine, then activate on the new one. Move your data by exporting a **backup** on the old machine and restoring it on the new one. See [Import, export and backup](/crq-pro/guides/import-export#moving-to-a-new-machine).

</details>

<details>

<summary>How do I back up my data?</summary>

Turn on **automatic backups** under **Settings > Application > Backup** and choose a folder (point it at OneDrive, Dropbox, or a network drive for an offsite copy). CRQ Pro then writes a full `.cqbackup` there on launch and daily. You can also **Export backup** at any time. This matters because your data on disk is encrypted with a key tied to this machine, a backup is the copy that survives a reinstall or a new machine. See [Data storage and security](/crq-pro/reference/data-security#backups).

</details>

<details>

<summary>Does CRQ Pro work offline?</summary>

Yes, for up to 14 days at a stretch. The app verifies your subscription online at launch; when the server is unreachable it runs on a 14-day grace period from the last successful check, with a badge showing days remaining. Reconnect and relaunch to reset it.

</details>

<details>

<summary>I deleted something by accident. Can I get it back?</summary>

Yes. Press **Ctrl+Z** to undo a recent deletion or edit. Otherwise, if it was a soft delete, open **Trash** at the bottom of the icon rail and restore it. Permanent deletes and **Empty trash** cannot be undone.

</details>

<details>

<summary>Does changing the currency convert my values?</summary>

No. Currency is a display label only. If you enter 500,000 with USD selected and switch to EUR, it displays as 500,000 EUR. Keep one currency per workspace to avoid confusion.

</details>

<details>

<summary>Where is my data stored, and is it safe?</summary>

In an AES-256-GCM encrypted file in your OS application data directory, with the key in your OS credential store. Nothing is synced to a cloud. See [Data storage and security](/crq-pro/reference/data-security).

</details>

<details>

<summary>How do I model the effect of a control or treatment?</summary>

Duplicate the baseline scenario, adjust the factors the treatment changes (for example, lower Vulnerability to reflect a new control, or lower Loss Magnitude for better response), and compare. The **Treatment Comparison Report** formalizes exactly this: a baseline plus named treatment options with risk-reduction deltas.

</details>


