CRQ studies
A CRQ study — cyber risk quantification — evaluates risk in money instead of matrix categories. You describe how often a loss event happens and how much it costs when it does, both as ranges rather than single numbers, and CyberGuard simulates the outcome to produce an annualised expected loss and the curve behind it. It is the same question as a qualitative assessment, asked in the language finance and the board already speak.
Where to find it
Section titled “Where to find it”Risk → CRQ studies in the sidebar.
Key concepts
Section titled “Key concepts”Three nested objects carry the analysis.
The container. It lives in a Domain and carries a Reference ID, Status, Authors, Reviewers and Observation, plus the two settings that make its numbers meaningful:
- Loss threshold — the maximum acceptable annual loss, the baseline your tolerance is measured against.
- Tolerance settings — the risk tolerance curve the study is judged against.
Scenario
Section titled “Scenario”One discrete risk being modelled — “ransomware on the e-commerce portal”. A scenario names the Assets it impacts and the Vulnerabilities it exploits, and carries an Owner, a Priority (P1 to P4) and a Status (draft, open, mitigate, accept, transfer).
Hypothesis
Section titled “Hypothesis”A parameter set for a scenario, one per risk stage — Inherent, Current or Residual. This is where treatment and simulation meet: each hypothesis declares which controls it assumes, split across existing controls (the baseline), added controls (what you would invest in) and removed controls. Comparing a current hypothesis with a residual one is how you price a treatment plan.
Its Simulation Parameters are three numbers:
- Probability (P) — how likely the loss event is in a year.
- Expected Loss Lower Bound (LB) — the best case; 5% of the time the loss would be lower than this.
- Expected Loss Upper Bound (UB) — the worst case; 5% of the time it will be higher.
The bounds define a lognormal distribution with a 90% confidence interval, which the simulation samples.
Running a study
Section titled “Running a study”Create the study, add a scenario, then add hypotheses to it. On each hypothesis, set the Treatment controls and the Simulation Parameters, save, and press Run simulation. The results appear immediately: a Loss Exceedance Curve plotting the probability of exceeding any given annual loss, alongside the headline metrics.
Changing anything marks the simulation stale; Retrigger all simulations re-runs everything in the study, including portfolio data and the tolerance curve.
Metrics
Section titled “Metrics”- ALE — annual loss expectancy, the mean annual loss.
- VaR 95%, VaR 99%, VaR 99.9% — value at risk at those percentiles: the loss level the bad years reach.
- Probability of exceeding loss threshold — how often the study breaches the line you drew.
- ROSI — return on security investment, computed for residual hypotheses as current ALE minus residual ALE minus treatment cost, divided by treatment cost.
Executive summary and key metrics
Section titled “Executive summary and key metrics”Two study-level views roll the scenarios up:
- Executive summary — the portfolio view: the combined study risk profile and its Loss Exceedance Curve, loss breakdown by scenario, ALE vs Treatment Cost by Scenario, inherent, current and residual ALE side by side, and the existing and additional controls behind them.
- Key metrics — a per-scenario table of ALE, VaR levels and threshold-exceedance probability at current and residual stages, with definitions of each metric and filters by scenario and risk level.
An Action plan view collects the controls the study depends on.
Related
Section titled “Related”- Risk assessments — the qualitative counterpart.
- Applied controls — where treatment costs come from.
- Assets and Vulnerabilities — what a scenario points at.
