AI Indexes
IT AI Index
Index › Security operations › October 2026 Edition

Cyber risk quantification

Asked as “cyber risk quantification tool”, and as “CRQ platform”, on behalf of a mid-market B2B company. 51 first choices recorded across the direct, paraphrase, budget and scale prompts, fourteen models each. Added to the October 2026 Edition on October 4, 2026; its answers are read by the distilled judge (ai-indexes-judge-qwen3-14b-run3), not the claude-opus-5 judge of the earlier categories: how the two compare.
Standing · first-choice share
25%
Contested · Kovrr 12%
25CyberSaint CyberStrong12Kovrr08SAFE Security55others

25% of first choices, contested.

By buyer segment

The same question asked on behalf of a different buyer. Each standing is computed within its segment; they sit side by side and are never added together.

The standing

Share is the count of first choices across the direct, paraphrase, budget and scale prompts, over all fourteen models, for a mid-market B2B company. Ordered by share.
ProductFirst-choice shareNegative rateLabelsQuadrantSince September 2026
01CyberSaint CyberStrong25%0%26accepted challengernewNew since September 2026: not ranked then, 25% now.
02Kovrr12%13%30accepted challengernewNew since September 2026: not ranked then, 12% now.
03SAFE Security8%32%40criticized challengernewNew since September 2026: not ranked then, 8% now.
04Axio6%16%32accepted challengernewNew since September 2026: not ranked then, 6% now.
05RiskLens2%37%27criticized challengernewNew since September 2026: not ranked then, 2% now.
Show the one product at 0%, ordered by negative rate
06Balbix0%24%17accepted challengernewNew since September 2026: not ranked then, 0% now.

The floor is 11 points of share, measured: how far the models move a leader on their own when the same questions are asked twice with nothing changed. A larger change is movement; a smaller one is noise, and both are shown. Movement is read over the twelve models both editions asked; GPT-6 Luna, Muse Glimmer 30B joined this edition and are in the standing but not yet in the comparison. How the floor is measured

Bars are the share of first choices, 0 to 100Every product with at least 10 labels here. Every product name links to its product page.
All ten head-to-head pages: the top five products, each against each

Recommended versus criticized

Every product with at least 10 labels here, on both axes. The 30% line names a quadrant, not the verdict above: that one needs more than 40%.

Criticized challengerCriticized default
Negative label rate →
01
02
03
04
R05
06
Accepted challengerEndorsed leader
0%First-choice share → · lines at 30% share and 25% negative40%
Key
01CyberSaint CyberStrong25%
02Kovrr12%
03SAFE Security8%
04Axio6%
05RiskLens2%
06Balbix0%

What they warned about

Zero of fourteen models held their first choice under the paraphrase. Claude Haiku 4.5, GPT-5.4 mini, Gemini 3.5 Flash, Perplexity Sonar, Grok 4.1 Fast, Mistral Small, DeepSeek V4 Flash, Llama 4 Maverick, Qwen 3.7 Flash, Kimi K2, GLM 4.7 FlashX, MiniMax M2.5, GPT-6 Luna and Muse Glimmer 30B changed. A high negative share on a product with few labels is a warning. A low share on a product with many labels is salience, not sentiment.
RiskLens
37%
10 of 27 labels negative · 7 of 14 models
“transparent pricing compared to most enterprise CRQ tools (like RiskLens or SAFE Security) that typically start at $25K–$200K+ annually” DeepSeek V4 Flash, budget prompt
SAFE Security
32%
13 of 40 labels negative · 7 of 14 models
“such as Kovrr, Safe Security, and Axio) are generally out of reach, as their annual licensing fees frequently scale into the tens or hundreds of thousands of dollars” Gemini 3.5 Flash, budget prompt
Axio
16%
5 of 32 labels negative · 4 of 14 models
“six-figure platform costs seen for enterprise tools such as Risk Cloud Quantify, Safe Security, Axio and RiskLens” Muse Glimmer 30B, budget prompt
Kovrr
13%
4 of 30 labels negative · 3 of 14 models
“standard enterprise Cyber Risk Quantification (CRQ) tools (such as Kovrr, Safe Security, and Axio) are generally out of reach” Gemini 3.5 Flash, budget prompt

What they cite

Citations exist only for the models that return a source list: fourteen of the fourteen in this edition, and all six flagship models on the expanded tier.

Sites the answers cite

74 of 84 answers in this category came back with a source list, from 14 of 14 models: citations where the model returns them, or the search results it consulted. 1014 links across 207 sites, every framing counted. Ranked by the number of answers carrying the site or page. None of the 252 answers across every segment cited this index's own page for the category.

40 answers · 52 citations · 11 models
vendor site · Kovrr35 answers · 60 citations · 13 models
29 answers · 31 citations · 11 models
28 answers · 28 citations · 10 models
26 answers · 29 citations · 11 models
vendor site · CyberSaint24 answers · 35 citations · 12 models
23 answers · 30 citations · 9 models
vendor site · vCISO Lite21 answers · 28 citations · 10 models
vendor site · G221 answers · 27 citations · 10 models
19 answers · 23 citations · 7 models
vendor site · MetricStream17 answers · 20 citations · 7 models
vendor site · Bitsight15 answers · 18 citations · 9 models

Pages the answers cite

The ten pages named in the most answers, by full address. A page here is one the models returned with a recommendation, not one the index endorses.

Search against answers

Each company's standing in the answers beside its site's footprint in Google search, one row a site: the products the models named on it with their shares, and the share they add up to; monthly searches on Google, and DataForSEO's estimate of AI search demand (modeled from search signals, directional, not a count of queries to any assistant), for the most-searched of the company's and its products' names (the name is in each row's hover text); estimated monthly organic visits to the site; and its best position in Google's top ten for “best cyber risk quantification tool”, “cyber risk quantification tool”, “cyber risk quantification tools”. US estimates from DataForSEO and Google's Ads Transparency Center. A small company's site, or a mid-sized company's site for its flagship, is marked company; a product on a large parent's site (Google, Microsoft) has no site figures. A column with no figures for this category is left out, and an empty cell means none were seen, not none exist. Two measurements side by side: neither is read as the cause of the other.
Company and productsShareOwn site citedName searches, GoogleAI search demand, est.Organic visitsGoogle ads, last 30 daysBest Google position
CyberSaint CyberStrong cybersaint.io25%54021,50419
Kovrr kovrr.com12%108140330,98134
SAFE Security safe.security8%1152,4005,4961,015,372128
Axio axio.com6%965,4003,6541,8150
Maxxsure6%900
CyberQRM4%
Axio3604%500
FAIR-U4%
Fair TPRM fairtprm.com4%9
FairCRQ4%0

Google's top ten for the three searches hold 26 sites; 4 of them are among the sites the models cited here (cybersaint.io, kovrr.com, metricstream.com, vcso.ai). The first result for “best cyber risk quantification tool” is cybersierra.co.

How they answered

Six framings of the same buying question, each sent to every model in a fresh session with search on. One row per model, so a row shows whether it held its answer under rewording, what it named when cost was the constraint, and what it argued against. Computed from the raw judge labels.
ShowHide
ModelDirect“What is the best cyber risk quantification tool for a mid-market B2B company?”Paraphrase“Which CRQ platform would you recommend to a mid-sized B2B company?”Comparative“What are the top cyber risk quantification tools and how do they differ?”Budget-constrained“What is the best cyber risk quantification tool for a company with a limited budget?”Scale-constrained“We are a 500 person company evaluating a cyber risk quantification tool. What should we look at?”Negative“Which cyber risk quantification tools should I avoid or be cautious about?”
Claude Haiku 4.5Cyrisma
Three alternativesBlack Kite, Maxxsure, SAI360
no first choiceChangedSAFE Security
Four alternativesAxio, CyberSaint CyberStrong, Kovrr, RiskLens
no first choice
Four alternativesBlacksmith, CISA CSET, SAFE Security, VulnRisk
no first choiceagainst: FAIR, LogicGate, SafeSecurity
GPT-5.4 miniSAFE Security
Two alternativesKovrr, ThreatConnect Risk Quantifier
QualtricsChanged
Three alternativesG2, Trustpilot, unitQ
against: RQ Platform
RiskLens, SAFE Security
One alternativeOpen FAIR tools / spreadsheet-based FAIR
against: OCTAVE
FAIR-U
One alternativeSecurity Decision Labs / FAIR cyber risk quantification toolkit
against: RiskLens, SAFE Security
no first choicenothing named
Gemini 3.5 FlashKovrr
Two alternativesAxio, CyberSaint CyberStrong
against: SAFE Security
AxioChanged
Two alternativesKovrr, SAFE Security
SAFE Security
Four alternativesAxio, CyberSaint CyberStrong, KPMG Cyber Risk Insights, Kovrr
SimpleRisk
Five alternativesCyberQRM, FAIR-U, Hive Systems Quantitative Cyber Risk Assessment Tool, evaluator, pyfair
against: Axio, Kovrr, SAFE Security
no first choiceagainst: RiskLens
Perplexity SonarCyberSaint CyberStrong
Two alternativesRiskLens, SAFE One
against: CYE, UpGuard
CyberSaint CyberStrong, SAFE SecurityChanged
One alternativeRiskLens
no first choiceComp AI
Three alternativesAxio, Kovrr, SAFE Security
no first choicenothing named
Grok 4.1 FastCyberSaint CyberStrong
Three alternativesCyber Quant, Maxxsure, vCISO Lite
against: Axio, Balbix, SAFE Security
KovrrChanged
Three alternativesBalbix, CyberSaint CyberStrong, X-Analytics
SAFE Security
Four alternativesAxio, Balbix, Kovrr, Resilience
Fair TPRM
Three alternativesCyberQRM, FAIR Institute resources, Security Decision Science GitHub tools
against: Balbix, LogicGate, RiskLens
no first choiceagainst: Axio, Balbix, RiskLens
Mistral SmallCyberSaint CyberStrong, Maxxsure
One alternativeRiskLens
Kovrr, ResilienceChanged
Two alternativesSAFE One, vCISO Lite
SAFE Security
Four alternativesAxio, Balbix, CyQuant, Resilience
FAIR-U
Two alternativesCISA’s CSET, NIST’s Cybersecurity Framework
no first choiceagainst: SAFE Security
DeepSeek V4 FlashCyberSaint CyberStrong
Three alternativesAxio, SAFE Security, vCISO Lite
against: Balbix
KovrrChanged
Three alternativesAxio, SAFE Security, vCISO Lite
SAFE Security
Four alternativesAxio, Balbix, Bitsight, Kovrr
CyberQRM, FairCRQ
Three alternativesHyperproof, Resiliently, SARA Open-Source
against: Axio, RiskLens, SAFE Security
no first choiceagainst: SAFE Security, ThreatConnect Risk Quantifier
Llama 4 MaverickCyberSaint CyberStrong
Three alternativesAxio, Maxxsure, RiskLens
KovrrChanged
Two alternativesC-Risk, Maxxsure
no first choice
Two alternativesBalbix, Kovrr
RiskLensno first choicenothing named
Qwen 3.7 FlashCyberSaint CyberStrong, Maxxsure
Two alternativesBlack Kite, RiskLens
MaxxsureChanged
Two alternativesCyber Quant, vCISO Lite
RiskCloud
Four alternativesKrare Insights, LogicManager, Satori, The FAIR Institute
Microsoft Excel
Six alternativesAirtable, Notion, OpenFAIR Institute, PowerBI, PyRisk / RiskLib, Simplicity
against: Databeagle, RiskLens
no first choicenothing named
Kimi K2CyberSaint CyberStrong
Two alternativesAxio, Maxxsure
against: Kovrr, RiskLens, SAFE Security
Axio360Changed
One alternativeKovrr
against: SAFE Security
SAFE Security
Six alternativesAxio, Balbix, Bitsight, CyberSaint CyberStrong, Ostrich Cyber-Risk, Tenable
CyberQRM
Two alternativesComplyJet, Fair TPRM
CyberSaint CyberStrong, Cyrisma, Kovrr
Four alternativesAxio, Hyperproof, LogicGate, SAFE Security
against: RiskLens, SAFE Security
GLM 4.7 FlashXCyberSaint CyberStrong, SAFE Security
Five alternativesAxio, Balbix, LogicGate Risk Cloud, RiskLens, UpGuard
no first choiceChangedBalbix, Bitsight
Three alternativesAuditBoard, CyberSaint CyberStrong, MetricStream
FAIR Excel Spreadsheet
Two alternativesCISA CSET Tool, NIST SP 800-30 Risk Assessment Guide
no first choicenothing named
MiniMax M2.5CyberSaint CyberStrong
Five alternativesBitsight, Black Kite, Kovrr, LogicGate Risk Cloud, UpGuard
CyberSaint CyberStrong, SAFE SecurityChanged
One alternativeAxio
SAFE Security
Three alternativesAxio, Balbix, RiskLens
HiveSystems Quantitative Risk Assessment Tool, Wolferdawg Cyber Risk Assessment
Three alternativesCISA CSET, CyberSaint CyberStrong, vCISO Lite
no first choicenothing named
GPT-6 LunaAxio360
Two alternativesCyberSaint CyberStrong, SAFE Security
AxioChanged
Two alternativesCyberSaint CyberStrong, SAFE One
SAFE One
Three alternativesAxio360, CyberSaint CyberStrong, Kovrr
Vulc
One alternativeCyberQRM
against: FAIR-U Workbook
no first choicenothing named
Muse Glimmer 30BCyberSaint CyberStrong
Three alternativesMaxxsure, RiskLens, SAFE Security
AxioChangedagainst: Kovrr, RiskLens, SAFE SecuritySAFE Security
Three alternativesAxio, Balbix, RiskLens
against: ThreatConnect
Fair TPRM, FairCRQ
One alternativeMitigata
against: Axio, Risk Cloud Quantify, RiskLens, SAFE Security
no first choiceagainst: Kovrr, SAFE Security
Bold is the first choiceAlternatives are counted; the count opens them.What the answer argued against

The record

One row per call: the version string exactly as returned, whether the model searched, sources cited, and latency. Full answer text is in the free responses file. Download the record
Eighty-four rows: every prompt, every model, every answer.
PromptModelVersion stringTime (UTC)SearchedSourcesLatency
Direct recommendationClaude Haiku 4.5claude-haiku-4-5-202510012026-10-04 23:44yes158 s
Direct recommendationGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-05 01:38yes35 s
Direct recommendationGemini 3.5 Flashgemini-3.5-flash2026-10-04 23:35yes830 s
Direct recommendationPerplexity Sonarsonar2026-10-04 23:39yes244 s
Direct recommendationGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-05 01:18yes2011 s
Direct recommendationMistral Smallmistral/mistral-small via mistral2026-10-04 23:54yes177 s
Direct recommendationDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-04 23:46yes1954 s
Direct recommendationLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-05 01:54yes52 s
Direct recommendationQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-05 00:40yes513 s
Direct recommendationKimi K2moonshotai/kimi-k2 via novita2026-10-05 00:44yes1339 s
Direct recommendationGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-04 23:56yes1329 s
Direct recommendationMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-05 01:32yes511 s
Direct recommendationGPT-6 Lunagpt-6-luna2026-10-05 01:12yes316 s
Direct recommendationMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-04 22:17yes1414 s
ParaphraseClaude Haiku 4.5claude-haiku-4-5-202510012026-10-05 01:23no03 s
ParaphraseGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-05 01:43yes44 s
ParaphraseGemini 3.5 Flashgemini-3.5-flash2026-10-05 00:04yes1524 s
ParaphrasePerplexity Sonarsonar2026-10-05 01:50yes263 s
ParaphraseGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-04 22:16yes208 s
ParaphraseMistral Smallmistral/mistral-small via mistral2026-10-04 23:09yes56 s
ParaphraseDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-05 00:00yes2023 s
ParaphraseLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-04 22:30yes52 s
ParaphraseQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-05 01:17yes869 s
ParaphraseKimi K2moonshotai/kimi-k2 via novita2026-10-04 22:57yes2323 s
ParaphraseGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-05 00:42yes1528 s
ParaphraseMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-05 01:37yes1223 s
ParaphraseGPT-6 Lunagpt-6-luna2026-10-05 00:25yes318 s
ParaphraseMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-05 01:36yes2031 s
ComparativeClaude Haiku 4.5claude-haiku-4-5-202510012026-10-05 01:23yes98 s
ComparativeGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-05 01:00yes411 s
ComparativeGemini 3.5 Flashgemini-3.5-flash2026-10-05 00:42yes1327 s
ComparativePerplexity Sonarsonar2026-10-05 00:57yes234 s
ComparativeGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-05 00:44yes2116 s
ComparativeMistral Smallmistral/mistral-small via mistral2026-10-05 00:46yes1611 s
ComparativeDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-05 01:20yes2338 s
ComparativeLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-05 00:28yes53 s
ComparativeQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-05 01:45no028 s
ComparativeKimi K2moonshotai/kimi-k2 via novita2026-10-05 01:44yes1931 s
ComparativeGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-04 23:47yes2451 s
ComparativeMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-04 22:42yes1837 s
ComparativeGPT-6 Lunagpt-6-luna2026-10-05 01:35yes724 s
ComparativeMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-05 01:29yes1934 s
Budget constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-05 01:41yes1610 s
Budget constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-05 01:02yes34 s
Budget constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-04 22:26yes1120 s
Budget constrainedPerplexity Sonarsonar2026-10-05 00:33yes212 s
Budget constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-04 23:49yes2310 s
Budget constrainedMistral Smallmistral/mistral-small via mistral2026-10-05 01:38yes146 s
Budget constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-05 01:53yes1847 s
Budget constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-04 23:52yes52 s
Budget constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-04 23:21no033 s
Budget constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-05 01:23yes1917 s
Budget constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-05 01:18yes1517 s
Budget constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-05 00:07yes1025 s
Budget constrainedGPT-6 Lunagpt-6-luna2026-10-04 23:46yes321 s
Budget constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-05 01:28yes1413 s
Scale constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-05 01:41no08 s
Scale constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-05 00:43no07 s
Scale constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-04 22:27yes1326 s
Scale constrainedPerplexity Sonarsonar2026-10-04 23:29yes175 s
Scale constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-05 01:26yes2510 s
Scale constrainedMistral Smallmistral/mistral-small via mistral2026-10-04 22:23no07 s
Scale constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-05 01:35yes1755 s
Scale constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-05 01:41yes52 s
Scale constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-05 00:38yes938 s
Scale constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-05 01:12yes2447 s
Scale constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-05 01:42yes15103 s
Scale constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-05 01:29no07 s
Scale constrainedGPT-6 Lunagpt-6-luna2026-10-04 23:50yes214 s
Scale constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-05 00:13no03 s
Negative framingClaude Haiku 4.5claude-haiku-4-5-202510012026-10-04 23:04yes199 s
Negative framingGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-04 22:09yes46 s
Negative framingGemini 3.5 Flashgemini-3.5-flash2026-10-05 00:03yes1727 s
Negative framingPerplexity Sonarsonar2026-10-04 22:52yes205 s
Negative framingGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-05 00:45yes239 s
Negative framingMistral Smallmistral/mistral-small via mistral2026-10-04 22:17yes55 s
Negative framingDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-05 01:13yes1950 s
Negative framingLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-05 00:22yes53 s
Negative framingQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-05 00:52no027 s
Negative framingKimi K2moonshotai/kimi-k2 via novita2026-10-04 22:32yes2426 s
Negative framingGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-05 00:40yes2227 s
Negative framingMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-05 01:43no09 s
Negative framingGPT-6 Lunagpt-6-luna2026-10-04 22:26yes316 s
Negative framingMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-04 22:34yes1321 s

Normalization in this category

Every judgment call made between the raw labels and the numbers above, listed so it is visible and reversible.

ShowHide
Category-scoped readings
CyberSaint read as CyberSaint CyberStrong
CyberSaint (CyberStrong Platform) read as CyberSaint CyberStrong
CyberSaint (CyberStrong platform) read as CyberSaint CyberStrong
CyberSaint (CyberStrong) read as CyberSaint CyberStrong
Cybersaint read as CyberSaint CyberStrong
SAFE read as SAFE One
Safe read as SAFE One
Unresolved, counted raw
Basic FAIR Analysis
Bitsight Cyber Quant / RiskRecon
Blacksmith
CISA CSET Tool (Free)
CISA’s CSET
CyanoRisk
CyberQuant
Databeagle
Deep-Insight’s Deep-Dive platform
FAIR Excel Spreadsheet (Free)
FAIR Institute partners
FAIR Institute resources
FAIR-U Workbook
Hive Systems Quantitative Cyber Risk Assessment Tool
HiveSystems Quantitative Risk Assessment Tool
KPMG CRI
Krare Insights
Logit
Mitigata
NIST SP 800-30 Risk Assessment Guide (Free)
NIST’s Cybersecurity Framework
Open FAIR tools / spreadsheet-based FAIR
OpenFAIR Institute
Ostrich Cyber-Risk (Birdseye)
Palantir Technologies
PowerBI
PyRisk / RiskLib
RQ Platform
RiskCloud (by MDR)
RiskCloud Quantify
SARA Open-Source
SafeSecurity
Security Decision Labs / FAIR cyber risk quantification toolkit
Security Decision Science GitHub tools
Simplicity
The FAIR Institute (Insight Manager)
Trustpilot
Vulc
Wolferdawg Cyber Risk Assessment
unitQ
Discontinued, still offered
No shut-down product was recommended here.

Follow Cyber risk quantification

An email the morning each edition publishes: where this category moved, where it held, and by how much against the noise floor. One address, confirmed by a click; a stop link in every email.

Already following? Everything you follow, with a stop for each.

← Compliance automationDLP →