AI Indexes
IT AI Index
Index › Security operations › Cyber risk quant › Enterprise › October 2026 Edition

Cyber risk quantification for enterprise buyers

Asked as “cyber risk quantification tool”, and as “CRQ platform”, on behalf of an enterprise B2B company. 43 first choices recorded across the direct, paraphrase, budget and scale prompts, fourteen models each. Added to the October 2026 Edition on October 4, 2026; its answers are read by the distilled judge (ai-indexes-judge-qwen3-14b-run3), not the claude-opus-5 judge of the earlier categories: how the two compare.
Standing · first-choice share
56%
Clear leader
56SAFE Security09RiskLens07Axio28others

56% of first choices, clear leader.

By buyer segment

The same question asked on behalf of a different buyer. Each standing is computed within its segment; they sit side by side and are never added together.

The standing

Share is the count of first choices across the direct, paraphrase, budget and scale prompts, over all fourteen models, for an enterprise B2B company. Ordered by share.
ProductFirst-choice shareNegative rateLabelsQuadrant
01SAFE Security56%2%40endorsed leader
02RiskLens9%0%25accepted challenger
03Axio7%2%40accepted challenger
04Balbix2%0%22accepted challenger
Show the three products at 0%, ordered by negative rate
06CyberSaint CyberStrong0%12%17accepted challenger
07Bitsight0%8%13accepted challenger
05Kovrr0%2%44accepted challenger
Bars are the share of first choices, 0 to 100Every product with at least 10 labels here. Every product name links to its product page.
All ten head-to-head pages: the top five products, each against each

One product takes 56% of first choices here, so the chart would put six markers in one corner and one at the far edge. The two measurements it plots are columns in the standing above: share, and the negative label rate. Zero products carry a negative rate above 25% in this category.

What they warned about

Five of fourteen models held their first choice under the paraphrase. Claude Haiku 4.5, GPT-5.4 mini, Gemini 3.5 Flash, Mistral Small, Qwen 3.7 Flash, GLM 4.7 FlashX, MiniMax M2.5, GPT-6 Luna and Muse Glimmer 30B changed. A high negative share on a product with few labels is a warning. A low share on a product with many labels is salience, not sentiment.
Archer
40%
2 of 5 labels negative · 2 of 14 models · 1 hard negative
“GRC platforms (ServiceNow, Archer, OneTrust, etc.) now tout "CRQ capabilities"” DeepSeek V4 Flash, negative prompt
CyberSaint CyberStrong
12%
2 of 17 labels negative · 2 of 14 models · 1 hard negative
“Avoid mid-market tools like CyberSaint ($30K–$80K) as they lack depth for thousands of users.” Grok 4.1 Fast, budget prompt
OneTrust
67%
2 of 3 labels negative · 2 of 14 models · 1 hard negative
“GRC platforms (ServiceNow, Archer, OneTrust, etc.) now tout "CRQ capabilities"” DeepSeek V4 Flash, negative prompt
Open FAIR
100%
1 of 1 labels negative · 1 of 14 models · 1 hard negative
“Pure consulting-led or basic FAIR spreadsheets (e.g., legacy Open FAIR tools) lack scalability for large enterprises.” Grok 4.1 Fast, negative prompt

What they cite

Citations exist only for the models that return a source list: fourteen of the fourteen in this edition, and all six flagship models on the expanded tier.

Sites the answers cite

80 of 84 answers in this category came back with a source list, from 14 of 14 models: citations where the model returns them, or the search results it consulted. 1182 links across 260 sites, every framing counted. Ranked by the number of answers carrying the site or page. None of the 252 answers across every segment cited this index's own page for the category.

vendor site · Kovrr48 answers · 85 citations · 13 models
44 answers · 53 citations · 12 models
vendor site · Bitsight38 answers · 48 citations · 12 models
vendor site · CyberSaint34 answers · 44 citations · 12 models
34 answers · 44 citations · 10 models
30 answers · 37 citations · 10 models
vendor site · SAFE27 answers · 61 citations · 10 models
vendor site · G226 answers · 32 citations · 11 models
24 answers · 25 citations · 11 models
22 answers · 25 citations · 9 models
vendor site · MetricStream18 answers · 25 citations · 8 models
17 answers · 18 citations · 8 models

Pages the answers cite

The ten pages named in the most answers, by full address. A page here is one the models returned with a recommendation, not one the index endorses.

Search against answers

Each company's standing in the answers beside its site's footprint in Google search, one row a site: the products the models named on it with their shares, and the share they add up to; monthly searches on Google, and DataForSEO's estimate of AI search demand (modeled from search signals, directional, not a count of queries to any assistant), for the most-searched of the company's and its products' names (the name is in each row's hover text); estimated monthly organic visits to the site; and its best position in Google's top ten for “best cyber risk quantification tool”, “cyber risk quantification tool”, “cyber risk quantification tools”. US estimates from DataForSEO and Google's Ads Transparency Center. A small company's site, or a mid-sized company's site for its flagship, is marked company; a product on a large parent's site (Google, Microsoft) has no site figures. A column with no figures for this category is left out, and an empty cell means none were seen, not none exist. Two measurements side by side: neither is read as the cause of the other.
Company and productsShareOwn site citedName searches, GoogleAI search demand, est.Organic visitsGoogle ads, last 30 daysBest Google position
SAFE One safe.security
SAFE Security 56%, SAFE One 7%
63%1152,4005,4961,015,372128
RiskLens risklens.com9%84900
Axio axio.com7%965,4003,6541,8150
Balbix balbix.com2%464805
Axio3602%500
RiskRecon riskrecon.com2%1572092,5460
Derive Risk deriverisk.com2%2
CyberStrong2%
Derive2%
Safe Security – acquired RiskLens2%

Google's top ten for the three searches hold 26 sites; 5 of them are among the sites the models cited here (cybersaint.io, kovrr.com, metricstream.com, safe.security, vcso.ai). The first result for “best cyber risk quantification tool” is cybersierra.co.

How they answered

Six framings of the same buying question, each sent to every model in a fresh session with search on. One row per model, so a row shows whether it held its answer under rewording, what it named when cost was the constraint, and what it argued against. Computed from the raw judge labels.
ShowHide
ModelDirect“What is the best cyber risk quantification tool for an enterprise B2B company?”Paraphrase“Which CRQ platform would you recommend to a large B2B company with thousands of employees?”Comparative“What are the top enterprise-grade cyber risk quantification tools and how do they differ?”Budget-constrained“What is the best cyber risk quantification tool for a large company that needs predictable total cost across thousands of users?”Scale-constrained“We are a 5,000 person company with SSO, SOC 2 and procurement review requirements evaluating a cyber risk quantification tool. What should we look at?”Negative“Which cyber risk quantification tools should a large enterprise avoid or be cautious about?”
Claude Haiku 4.5no first choiceSAFE SecurityChangedRiskLens, SAFE Security
Five alternativesArcher, Balbix, CyberSaint CyberStrong, Kovrr, LogicGate Risk Cloud
SAFE Security
Three alternativesBitsight, Kovrr, MetricStream
no first choiceagainst: FAIR Model, LogicGate, MetricStream, OCTAVE Method
GPT-5.4 miniSAFE Security
Two alternativesFAIR, Gartner Third-Party Cybersecurity Insights
ServiceNowChanged
One alternativeRiskLens
RiskLens, SAFE Security
One alternativeCYE
against: Drata, Vanta
SAFE Security
Two alternativesAxio, Qualys ETM
no first choicenothing named
Gemini 3.5 FlashSAFE Security
Three alternativesAxio, CyberSaint CyberStrong, Kovrr
SAFE OneChanged
Two alternativesAxio, Kovrr
SAFE Security
Five alternativesAxio, CyberSaint CyberStrong, DeNexus, Kovrr, ThreatConnect
CyberStrong
Four alternativesKovrr, LogicManager, SAFE One, SimpleRisk
no first choiceagainst: Bitsight, SecurityScorecard
Perplexity SonarSAFE Security
Four alternativesAxio, Black Kite, Kovrr, RiskLens
SAFE SecurityHeld
One alternativeAxio
no first choiceAxio, SAFE Security
Two alternativesKovrr, RiskLens
no first choicenothing named
Grok 4.1 FastSAFE Security
Three alternativesAxio, Balbix, Kovrr
SAFE SecurityHeld
Two alternativesBalbix, Kovrr
SAFE Security
Four alternativesAxio, Balbix, KPMG, Kovrr
SAFE Security
Four alternativesAxio, Balbix, Kovrr, Resilience
against: CyberSaint CyberStrong
RiskLens
Two alternativesBalbix, Kovrr
against: Axio, Hyver by CYE, Open FAIR, Resilience, SAFE Security
Mistral SmallAxio, SAFE Security
Two alternativesKovrr, RiskRecon
RiskLens, SAFE SecurityChanged
Two alternativesC-Risk, Kovrr
SAFE Security
Four alternativesAxio, Balbix, KPMG, Kovrr
SAFE Security
Two alternativesKovrr, Resilience
no first choicenothing named
DeepSeek V4 FlashSAFE Security
Three alternativesAxio, KPMG Cyber Risk Insights, Kovrr
SAFE SecurityHeld
Two alternativesAxio, Balbix
against: Kovrr
SAFE Security
Four alternativesAxio, CyQuant, Kovrr, RiskLens
SAFE Security
Three alternativesBalbix, Bitsight Financial Quantification, RiskLens
SAFE Security
Four alternativesAxio, CyberSaint CyberStrong, Kovrr, RiskLens
against: Archer, CyberSaint CyberStrong, OneTrust, ServiceNow
Llama 4 Maverickno first choiceno first choiceHeldno first choiceno first choiceSAFE Security
Four alternativesAxio, Balbix, LogicGate Risk Cloud, MetricStream
nothing named
Qwen 3.7 FlashAxio, RiskRecon
Two alternativesKovrr, Resilience
SqualifyChanged
Three alternativesKovrr, Mastercard Cyber Quant, X-Analytics
SAFE Security
Two alternativesAxio, ThreatConnect
RiskLens
Two alternativesLogicGate One, Wiz
against: Diligent
no first choiceagainst: Archer, OneTrust, ServiceNow Integrated Risk Management
Kimi K2SAFE Security
Two alternativesAxio, Balbix Security Cloud
SAFE SecurityHeld
Three alternativesAxio, Balbix, Kovrr
SAFE Security
Five alternativesAxio, Bitsight, Citalid, Kovrr, Tenable
Derive Risk
Two alternativesAxio360, SAFE Security
no first choicenothing named
GLM 4.7 FlashXBalbix, SAFE Security
Three alternativesAxio, CyberSaint CyberStrong, KPMG
no first choiceChangedno first choice
Seven alternativesBitsight, CyQuant, CyberCube Analytics, Kovrr, RiskLens, SecurityScorecard, UpGuard
SAFE Security
Two alternativesBalbix, Observeri
no first choicenothing named
MiniMax M2.5no first choiceSAFE SecurityChanged
Three alternativesAxio, Balbix, Kovrr
SAFE Security
Five alternativesAxio, Balbix, Bitsight, KPMG Cyber Risk Insights, ServiceNow Integrated Risk Management
no first choiceno first choicenothing named
GPT-6 LunaAxio360
Two alternativesKovrr, SAFE One
SAFE OneChanged
One alternativeAxio
no first choiceDerive
Two alternativesAxio, SAFE One
no first choicenothing named
Muse Glimmer 30BRiskLens
Six alternativesAxio360, Black Kite, Kovrr, RiskRecon, SAFE Security, SecurityScorecard
SAFE OneChanged
Three alternativesAxio, Balbix, RiskLens
SAFE Security
Four alternativesAxio, CyberSaint CyberStrong, KPMG, RiskLens
against: ThreatConnect
Safe Security – acquired RiskLens
Three alternativesAxio, Derive Risk, MetricStream
no first choiceagainst: RiskLens/Safe Security
Bold is the first choiceAlternatives are counted; the count opens them.What the answer argued against

The record

One row per call: the version string exactly as returned, whether the model searched, sources cited, and latency. Full answer text is in the free responses file. Download the record
Eighty-four rows: every prompt, every model, every answer.
PromptModelVersion stringTime (UTC)SearchedSourcesLatency
Direct recommendationClaude Haiku 4.5claude-haiku-4-5-202510012026-10-04 23:39yes97 s
Direct recommendationGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-05 01:46yes44 s
Direct recommendationGemini 3.5 Flashgemini-3.5-flash2026-10-05 00:25yes2131 s
Direct recommendationPerplexity Sonarsonar2026-10-05 00:57yes272 s
Direct recommendationGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-04 22:19yes2312 s
Direct recommendationMistral Smallmistral/mistral-small via mistral2026-10-05 01:53yes55 s
Direct recommendationDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-05 00:58yes2161 s
Direct recommendationLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-04 22:26yes52 s
Direct recommendationQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-04 23:53yes932 s
Direct recommendationKimi K2moonshotai/kimi-k2 via novita2026-10-05 01:00yes2131 s
Direct recommendationGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-05 01:25yes1440 s
Direct recommendationMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-04 22:34yes1034 s
Direct recommendationGPT-6 Lunagpt-6-luna2026-10-05 00:30yes416 s
Direct recommendationMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-05 01:11yes1520 s
ParaphraseClaude Haiku 4.5claude-haiku-4-5-202510012026-10-05 00:32yes96 s
ParaphraseGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-05 01:32yes25 s
ParaphraseGemini 3.5 Flashgemini-3.5-flash2026-10-04 22:51yes1626 s
ParaphrasePerplexity Sonarsonar2026-10-05 01:49yes332 s
ParaphraseGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-05 00:30yes239 s
ParaphraseMistral Smallmistral/mistral-small via mistral2026-10-05 00:45yes53 s
ParaphraseDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-05 01:25yes2338 s
ParaphraseLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-05 01:46yes52 s
ParaphraseQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-04 23:09yes540 s
ParaphraseKimi K2moonshotai/kimi-k2 via novita2026-10-04 22:21yes2023 s
ParaphraseGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-04 22:22yes2519 s
ParaphraseMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-04 23:20yes923 s
ParaphraseGPT-6 Lunagpt-6-luna2026-10-04 22:49yes116 s
ParaphraseMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-05 00:42yes2321 s
ComparativeClaude Haiku 4.5claude-haiku-4-5-202510012026-10-05 01:21yes99 s
ComparativeGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-05 00:22yes1112 s
ComparativeGemini 3.5 Flashgemini-3.5-flash2026-10-04 23:06yes2236 s
ComparativePerplexity Sonarsonar2026-10-05 01:00yes184 s
ComparativeGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-05 01:38yes1711 s
ComparativeMistral Smallmistral/mistral-small via mistral2026-10-05 00:16yes1712 s
ComparativeDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-05 01:45yes2043 s
ComparativeLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-04 23:05yes52 s
ComparativeQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-05 01:55yes1452 s
ComparativeKimi K2moonshotai/kimi-k2 via novita2026-10-05 00:17yes2167 s
ComparativeGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-04 22:54yes2370 s
ComparativeMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-04 22:33yes2530 s
ComparativeGPT-6 Lunagpt-6-luna2026-10-05 01:08yes1039 s
ComparativeMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-05 00:43yes2240 s
Budget constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-05 01:04yes179 s
Budget constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-04 23:39yes65 s
Budget constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-04 22:41yes2029 s
Budget constrainedPerplexity Sonarsonar2026-10-04 22:32yes244 s
Budget constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-04 22:35yes1511 s
Budget constrainedMistral Smallmistral/mistral-small via mistral2026-10-05 00:16yes53 s
Budget constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-05 00:13yes2422 s
Budget constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-05 01:46yes52 s
Budget constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-04 22:50no028 s
Budget constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-05 00:17yes2138 s
Budget constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-05 00:32yes22225 s
Budget constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-05 01:38yes2151 s
Budget constrainedGPT-6 Lunagpt-6-luna2026-10-05 01:21yes223 s
Budget constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-04 23:11yes2233 s
Scale constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-04 23:49yes1713 s
Scale constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-05 01:07yes511 s
Scale constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-05 01:32yes627 s
Scale constrainedPerplexity Sonarsonar2026-10-05 01:19yes168 s
Scale constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-05 00:04yes1810 s
Scale constrainedMistral Smallmistral/mistral-small via mistral2026-10-05 00:48no010 s
Scale constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-05 01:27yes2352 s
Scale constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-05 01:43yes54 s
Scale constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-04 23:56no027 s
Scale constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-05 01:07yes1521 s
Scale constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-04 23:54yes22195 s
Scale constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-05 01:01yes1571 s
Scale constrainedGPT-6 Lunagpt-6-luna2026-10-05 01:21yes324 s
Scale constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-05 01:02yes1420 s
Negative framingClaude Haiku 4.5claude-haiku-4-5-202510012026-10-05 00:51yes1813 s
Negative framingGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-05 01:16yes47 s
Negative framingGemini 3.5 Flashgemini-3.5-flash2026-10-05 00:57yes1828 s
Negative framingPerplexity Sonarsonar2026-10-05 00:52yes204 s
Negative framingGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-05 00:39yes2118 s
Negative framingMistral Smallmistral/mistral-small via mistral2026-10-05 01:09yes55 s
Negative framingDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-04 23:46yes2271 s
Negative framingLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-05 01:15yes53 s
Negative framingQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-04 22:12no034 s
Negative framingKimi K2moonshotai/kimi-k2 via novita2026-10-04 23:42yes2324 s
Negative framingGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-05 00:16yes1849 s
Negative framingMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-05 01:56yes2172 s
Negative framingGPT-6 Lunagpt-6-luna2026-10-04 23:15yes418 s
Negative framingMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-05 01:15yes1932 s

Normalization in this category

Every judgment call made between the raw labels and the numbers above, listed so it is visible and reversible.

ShowHide
Category-scoped readings
CyberSaint read as CyberSaint CyberStrong
CyberSaint (CyberStrong) read as CyberSaint CyberStrong
SAFE read as SAFE One
Unresolved, counted raw
Axio Global
Balbix Security Cloud
BitSight RiskRecon/Cyber Quant
Cyber Horizon
CyberStrong (by CyberSaint)
DeNexus (DeRISK Platform)
FAIR Model
Gartner Third-Party Cybersecurity Insights
Hyver by CYE
KPMG firms
LogicGate One
OCTAVE Method
Observeri
Qualys ETM
S&P Global/PRA Group
Safe Security – acquired RiskLens
Discontinued, still offered
No shut-down product was recommended here.
← Compliance automationDLP →