RisqRadar
Cyber risk in dollars, not guesswork.
RisqRadar turns your controls, vulnerabilities, vendors, and audit posture into one financial model of loss, so you can tell the board how much risk you carry, which fix buys the most reduction per dollar, and prove it to an auditor.
Explore RisqRadarCRQ engine · 14+ frameworks · TPRM · audit-ready
Heat maps don't survive a board meeting.
A red-amber-green grid can't answer the only questions leadership actually asks: How much could this cost us? Which control spend reduces the most risk? Are we ready if the auditor shows up Monday?
RisqRadar answers all three from a single model: quantified in currency, backed by evidence, and defensible line by line.
One Platform, Four Jobs
Quantify the risk. Prove the compliance. Govern the exceptions. Watch the edges. Every module feeds the same graph, so evidence, controls, and dollars are reused across the business, never re-entered.
Loss, modeled, not colored in
A real quantitative engine, not a scored spreadsheet.
- ✓Monte Carlo loss-exceedance simulation that puts a dollar figure and a probability on every scenario
- ✓Capture actual loss events and backtest the model against them
- ✓Estimator calibration and confidence surfaced next to each figure
- ✓Risk appetite and tolerance with breach alerts the moment a line is crossed
Audit-ready, continuously
One control engine across cyber, privacy, and industrial-safety regimes.
- ✓NIST CSF, ISO 27001, DORA, NIS2, GDPR, HIPAA, OSHA PSM, EPA RMP, PHMSA, DOT, DOE, USCG and more
- ✓Coverage and gap views, evidence linking, and PBC request tracking
- ✓Type-II observation-window tracking computed from your validation history
- ✓A shareable Trust Center and per-auditor access portals
Exceptions with a shelf life
Waivers that are time-boxed, attested, and re-checked automatically.
- ✓Policies mapped to the controls they satisfy, counted as evidence automatically
- ✓Compensating controls that actually move the modeled likelihood
- ✓Security-exception register with dual attestation and segregation of duties
- ✓Automated recertification, so every exception is renewed or lapsed on schedule
Third parties and change, tracked
The edges of your risk, monitored without extra headcount.
- ✓Vendor register with on-demand external security scans and outbound questionnaires
- ✓New-technology risk assessments, with an ISO 42001 / NIST AI RMF addendum for AI
- ✓A regulatory-change monitor that flags a framework when the rules move
- ✓Jira and ServiceNow ticketing and a unified notification center, built in
The QRM™ Methodology
NIST 800-30
Federal standard for risk assessment
Hubbard Calibration
Proven techniques to fix overconfidence
Monte Carlo
Loss-exceedance modeling of uncertainty
Backtested
Real loss events checked against the model
The Five Factors of QRM
| Factor | What It Measures |
|---|---|
| TPThreat Probability | How often attackers try |
| RRRealization Rate | How often they succeed |
| ISImpact Severity | Direct costs when they do |
| CICascading Impact | Secondary costs that follow |
| IMImpact Multiplier | Probability of those secondaries |
The Result: Annualized Loss Exposure
ALE = (TP × RR) × (IS + (CI × IM))
Run through Monte Carlo simulation, it produces a loss-exceedance curve: the expected annual loss and the 1-in-20-year tail, instead of a single flattering number.
Why RisqRadar
Built to be believed by the board and the auditor.
Dollars, not scores
A genuine actuarial-style engine (loss exceedance, calibration, backtesting), so risk is a number you can budget against, not a color you argue about.
Breadth in one engine
Cyber, privacy, and industrial-safety frameworks share one model. Map a control once; it counts everywhere it applies, across every business unit.
Evidence-grade access
A database-enforced auditor role confines an outside reviewer to exactly the assessment you grant: read-only, and provable, not just hidden in the UI.
Secure by construction
Per-tenant isolation and envelope-encrypted connector credentials. Bring your own keys for external scanners, so your secrets stay yours.
Frameworks & Regimes, One Control Library
Map a control once. It counts everywhere it applies: cyber, privacy, and industrial-safety regimes alike.
What's Inside
Every module writes to the same risk graph. An asset, a control, a policy, or a vendor is entered once and reused everywhere it matters.
Inventory
- Applications
- Assets
- Service Accounts
- App Registrations
- Copilot Agents
- Agent Governance
Risk Quantification
- Risk Scenarios
- Controls
- Key-Person Risk
- Portfolio
- Loss Events
- Calibration
Findings & Treatment
- Vulnerabilities
- Risk Register
- Remediation & POA&M
- Risk Acceptance
- Control Exceptions
Third Parties
- Vendors
- Contract Portfolio
- Contract Cybersecurity Review
- Breach Monitor
Compliance
- Audit Readiness
- Policies
- Document Library
- Risk Assessments
- Access Review
Resilience & Insights
- Business Impact
- Continuity
- Incidents
- Analytics
- Alerts
- AI ROI
AI That Guides, Not Replaces
Benchmarks, validation, and narrative at every step, but never a single "correct" answer handed down. You remain in control of the estimate.
AI Calibration Coach
Analyzes calibration performance, detects cognitive biases (anchoring, overconfidence, availability), and prescribes exercises that improve estimation accuracy.
AI Estimation Assistant
Available on every input field. Industry benchmarks, range validation, and decomposition help, referencing sources like Verizon DBIR and IBM/Ponemon.
AI Scenario Generator
Reads your organization profile and proposes relevant risk scenarios with pre-populated QRM estimates, cutting time-to-first-number from weeks to minutes.
AI Report Narrator
Generates board-ready talking points, executive summaries, and Q&A prep. Pick the audience (Board, Executive, Technical, Audit) and get tailored language.
AI Vulnerability Enrichment
Turns a raw scanner finding into a modeled impact: likely exploit path, affected controls, and the QRM factors it moves, instead of another CVSS number.
AI Compliance Gap Summary
Reads coverage across a framework and writes the gap narrative: what is missing, what evidence would close it, and what it is worth in risk reduction.
Connected to the Tools You Run
Connector credentials are envelope-encrypted per tenant, and you can bring your own keys for external scanners.
Microsoft Entra ID
App registrations, service principals, group attestation
Microsoft Graph & SharePoint
Policy search, attach, and approved-version pinning
Tenable, Qualys, Rapid7
Vulnerability ingestion mapped to controls and scenarios
CISA KEV & Shodan
Known-exploited enrichment and external exposure checks
Jira & ServiceNow
Two-way remediation ticketing with deep links back
SIEM egress
Splunk and Sentinel-compatible event and agent-metric streams
Who It's For
Made for complex, multi-entity organizations. When you're accountable for many business units, many frameworks, and many vendors, RisqRadar puts the whole picture, and its price tag, in one place.
Risk officers
Quantified exposure to take to the board, and the ROI case for every control investment.
Compliance & audit
Continuous evidence, coverage and gap tracking, and auditor access that is safe to hand out.
IT & security
Vulnerabilities, controls, and third-party posture tied straight to loss and to the frameworks they satisfy.
Business units
A simple intake for new-technology requests, with no login, just a secure link.
Trusted Methodology
Based on Proven Research
"When people give 90% confidence intervals, they typically contain the true answer only 50-60% of the time."
Douglas Hubbard, "How to Measure Anything"
NIST Aligned
QRM maps directly to NIST Special Publication 800-30, the federal standard for conducting risk assessments.
- • Regulatory alignment
- • Audit defensibility
- • Framework compatibility
Industry Benchmarks
The AI Estimation Assistant references:
- • Verizon Data Breach Investigations Report
- • IBM/Ponemon Cost of a Data Breach
- • Coveware Ransomware Reports
- • Mandiant M-Trends
- • HHS HIPAA Penalty Database
Stop reporting risk in colors.
Book a walkthrough and we'll model a scenario from your own environment: a loss-exceedance curve, a control-ROI case, and an audit-readiness snapshot in one session.
Request a Demo