RisqRadar

Cyber risk in dollars, not guesswork.

RisqRadar turns your controls, vulnerabilities, vendors, and audit posture into one financial model of loss, so you can tell the board how much risk you carry, which fix buys the most reduction per dollar, and prove it to an auditor.

Explore RisqRadar

CRQ engine · 14+ frameworks · TPRM · audit-ready

Heat maps don't survive a board meeting.

A red-amber-green grid can't answer the only questions leadership actually asks: How much could this cost us? Which control spend reduces the most risk? Are we ready if the auditor shows up Monday?

RisqRadar answers all three from a single model: quantified in currency, backed by evidence, and defensible line by line.

One Platform, Four Jobs

Quantify the risk. Prove the compliance. Govern the exceptions. Watch the edges. Every module feeds the same graph, so evidence, controls, and dollars are reused across the business, never re-entered.

01
Quantify

Loss, modeled, not colored in

A real quantitative engine, not a scored spreadsheet.

  • Monte Carlo loss-exceedance simulation that puts a dollar figure and a probability on every scenario
  • Capture actual loss events and backtest the model against them
  • Estimator calibration and confidence surfaced next to each figure
  • Risk appetite and tolerance with breach alerts the moment a line is crossed
02
Comply

Audit-ready, continuously

One control engine across cyber, privacy, and industrial-safety regimes.

  • NIST CSF, ISO 27001, DORA, NIS2, GDPR, HIPAA, OSHA PSM, EPA RMP, PHMSA, DOT, DOE, USCG and more
  • Coverage and gap views, evidence linking, and PBC request tracking
  • Type-II observation-window tracking computed from your validation history
  • A shareable Trust Center and per-auditor access portals
03
Govern

Exceptions with a shelf life

Waivers that are time-boxed, attested, and re-checked automatically.

  • Policies mapped to the controls they satisfy, counted as evidence automatically
  • Compensating controls that actually move the modeled likelihood
  • Security-exception register with dual attestation and segregation of duties
  • Automated recertification, so every exception is renewed or lapsed on schedule
04
Watch

Third parties and change, tracked

The edges of your risk, monitored without extra headcount.

  • Vendor register with on-demand external security scans and outbound questionnaires
  • New-technology risk assessments, with an ISO 42001 / NIST AI RMF addendum for AI
  • A regulatory-change monitor that flags a framework when the rules move
  • Jira and ServiceNow ticketing and a unified notification center, built in

The QRM™ Methodology

NIST 800-30

Federal standard for risk assessment

Hubbard Calibration

Proven techniques to fix overconfidence

Monte Carlo

Loss-exceedance modeling of uncertainty

Backtested

Real loss events checked against the model

The Five Factors of QRM

FactorWhat It Measures
TPThreat ProbabilityHow often attackers try
RRRealization RateHow often they succeed
ISImpact SeverityDirect costs when they do
CICascading ImpactSecondary costs that follow
IMImpact MultiplierProbability of those secondaries

The Result: Annualized Loss Exposure

ALE = (TP × RR) × (IS + (CI × IM))

Run through Monte Carlo simulation, it produces a loss-exceedance curve: the expected annual loss and the 1-in-20-year tail, instead of a single flattering number.

Why RisqRadar

Built to be believed by the board and the auditor.

$

Dollars, not scores

A genuine actuarial-style engine (loss exceedance, calibration, backtesting), so risk is a number you can budget against, not a color you argue about.

Breadth in one engine

Cyber, privacy, and industrial-safety frameworks share one model. Map a control once; it counts everywhere it applies, across every business unit.

Evidence-grade access

A database-enforced auditor role confines an outside reviewer to exactly the assessment you grant: read-only, and provable, not just hidden in the UI.

Secure by construction

Per-tenant isolation and envelope-encrypted connector credentials. Bring your own keys for external scanners, so your secrets stay yours.

Frameworks & Regimes, One Control Library

Map a control once. It counts everywhere it applies: cyber, privacy, and industrial-safety regimes alike.

NIST CSFNIST 800-53NIST 800-30ISO 27001ISO 42001NIST AI RMFSOC 2Trust Controls BaselineDORANIS2GDPRHIPAAOSHA PSMEPA RMPPHMSA HMRDOT FMCSADOE 851USCG 33 CFR

What's Inside

Every module writes to the same risk graph. An asset, a control, a policy, or a vendor is entered once and reused everywhere it matters.

Inventory

  • Applications
  • Assets
  • Service Accounts
  • App Registrations
  • Copilot Agents
  • Agent Governance

Risk Quantification

  • Risk Scenarios
  • Controls
  • Key-Person Risk
  • Portfolio
  • Loss Events
  • Calibration

Findings & Treatment

  • Vulnerabilities
  • Risk Register
  • Remediation & POA&M
  • Risk Acceptance
  • Control Exceptions

Third Parties

  • Vendors
  • Contract Portfolio
  • Contract Cybersecurity Review
  • Breach Monitor

Compliance

  • Audit Readiness
  • Policies
  • Document Library
  • Risk Assessments
  • Access Review

Resilience & Insights

  • Business Impact
  • Continuity
  • Incidents
  • Analytics
  • Alerts
  • AI ROI

AI That Guides, Not Replaces

Benchmarks, validation, and narrative at every step, but never a single "correct" answer handed down. You remain in control of the estimate.

AI Calibration Coach

Analyzes calibration performance, detects cognitive biases (anchoring, overconfidence, availability), and prescribes exercises that improve estimation accuracy.

AI Estimation Assistant

Available on every input field. Industry benchmarks, range validation, and decomposition help, referencing sources like Verizon DBIR and IBM/Ponemon.

AI Scenario Generator

Reads your organization profile and proposes relevant risk scenarios with pre-populated QRM estimates, cutting time-to-first-number from weeks to minutes.

AI Report Narrator

Generates board-ready talking points, executive summaries, and Q&A prep. Pick the audience (Board, Executive, Technical, Audit) and get tailored language.

AI Vulnerability Enrichment

Turns a raw scanner finding into a modeled impact: likely exploit path, affected controls, and the QRM factors it moves, instead of another CVSS number.

AI Compliance Gap Summary

Reads coverage across a framework and writes the gap narrative: what is missing, what evidence would close it, and what it is worth in risk reduction.

Connected to the Tools You Run

Connector credentials are envelope-encrypted per tenant, and you can bring your own keys for external scanners.

Microsoft Entra ID

App registrations, service principals, group attestation

Microsoft Graph & SharePoint

Policy search, attach, and approved-version pinning

Tenable, Qualys, Rapid7

Vulnerability ingestion mapped to controls and scenarios

CISA KEV & Shodan

Known-exploited enrichment and external exposure checks

Jira & ServiceNow

Two-way remediation ticketing with deep links back

SIEM egress

Splunk and Sentinel-compatible event and agent-metric streams

Who It's For

Made for complex, multi-entity organizations. When you're accountable for many business units, many frameworks, and many vendors, RisqRadar puts the whole picture, and its price tag, in one place.

Risk officers

Quantified exposure to take to the board, and the ROI case for every control investment.

Compliance & audit

Continuous evidence, coverage and gap tracking, and auditor access that is safe to hand out.

IT & security

Vulnerabilities, controls, and third-party posture tied straight to loss and to the frameworks they satisfy.

Business units

A simple intake for new-technology requests, with no login, just a secure link.

Trusted Methodology

Based on Proven Research

"When people give 90% confidence intervals, they typically contain the true answer only 50-60% of the time."

Douglas Hubbard, "How to Measure Anything"

NIST Aligned

QRM maps directly to NIST Special Publication 800-30, the federal standard for conducting risk assessments.

  • • Regulatory alignment
  • • Audit defensibility
  • • Framework compatibility

Industry Benchmarks

The AI Estimation Assistant references:

  • • Verizon Data Breach Investigations Report
  • • IBM/Ponemon Cost of a Data Breach
  • • Coveware Ransomware Reports
  • • Mandiant M-Trends
  • • HHS HIPAA Penalty Database

Stop reporting risk in colors.

Book a walkthrough and we'll model a scenario from your own environment: a loss-exceedance curve, a control-ROI case, and an audit-readiness snapshot in one session.

Request a Demo