Home / Risk quantification

An offer, delivered with you · not a product you switch on

Make cyber risk easier to compare, prioritise and explain.

Quantification earns its place when it supports a decision. MyRISK helps teams frame scenarios, estimate impact, record the assumptions behind the numbers, and give an investment or acceptance decision a rationale that still reads a year later.

Why now

The number is not the hard part. The reasoning behind it is.

Most quantification work fails not because the model is wrong, but because nobody can reconstruct how the figure was reached. Six months on, the scenario has moved, the assumptions are undocumented, and the decision it supported cannot be defended.

The useful version answers a question somebody is actually being asked: is this exposure worth funding, and what did we assume when we said so.

What usually prompts the conversation

  • Cyber risks are hard to compare against each other
  • Financial exposure is unclear
  • Investment trade-offs are difficult to explain
  • Assumptions are not recorded anywhere
  • Risk acceptance lacks a business rationale
  • Board reporting is either too technical or too generic

What the work produces

Decision-ready, and legible to whoever asks next.

Scenario definitions

The events being estimated, written so two people read them the same way.

Exposure estimates

Ranges rather than false precision, with what drives them stated.

Assumptions register

What was assumed, by whom, and what would change the answer.

Treatment options

What could be done, at what cost, against what reduction.

Board-ready reporting

The same analysis, at the altitude the audience needs.

A traceable record

The rationale, the actions and the review points, kept together.

Where it goes next

The work stands on its own. Where an investment decision follows, it leads to Trace.

When an investment decision follows

Quantification usually exists to justify spending money, or to justify not spending it. That decision is the one someone questions months later — so it belongs in Trace, where the numbers, the assumptions behind them, the authority and the later change stay together.

Explore Trace

When the analysis is the whole engagement

Scenario design, modelling and the reporting around it are consulting work, scoped and delivered with your team rather than bought as software. It is a complete piece of work on its own, and does not have to lead anywhere else.

Explore Consulting

Taught as well as practised

UNSW Business School is putting this in a classroom, and MyRISK is delivering it.

In September 2026 UNSW Business School announced a new series of short courses in cyber risk quantification and resilience. The first is Fundamentals of Cyber Risk Quantification — “practical approaches to understanding, assessing and communicating cyber risk for better-informed organisational decisions”, written for professionals connecting cybersecurity, risk management and business outcomes. UNSW names Risk2Solutions, TrendAI and MyRISK alongside it.

MyRISK develops and delivers the course. The same practice this page describes, taught to a university's standard and examined by its faculty.

Newly announced: UNSW has not yet published a schedule. UNSW Business School's announcement

Being straight about it

What this is, and what it is not.

  • This is an offer, not a product. It is delivered with you, and there is no quantification module to log into.
  • FAIR is a method, not a MyRISK product. Where a FAIR-style approach fits, that is how the work is framed — it is not something MyRISK sells you a licence to.
  • A number is not an assurance. Quantification supports a judgement; it does not replace one, and it is not a compliance opinion.

Which decision are you being asked to justify?

Bring that one. It is a better starting point than a model.