A collection of awesome projects, blog posts, books, and talks on quantifying risk
-
Updated
Apr 13, 2020
A collection of awesome projects, blog posts, books, and talks on quantifying risk
Interactive CRQ Monte Carlo simulation tool for quantifying cybersecurity risk using FAIR methodology. Built for EU SMBs, vCISOs, and security practitioners.
FAIR cyber risk quantification toolkits, agent-based control simulation (FAIR-CAM), threat event frequency estimator (PyPI), LLM classification validator (PyPI), Monte Carlo risk engine with IRIS benchmarks.
Reusable decision-science utilities for security: Monte Carlo, Bayes, Survival, VoI, light causal helpers.
Evidence-governed quantitative cyber risk — a trustworthy CLI and scenario engine where every number traces to a reviewed public source.
Bayesian risk modelling and quantification notebooks for cybersecurity
Local-first quantitative cyber risk platform built on the FAIR methodology: Monte Carlo simulation, portfolio aggregation, and executive reporting. No cloud, no telemetry. (Beta)
Cybersecurity risk intelligence dashboard analyzing CVE vulnerabilities, CVSS risk scores, and financial exposure using Power BI.
Simple risk quantification framework with scoring model and executive summary examples.
Threat modeling case study applying PASTA (7-stage) and FAIR (Monte Carlo) to quantify ransomware risk in a HIPAA-regulated SaaS environment. Includes control investment ROI analysis and presentation talking points.
Bayesian-inspired Impact Forecast Algorithm (IFA) for quantifying material impact risk
Open-source data breach cost predictor & cyber-risk quantification engine — IBM benchmarks + DPDP/GDPR penalties + Monte Carlo + security-investment ROI
What does a bad year cost — and can you prove the number? Which shared dependency drags everything down at once? Did an AI agent just touch a tool it never should have? How fast do you really detect? Three working tools answer — from seeded, sealed data you can re-check in your browser.
Agentic, controls-as-code GRC engine: one SCF-mapped control set → every framework. OSCAL-validated, FAIR-quantified, policy-as-code, human-gated AI. CI proves it.
FAIR Monte Carlo cyber risk quantification: translates technical vulnerabilities into probable financial loss distributions, then has Claude draft the board narrative. Next.js + Recharts + Trigger.dev + Supabase.
Vulnerability Financial Impact Engine — FAIR-lite Monte Carlo risk quantification that translates security findings into dollar-denominated expected loss
Vulnerability Financial Impact Engine — FAIR-lite Monte Carlo risk quantification that translates security findings into dollar-denominated expected loss
GitHub profile README: GRC engineering, FAIR cyber risk quantification, compliance-as-code, and AI-assisted GRC.
19 interactive Jupyter notebooks for statistical decision-making in security: Monte Carlo, Bayesian, survival analysis, causal inference, FAIR.
Cyberwrite — independent third-party profile of a public API surface, by API Evangelist. Cyberwrite is an AI-powered cyber insurance intelligence platform that turns raw data into explainable, defensible financial decisions for the cyber insurance lifecycle. Founded in 2016 and operating from Tel Aviv and New York, its platform combines the 4SEEN A
To associate your repository with the risk-quantification topic, visit your repo's landing page and select "manage topics."