Skip to content

Put a dollar figure on every cyber risk — even the ones you can't scan

CyQuantiFi is a cyber risk quantification platform for Australian critical infrastructure. We replace red/amber/green heatmaps with an engineering-grade Annual Loss Expectancy in dollars — across the assets you can scan, and the OT, legacy and third-party systems you can't.

YOUR RISK, IN DOLLARS honest worst case A loss distribution — not a colour on a heatmap — with the fatter tail correlated risk creates.

Heatmaps can't answer the board's question

Boards, regulators and insurers all ask the same thing: what is this cyber risk worth in dollars, and how confident are we? A colour in a cell doesn't answer it. Meanwhile the cost of getting it wrong keeps climbing.

84,700+
Cybercrime reports a year

Roughly one every six minutes (ASD Annual Cyber Threat Report).

$80,850
Average business cost

Per cybercrime incident — up about 50% year on year (ASD).

$3.3M
SOCI penalty exposure

As enforcement of the Security of Critical Infrastructure Act steps up.


Two ways to quantify — including the assets no one else can

Every other CRQ tool needs to scan. Your highest-consequence systems — OT/SCADA, air-gapped, legacy, classified, third-party — can't be scanned safely. CyQuantiFi quantifies both, and both produce the same output: a dollar figure with confidence intervals.

🖥️ Scannable IT

A lightweight agent builds attack graphs from your environment, then a FAIR-aligned Monte Carlo simulation turns them into an Annual Loss Expectancy in dollars.

🛰️ Unscannable assets

Where there's no telemetry, structured expert consensus with calibration tracking produces a defensible probability — feeding the same simulation, the same dollar output.


What you get

💲 Dollars, not colours

A board-ready Annual Loss Expectancy with confidence intervals — a number you can budget and attest against.

📐 Calibrated inputs

We measure expert accuracy over time, so the number carries a defensible confidence range — not a guess in a cell.

🌊 Correlated risk (Threat Tide)

Model the "shared weather" that makes linked supply-chain risks fail together — an honest worst case, not an artificially calm one.

🔒 Sovereign & FOCI-clean

Australian-incorporated and Australian-hosted — a clean answer to the Enhanced CIRMP foreign-influence clause.


Built for Australian regulation

CyQuantiFi maps natively to the obligations that actually drive spend — so quantification becomes evidence, not homework.

SOCI & CIRMP

Board-ready dollar figures mapped to the all-hazards CIRMP framework and annual reporting.

APRA CPS 234

Quantified information-security risk, including third parties, for regulated financial entities.

IRAP & Essential Eight

Independent assessment against the ISM and Essential Eight — with the option to price every gap.


Why it's credible

🎖️ Defence-grade heritage

The methodology traces to risk-quantification frameworks used within Defence.

📄 Patent-filed technology

Two patents filed with IP Australia cover our expert-consensus engine and correlated cross-graph risk.

📐 Math over vibes

Every number is traceable, ranged and defensible. We show the working — no black boxes for your board or regulator to distrust.


Explore CyQuantiFi

Services

CRQ for SOCI/CIRMP, third-party & supply-chain, and IRAP & Essential Eight.

SOCI / CIRMP →
Third-party & supply chain →
IRAP & Essential Eight →
How we compare

See CyQuantiFi against the platforms you're evaluating.

vs Safe Security →
vs Avertro →
vs 6clicks →
The platform

A closer look at how the quantification works, end to end.

See the platform →

See your cyber risk in dollars

Book a 30-minute demo — including the assets your scanners can't reach.