What changed
The Cyber Risk Quantification (CRQ) engine (RFC-017) shipped this month as the math layer underneath every dollar figure the platform will produce from this point forward. The cost-methodology work in the platform stops being a lookup table and starts being a live simulation of the customer’s actual exposure.
Why it matters
Every product improvement that talks about a dollar figure — maturity-assessment cost breakdown, per-finding ALE, board-facing risk reports, quantified vendor exposure, LEC curves in the CFO panel — is now driven by the same math the FAIR Institute and NIST 800-30 Rev. 1 use, not a lookup table. The industry norm of red-yellow-green cyber risk is an unforced error. This engine is the platform’s answer.
LECs are what board risk committees actually reason against. The engine produces them at the percentiles those committees ask for, with the inputs documented and the methodology citable.
For the methodology this engine implements at SMB scale, see Cyber Risk Quantification for Mid-Market. For the show-your-work discipline the LEC output supports, see Why This Probability: Bayesian Conditional Exposure.
Availability
Live now across the platform’s cost outputs. Every panel that previously rendered a hardcoded cost range reads from the engine.
Scenario distributions and the blended labor rate are seeded from the FAIR Institute methodology and public BLS + Gartner wage data. A customer override to the labor rate carries through every downstream dollar figure: per-finding ALE, maturity-assessment cost breakdowns, and quantified vendor exposure.
Known limitations
The simulation horizon is one year. Multi-year loss curves aren’t produced by the engine in this iteration.