A collection of awesome projects, blog posts, books, and talks on quantifying risk
-
Updated
Apr 13, 2020
A collection of awesome projects, blog posts, books, and talks on quantifying risk
Interactive CRQ Monte Carlo simulation tool for quantifying cybersecurity risk using FAIR methodology. Built for EU SMBs, vCISOs, and security practitioners.
FAIR cyber risk quantification toolkits, agent-based control simulation (FAIR-CAM), threat event frequency estimator (PyPI), LLM classification validator (PyPI), Monte Carlo risk engine with IRIS benchmarks.
Reusable decision-science utilities for security: Monte Carlo, Bayes, Survival, VoI, light causal helpers.
Bayesian risk modelling and quantification notebooks for cybersecurity
Evidence-governed quantitative cyber risk — a trustworthy CLI and scenario engine where every number traces to a reviewed public source.
Local-first quantitative cyber risk platform built on the FAIR methodology: Monte Carlo simulation, portfolio aggregation, and executive reporting. No cloud, no telemetry. (Beta)
Cybersecurity risk intelligence dashboard analyzing CVE vulnerabilities, CVSS risk scores, and financial exposure using Power BI.
Interactive loss exceedance curve guide, restyled to my portfolio palette
Interactive Monte Carlo demo: watch the law of large numbers converge on a fair coin. A training exercise.
Interactive risk quantifier: place risks on a 5x5 heat map, add frequency and loss ranges, then run 10,000 Monte Carlo iterations to turn the matrix into a loss distribution.
Interactive FAIR taxonomy study tool: build the decomposition tree from memory, assign units, match definitions. A training exercise.
Threat modeling case study applying PASTA (7-stage) and FAIR (Monte Carlo) to quantify ransomware risk in a HIPAA-regulated SaaS environment. Includes control investment ROI analysis and presentation talking points.
FAIR Monte Carlo cyber risk quantification: translates technical vulnerabilities into probable financial loss distributions, then has Claude draft the board narrative. Next.js + Recharts + Trigger.dev + Supabase.
Bayesian-inspired Impact Forecast Algorithm (IFA) for quantifying material impact risk
Open-source data breach cost predictor & cyber-risk quantification engine — IBM benchmarks + DPDP/GDPR penalties + Monte Carlo + security-investment ROI
Source-backed starting ranges for cyber loss estimates: 11 shards across 8 countries, every parameter carrying its citation, confidence level and stated limitation
Agentic, controls-as-code GRC engine: one SCF-mapped control set → every framework. OSCAL-validated, FAIR-quantified, policy-as-code, human-gated AI. CI proves it.
Cyberwrite is an AI-powered cyber insurance intelligence platform, founded in 2017, that turns raw data into explainable, defensible financial decisions for the cyber insurance market.
Offline, self-contained HTML tools for calibrated probability estimation training: practice trainer with Brier scoring, a nine-module course, and a verified question bank.
Add a description, image, and links to the risk-quantification topic page so that developers can more easily learn about it.
To associate your repository with the risk-quantification topic, visit your repo's landing page and select "manage topics."