Open source · MIT licensed

Cyber P&L: Open-Source Cyber Risk Quantification

Transparent Monte Carlo loss modeling for CISO–CFO decisions, control valuation, risk appetite, and security investment prioritization.

Cyber P&L cyber risk quantification preview showing a loss exceedance curve and CISO-CFO decision themes.
v0.1.1Public, versioned release
FAIR-styleTransparent loss analysis
Monte CarloRanges, tails, and uncertainty
Governed inputsOwners, sources, and attestations

The decision problem

Turn cyber risk into decisions leaders can examine

Heat maps can help organize a conversation, but they cannot tell a CISO, CFO, risk committee, or board what a bad year could cost, whether a proposed control changes that exposure, or which investment deserves priority.

Cyber risk quantification estimates the frequency and financial magnitude of cyber loss scenarios so leaders can compare exposure, risk appetite, control value, and security investments on a common economic basis.

01

How much risk are we carrying?

Estimate expected annual loss and tail exposure by scenario rather than compressing uncertainty into a single color or score.

02

Which controls change the outcome?

Model control counterfactuals, dependencies, annualized cost, loss avoided, net ROSI, and payback without pretending effects are additive.

03

Are we inside risk appetite?

Test every approved loss threshold and expose the evidence, owner, assumptions, and model limits behind the result.

Illustrative decision output

Give leadership a range, not a false promise

The bundled demonstration is a fictional $180M SaaS company. It shows how a governed model can place annual loss, bad-year exposure, appetite, and assumption status in one reviewable statement.

Every number below is an illustrative template—not a benchmark or forecast for another organization.

Cyber P&L · Example SaaS Inc. · 20,000 simulated years
Expected annual loss$1.36M
Bad year (p95)$4.31M
Severe tail (p99)$7.89M
Risk appetite checksWithin

Assumption status remains incomplete until the required evidence and organization-specific attestations are supplied.

Reading a loss exceedance curve

A loss exceedance curve shows the probability that annual cyber loss will exceed each financial threshold. Moving from left to right, the curve makes expected loss and tail exposure visible without reducing uncertainty to a single score.

Leaders can use the curve to compare modeled exposure with risk appetite and examine how a control or investment changes the distribution. The result remains decision support—not a forecast—and is only as reliable as the scenarios, evidence, ranges, and dependencies behind it.

Cyber P&L example decision statement showing expected annual loss, p95 exposure, risk appetite, control value, investment rankings, and assumption sensitivity for a fictional company.
Illustrative Cyber P&L output for a fictional company. The figures are a demonstration, not a benchmark or forecast. Open the full-size statement.

Three practical use cases

Where Cyber P&L supports executive decisions

Security investment prioritization

Compare proposals using loss avoided, benefit-cost ratio, net ROSI, payback, and change in p95 exposure.

  • Build a defensible business case
  • Separate cost from value
  • Show uncertainty explicitly

Board and risk-committee reporting

Translate technical scenarios into financial ranges, appetite tests, decision ownership, and documented model limitations.

  • Connect cyber risk to enterprise risk
  • Make assumptions reviewable
  • Support CISO–CFO alignment

Control valuation and assurance

Remove a control and its declared dependencies, then rerun the model with stable, independently seeded input streams.

  • Estimate existing-control value
  • Test replacements and dependencies
  • Connect operational evidence to risk

How it works

A transparent path from scenario to decision

STEP 01Define scenariosDescribe service, threat, event frequency, and CFO-recognizable loss components.
STEP 02Calibrate rangesReplace the fictional inputs with internal evidence, accountable owners, and dated sources.
STEP 03Simulate lossRun Monte Carlo analysis to estimate annual loss and exceedance probabilities.
STEP 04Test decisionsCompare appetite, controls, counterfactuals, proposals, payback, and tail reduction.
STEP 05Govern the modelValidate schemas, evidence, sources, owners, dependencies, and required attestations.

Trust model

Open assumptions are a control—not a weakness

What the project makes inspectable

  • Scenario and business assumptions
  • Input owners, sources, dates, and evidence status
  • Control dependencies and replacements
  • Risk-appetite thresholds and decision outputs
  • Model limits and endpoint sensitivity

What the project does not claim

  • No universal breach-cost benchmark
  • No certified FAIR or Open FAIR conformance
  • No actuarial, accounting, insurance, legal, or investment advice
  • No readiness claim before organization-specific evidence and approval
  • No promise that uncertain inputs become facts
Important: Cyber P&L ships as a structurally valid illustrative template. A real organization should not use its output for executive decisions until its own evidence, accountable owners, model review, and required attestations pass operational validation.

Apply the method

From initial fit to an executive decision model

The software is free and open source. Advisory work helps an organization frame the right scenarios, calibrate credible inputs, govern assumptions, and turn the model into a decision process.

No-cost entry

20-minute Cyber Risk Fit Call

A brief conversation to identify the decision, audience, available evidence, and whether quantitative analysis is appropriate.

Discuss fit
Paid working session

90-minute Cyber Risk Decision Workshop

Frame one material decision, candidate loss scenarios, control choices, evidence gaps, owners, and the next defensible step.

Request a workshop
Fixed scope

Cyber Risk Quantification & Investment Readiness Assessment

Build a prioritized model plan covering scenarios, evidence, governance, investment questions, validation criteria, and named owners.

Discuss an assessment
Ongoing advisory

Quarterly Cyber Risk & Security Investment Advisory

Review assumptions, risk appetite, control performance, investment choices, executive reporting, and changes in the threat or business environment.

Discuss advisory support

About the creator

Created by Jessen Kurien

Jessen Kurien is a cybersecurity leader, advisor, and author with 18+ years across MSSP operations, enterprise SOC leadership, incident response, detection engineering, security product development, GRC, and AI governance.

During nearly 15 years at Microsoft he was part of the founding team of the Microsoft Threat Intelligence Center (MSTIC), contributed early detections to Microsoft Sentinel, and led a detection engineering team in Microsoft Defender XDR. He also conducted ISO/IEC 27001 audits, and has built and run security operations from both sides of the relationship—as the provider and as the enterprise.

He holds CISM, CISA, and the ISO/IEC 42001 Lead Implementer credential, and advises CISOs and security leaders on cyber defense, SIEM/XDR strategy, incident response, cyber risk, and Artificial Intelligence Management Systems.

Frequently asked questions

Cyber risk quantification questions

What is Cyber P&L?

Cyber P&L is an open-source Python project that uses FAIR-style loss analysis and Monte Carlo simulation to support cyber risk, control, appetite, and security-investment decisions.

Is Cyber P&L a financial statement?

No. It is not an accounting or GAAP profit-and-loss statement, actuarial model, insurance model, forecast, or substitute for professional financial, legal, or investment advice.

How does it support CISO–CFO communication?

It expresses cyber scenarios using financial ranges, tail exposure, risk appetite, control economics, evidence ownership, and explicit model limits instead of relying only on technical scores.

Does it implement FAIR?

It uses a FAIR-style loss-event frequency and loss-magnitude approach. It is not affiliated with, certified by, or endorsed by The Open Group and does not claim Open FAIR conformance.

Can organizations use the sample results?

No. The bundled company, costs, controls, measurements, and results are fictional. Organizations must replace them with scoped evidence, accountable owners, review, and required attestations.

What can a cyber risk assessment deliver?

A fixed-scope engagement can produce a decision statement, prioritized scenarios, an evidence and assumption register, risk-appetite tests, control/investment comparisons, validation criteria, and named owners.

Put one cyber-risk decision on a reviewable economic basis

Start with the open-source model, or discuss a bounded assessment for a security investment, control, risk-appetite, or board-reporting decision.