CyQuantiFi replaces heatmaps with dollar-valued cyber risk using FAIR methodology and Monte Carlo simulation - including OT, legacy, and unscannable assets.
CyQuantiFi is an enterprise exposure assessment and cyber risk quantification (CRQ) platform built for Australian critical infrastructure. It replaces red/amber/green heatmaps with engineering-grade Annual Loss Expectancy in dollars - across the assets you can scan, and the OT, legacy and third-party systems you cannot.
The problem: The cybersecurity industry still cannot answer the board's most basic question - "How much could this cost us?" With 84,700+ cybercrime reports per year in Australia, an average business cost of $80,850 per incident (up 50% year on year), and SOCI penalty exposure reaching $3.3M, boards need dollar figures with confidence intervals, not colours in a cell.
What the Platform Does
CyQuantiFi ingests security findings, asset and identity information from across your enterprise estate (on-prem and cloud), correlates them into a single de-duplicated exposure register, models relationships between assets, identities, applications and cloud resources as a graph, identifies and validates attack paths, and expresses the resulting exposure in both technical and financial terms using the FAIR methodology over Monte Carlo simulation.
Key outputs:
Annualised loss expectancy (ALE) and value-at-risk by business service
Pre-remediation and post-remediation comparison of loss distributions
Risk appetite control at conservative (P75), moderate (P90), or aggressive (P95) levels
Portfolio aggregation via Gaussian copula with explicit coupling
Key Capabilities
Exposure Correlation Engine: Resolves findings to assets, de-duplicates by deterministic fingerprint with lifecycle ageing. Human triage decisions survive re-ingest and are never overwritten by new scanner runs.
Probabilistic Attack Graph with SAGE Validation: Autonomous engine tests whether modelled attack paths are actually traversable in your environment. CVE overlay binds live NVD data to graph nodes. MITRE ATT&CK overlay maps paths to techniques.
Accumulation Map: Shows where separate parts of the estate share a dependency, modelling concentration risk across shared platforms such as Microsoft 365, AWS, CrowdStrike, Okta, Cisco and Snowflake.
Quantify Unscannable Assets: OT, legacy, air-gapped and unagented assets are modelled via expert consensus and NetFlow - not guessed. This is a key differentiator: the majority of enterprise cyber exposure typically sits on assets no scanning tool can assess.
What-If Analysis: Model control changes (e.g. EDR deployment) and see the dollar reduction in ALE with measurable ROI.
CTI Intelligence Pipeline: Automated and continuous. Ingests TAXII v2.1, RSS feeds, NVD/CVE, custom APIs, email and document uploads. AI CTI Agent handles analysis, triage, indicator extraction and MITRE ATT&CK mapping.
Expert Consensus Engine (Patent Filed): Combines AI agent and human expert inputs with calibration track records where higher accuracy equals more influence, producing defensible probability estimates for unscannable assets.
Correlated Risk (Threat Tide): Models shared conditions that make linked supply-chain risks fail together - producing an honest worst case, not an artificially calm one.
AWS Integration
AWS Security Hub Connector: Ingests ASFF findings from GuardDuty, Inspector, Macie, Access Analyzer and control failures, bound to resource ARN
AWS IAM Connector: Users, roles, groups with inline, managed and trust policy documents
Amazon Bedrock (ap-southeast-2): Optional AI features including CTI agent and graph builder wizard, maintaining Australian data residency
Deployed on AWS ap-southeast-2 (Sydney) with AWS role assumption using external ID for connector authentication - no static keys
Regulatory Framework Mapping
SOCI and CIRMP: Board-ready dollar figures mapped to the all-hazards CIRMP framework and annual reporting
APRA CPS 234: Quantified information-security risk including third parties for regulated financial entities
ACSC Essential Eight (ML0-ML3) and Australian Government ISM (1,192 controls)
Additional frameworks: NIST CSF 2.0, ISO 27001:2022 Annex A, CIS Controls v8, NIST SP 800-53 Rev 5 with OSCAL import/export
Connectors
Microsoft Entra ID, Microsoft Sentinel, Microsoft Defender, Microsoft Defender EASM, Azure RBAC, AWS Security Hub, AWS IAM, Obsidian SSPM, GitHub Advanced Security, ServiceNow, certificate transparency discovery, NetFlow REST and multiple CTI feeds.
Sovereign and FOCI-Clean
Australian-incorporated, Australian-owned, Australian-operated and hosted in the AWS Sydney region. Defence-grade heritage with methodology tracing to risk-quantification frameworks used within Defence. All data remains in Australian jurisdiction with TLS 1.3 and hybrid post-quantum key establishment using ML-KEM.
Highlights
Dollar-Valued Cyber Risk From Attack Graphs, Not Spreadsheets: CyQuantiFi ingests security findings, correlates them into a de-duplicated exposure register, models asset relationships as probabilistic attack graphs, and runs FAIR-aligned Monte Carlo simulations to produce annualised loss expectancy (ALE) and value-at-risk per business service.
Quantify Unscannable Assets That Other Tools Cannot Reach: 82.5% of enterprise cyber exposure typically sits on assets no scanner can assess - OT/SCADA, air-gapped, legacy, classified, and third-party systems. CyQuantiFi's patent-filed expert consensus engine combines AI and calibrated human inputs to produce defensible probability estimates for these assets, feeding the same Monte Carlo simulation and producing the same dollar output as scanned environments.
Australian-Sovereign Platform Built for SOCI, APRA CPS 234, and Essential Eight: Deployed on AWS ap-southeast-2 (Sydney) with full Australian data residency. Maps natively to SOCI/CIRMP, APRA CPS 234, NIST CSF 2.0, ISO 27001, ACSC Essential Eight, and CIS Controls v8. Integrates with AWS Security Hub, Entra ID, Microsoft Defender, Sentinel, Okta, ServiceNow, and CTI feeds. Australian-owned, Australian-operated, and FOCI-clean - a direct answer to Enhanced CIRMP foreign-influence requirements.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This listing offers a single pricing dimension: Free. You pay nothing to use it, and there is no paid tier, usage charge, or commitment tied to this dimension. Because only one option exists, there are no tiers to compare or quantity levels to scale between. The platform quantifies cyber risk as a dollar-based Annual Loss Expectancy for both scannable and unscannable assets. All included capabilities fall under this one no-cost dimension.
Top-of-mind questions for buyers
What does the Free dimension of CyQuantiFi actually let me do?
The Free dimension carries no usage charge or commitment. CyQuantiFi turns cyber risk into a dollar-based Annual Loss Expectancy with confidence intervals. It quantifies both scannable IT assets and unscannable systems like OT, air-gapped, legacy, and third-party assets, producing board-ready figures rather than red/amber/green heatmaps.
How does the platform quantify assets it cannot scan?
For scannable IT, a lightweight agent builds attack graphs, then a FAIR-aligned Monte Carlo simulation produces a dollar figure. For unscannable assets with no telemetry, structured expert consensus with calibration tracking produces a defensible probability. Both feed the same simulation and yield the same dollar-based output. The Free dimension covers both approaches.
Since it is free, will my cost change as I add more assets or reports?
No. This listing has one dimension: Free. There is no per-asset charge, no usage meter, and no tier to move between. Adding more assets, running more simulations, or generating more reports does not change your cost, because no paid usage exists to accrue against.
www.cyquantifi.com
Helpful?
Vendor refund policy
CyQuantiFi offers subscription-based access to the platform. Refund requests are handled directly by the CyQuantiFi team and reviewed on a case-by-case basis.
To request a refund, contact the CyQuantiFi support team by email at services@cyquantifi.com. All refund enquiries are handled by Australian-based staff. Your Named Technical Account Manager is your primary point of contact for billing and subscription matters, including cancellations and refund requests.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
CyQuantiFi provides Australian-based support with no offshore tier. All support is delivered by Australian staff during standard business hours of 07:00-19:00 AEST on business days, with 24x7 coverage for critical incidents.
Named Technical Account Manager assigned to your organisation
Managing Director-level executive sponsor for escalation
Monthly service reports detailing platform health, incident summaries, and usage metrics
Quarterly service reviews to assess outcomes and plan ahead
Getting Help:
For product issues, troubleshooting, or general enquiries, contact the CyQuantiFi support team via email. Enterprise customers receive priority support with dedicated response channels.
Onboarding and Implementation:
CyQuantiFi follows a structured implementation approach: Establish (4-6 weeks for platform setup and configuration), Integrate (6-10 weeks for connector deployment and data ingestion), Transition (4 weeks for knowledge transfer and operational handover), and Run (ongoing operations for the contract term). Enterprise tier includes 20 consulting hours for configuration, integration assistance, and custom reporting.
Refunds and Account Changes:
For billing enquiries, subscription changes, or refund requests, contact the CyQuantiFi team directly. All requests are handled by Australian-based staff.
To reach CyQuantiFi support, visit https://www.cyquantifi.com or book a consultation through the platform.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Orpheus strengthens third-party risk management with continuous outside-in monitoring of each supplier's external attack surface, informed by threat intelligence and predictive Cyber Risk Ratings. See where supplier exposure is changing and why, without relying on supplier input
SAFE One makes cybersecurity an accelerator to the business by delivering the industry's only data-driven, unified platform for managing all of your first-party and third-party cyber risks.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.