Listing Thumbnail

    CyQuantiFi - Cyber Risk Quantification in Dollars, Not Heatmaps

     Info
    Sold by: CyQuantiFi 
    Deployed on AWS
    AWS Free Tier
    CyQuantiFi replaces heatmaps with dollar-valued cyber risk using FAIR methodology and Monte Carlo simulation - including OT, legacy, and unscannable assets.

    Overview

    Cyber Risk, in Dollars

    CyQuantiFi is an enterprise exposure assessment and cyber risk quantification (CRQ) platform built for Australian critical infrastructure. It replaces red/amber/green heatmaps with engineering-grade Annual Loss Expectancy in dollars - across the assets you can scan, and the OT, legacy and third-party systems you cannot.

    The problem: The cybersecurity industry still cannot answer the board's most basic question - "How much could this cost us?" With 84,700+ cybercrime reports per year in Australia, an average business cost of $80,850 per incident (up 50% year on year), and SOCI penalty exposure reaching $3.3M, boards need dollar figures with confidence intervals, not colours in a cell.

    What the Platform Does

    CyQuantiFi ingests security findings, asset and identity information from across your enterprise estate (on-prem and cloud), correlates them into a single de-duplicated exposure register, models relationships between assets, identities, applications and cloud resources as a graph, identifies and validates attack paths, and expresses the resulting exposure in both technical and financial terms using the FAIR methodology over Monte Carlo simulation.

    Key outputs:

    • Annualised loss expectancy (ALE) and value-at-risk by business service
    • Pre-remediation and post-remediation comparison of loss distributions
    • Risk appetite control at conservative (P75), moderate (P90), or aggressive (P95) levels
    • Portfolio aggregation via Gaussian copula with explicit coupling

    Key Capabilities

    • Exposure Correlation Engine: Resolves findings to assets, de-duplicates by deterministic fingerprint with lifecycle ageing. Human triage decisions survive re-ingest and are never overwritten by new scanner runs.
    • Probabilistic Attack Graph with SAGE Validation: Autonomous engine tests whether modelled attack paths are actually traversable in your environment. CVE overlay binds live NVD data to graph nodes. MITRE ATT&CK overlay maps paths to techniques.
    • Accumulation Map: Shows where separate parts of the estate share a dependency, modelling concentration risk across shared platforms such as Microsoft 365, AWS, CrowdStrike, Okta, Cisco and Snowflake.
    • Quantify Unscannable Assets: OT, legacy, air-gapped and unagented assets are modelled via expert consensus and NetFlow - not guessed. This is a key differentiator: the majority of enterprise cyber exposure typically sits on assets no scanning tool can assess.
    • What-If Analysis: Model control changes (e.g. EDR deployment) and see the dollar reduction in ALE with measurable ROI.
    • CTI Intelligence Pipeline: Automated and continuous. Ingests TAXII v2.1, RSS feeds, NVD/CVE, custom APIs, email and document uploads. AI CTI Agent handles analysis, triage, indicator extraction and MITRE ATT&CK mapping.
    • Expert Consensus Engine (Patent Filed): Combines AI agent and human expert inputs with calibration track records where higher accuracy equals more influence, producing defensible probability estimates for unscannable assets.
    • Correlated Risk (Threat Tide): Models shared conditions that make linked supply-chain risks fail together - producing an honest worst case, not an artificially calm one.

    AWS Integration

    • AWS Security Hub Connector: Ingests ASFF findings from GuardDuty, Inspector, Macie, Access Analyzer and control failures, bound to resource ARN
    • AWS IAM Connector: Users, roles, groups with inline, managed and trust policy documents
    • Amazon Bedrock (ap-southeast-2): Optional AI features including CTI agent and graph builder wizard, maintaining Australian data residency
    • Deployed on AWS ap-southeast-2 (Sydney) with AWS role assumption using external ID for connector authentication - no static keys

    Regulatory Framework Mapping

    • SOCI and CIRMP: Board-ready dollar figures mapped to the all-hazards CIRMP framework and annual reporting
    • APRA CPS 234: Quantified information-security risk including third parties for regulated financial entities
    • ACSC Essential Eight (ML0-ML3) and Australian Government ISM (1,192 controls)
    • Additional frameworks: NIST CSF 2.0, ISO 27001:2022 Annex A, CIS Controls v8, NIST SP 800-53 Rev 5 with OSCAL import/export

    Connectors

    Microsoft Entra ID, Microsoft Sentinel, Microsoft Defender, Microsoft Defender EASM, Azure RBAC, AWS Security Hub, AWS IAM, Obsidian SSPM, GitHub Advanced Security, ServiceNow, certificate transparency discovery, NetFlow REST and multiple CTI feeds.

    Sovereign and FOCI-Clean

    Australian-incorporated, Australian-owned, Australian-operated and hosted in the AWS Sydney region. Defence-grade heritage with methodology tracing to risk-quantification frameworks used within Defence. All data remains in Australian jurisdiction with TLS 1.3 and hybrid post-quantum key establishment using ML-KEM.

    Highlights

    • Dollar-Valued Cyber Risk From Attack Graphs, Not Spreadsheets: CyQuantiFi ingests security findings, correlates them into a de-duplicated exposure register, models asset relationships as probabilistic attack graphs, and runs FAIR-aligned Monte Carlo simulations to produce annualised loss expectancy (ALE) and value-at-risk per business service.
    • Quantify Unscannable Assets That Other Tools Cannot Reach: 82.5% of enterprise cyber exposure typically sits on assets no scanner can assess - OT/SCADA, air-gapped, legacy, classified, and third-party systems. CyQuantiFi's patent-filed expert consensus engine combines AI and calibrated human inputs to produce defensible probability estimates for these assets, feeding the same Monte Carlo simulation and producing the same dollar output as scanned environments.
    • Australian-Sovereign Platform Built for SOCI, APRA CPS 234, and Essential Eight: Deployed on AWS ap-southeast-2 (Sydney) with full Australian data residency. Maps natively to SOCI/CIRMP, APRA CPS 234, NIST CSF 2.0, ISO 27001, ACSC Essential Eight, and CIS Controls v8. Integrates with AWS Security Hub, Entra ID, Microsoft Defender, Sentinel, Okta, ServiceNow, and CTI feeds. Australian-owned, Australian-operated, and FOCI-clean - a direct answer to Enhanced CIRMP foreign-influence requirements.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    CyQuantiFi - Cyber Risk Quantification in Dollars, Not Heatmaps

     Info
    This product is available free of charge. Free subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    AI Insights

     Info

    Dimensions summary

    This listing offers a single pricing dimension: Free. You pay nothing to use it, and there is no paid tier, usage charge, or commitment tied to this dimension. Because only one option exists, there are no tiers to compare or quantity levels to scale between. The platform quantifies cyber risk as a dollar-based Annual Loss Expectancy for both scannable and unscannable assets. All included capabilities fall under this one no-cost dimension.

    Top-of-mind questions for buyers

    The Free dimension carries no usage charge or commitment. CyQuantiFi turns cyber risk into a dollar-based Annual Loss Expectancy with confidence intervals. It quantifies both scannable IT assets and unscannable systems like OT, air-gapped, legacy, and third-party assets, producing board-ready figures rather than red/amber/green heatmaps.
    For scannable IT, a lightweight agent builds attack graphs, then a FAIR-aligned Monte Carlo simulation produces a dollar figure. For unscannable assets with no telemetry, structured expert consensus with calibration tracking produces a defensible probability. Both feed the same simulation and yield the same dollar-based output. The Free dimension covers both approaches.
    No. This listing has one dimension: Free. There is no per-asset charge, no usage meter, and no tier to move between. Adding more assets, running more simulations, or generating more reports does not change your cost, because no paid usage exists to accrue against.
    www.cyquantifi.com
    Helpful?

    Vendor refund policy

    CyQuantiFi offers subscription-based access to the platform. Refund requests are handled directly by the CyQuantiFi team and reviewed on a case-by-case basis.

    To request a refund, contact the CyQuantiFi support team by email at services@cyquantifi.com . All refund enquiries are handled by Australian-based staff. Your Named Technical Account Manager is your primary point of contact for billing and subscription matters, including cancellations and refund requests.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    CyQuantiFi provides Australian-based support with no offshore tier. All support is delivered by Australian staff during standard business hours of 07:00-19:00 AEST on business days, with 24x7 coverage for critical incidents.

    Response Time SLAs by Severity:

    • Severity 1 (Critical): 1-hour response, 24x7 coverage
    • Severity 2 (High): 4 business hours
    • Severity 3 (Medium): 1 business day
    • Severity 4 (Low): 3 business days

    Support Includes:

    • Named Technical Account Manager assigned to your organisation
    • Managing Director-level executive sponsor for escalation
    • Monthly service reports detailing platform health, incident summaries, and usage metrics
    • Quarterly service reviews to assess outcomes and plan ahead

    Getting Help:

    For product issues, troubleshooting, or general enquiries, contact the CyQuantiFi support team via email. Enterprise customers receive priority support with dedicated response channels.

    Onboarding and Implementation:

    CyQuantiFi follows a structured implementation approach: Establish (4-6 weeks for platform setup and configuration), Integrate (6-10 weeks for connector deployment and data ingestion), Transition (4 weeks for knowledge transfer and operational handover), and Run (ongoing operations for the contract term). Enterprise tier includes 20 consulting hours for configuration, integration assistance, and custom reporting.

    Refunds and Account Changes:

    For billing enquiries, subscription changes, or refund requests, contact the CyQuantiFi team directly. All requests are handled by Australian-based staff.

    To reach CyQuantiFi support, visit https://www.cyquantifi.com  or book a consultation through the platform.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.