Skip to main content

Askara Exposure Model

Also known as:
  • AEM,
  • Exposure Model

Quantitative risk-analysis model that expresses cyber risk as financial loss exposure rather than ordinal severity scores, by decomposing it into loss event frequency and loss magnitude.

Written by Askara Solutions editorial team · Updated

The Askara Exposure Model is what breaks cyber risk out of red, amber, green. It treats a risk scenario as a probability distribution rather than a colour, and expresses the answer in the same units the rest of the business uses: euros or dollars per year.

The mechanics are deliberately simple. Loss is decomposed into loss event frequency (how often the bad thing happens) and loss magnitude (how much it costs when it does). Each factor is decomposed further: frequency into threat event frequency and the susceptibility of the controls; magnitude into primary and secondary loss. Each leaf is a three-point estimate (minimum, most likely, maximum) supplied by people who know the business. A Monte Carlo simulation rolls the distributions up.

What you get is annual loss expectancy expressed as a range, not a heatmap colour. That changes the conversations you can have. A board can compare risk against control investment; an underwriter can assess your insurance ceiling; a procurement team can build risk-based supplier requirements. None of those work when risk is expressed as "high" or "medium".

The model is deliberately portable. The factors, the decomposition tree, the three-point estimate elicitation and the Monte Carlo aggregation are all conventional quantitative-risk practice, so an analysis travels: another organisation, another auditor or an insurer can follow it end to end without translation. Nothing in it depends on tooling only Askara has.

The Risk Investigation Agent uses this model as its quantification engine, and pairs it with the Control Effectiveness Model to turn quantified exposure into a ranked control roadmap.

Related FAQs

Questions answered.