Cyber Risk Quantification (CRQ) gives security leaders the estimated cost of a supplier breach, turning third-party risk into financial exposure that holds up at board level.
NEW YORK — August 17, 2026 — Panorays, a leader in third-party cybersecurity risk management (TPCRM), today launched Cyber Risk Quantification, a new module that puts a dollar value on the cyber risk of every supplier relationship in their organization. CRQ calculates the annual financial exposure an organization faces from supplier-related cyber incidents, turning complex third-party risk into a clear business number. Now, security and business leaders can now bring both halves of the picture into the boardroom, which suppliers carry the most risk and what that risk is worth to the business.
CRQ draws on intelligence already available in Panorays, combining cyber posture ratings, questionnaire responses, business context, and threat signals across different sources and data formats. This allows organizations to put a financial measure on third-party risk using the information they already have, without adding another layer of assessments or manual work. Unlike tools that require teams to manually gather and enter the underlying figures, Panorays uses AI to derive them directly from supplier data already in the platform.
Built on the industry-recognized Open FAIR™ Version 2.0 framework, CRQ calculates an estimated Annualized Loss Expectancy (ALE) for every supplier across four key loss scenarios and provides an aggregated view of potential financial exposure across the entire portfolio. Each calculation is presented as a loss range, with a clear explanation of the factors driving the result. Organizations can adjust the underlying financial assumptions to reflect their own risk appetite and business context.
Panorays CRQ models four risk scenarios: Availability Loss, when a cyber event at a supplier disrupts business operations; Data Leak Loss, when a supplier breach exposes sensitive data; Fraud Loss, when a compromised supplier relationship enables fraudulent transaction, a risk scenario no other TPRM platform offers today; and Supply Chain Attack Loss, when attackers use a supplier as a route into the organization.
“Security teams working with Panorays are already great at identifying third-party cyber risk, and financial quantification opens up an exciting opportunity for board-level conversations,” said Matan Or-El, CEO and Co-Founder of Panorays. “CRQ translates supplier risk into business terms, giving leadership a solid benchmark for exposure and a stronger basis for strategic decisions.”
Key Capabilities and Benefits
- Translate technical risk into financial language: Frame third-party exposure in clear dollar terms that resonate with boards, CFOs, and executive leadership.
- Prioritize high-impact suppliers: Focus remediation and oversight on the supplier relationships presenting the highest financial liability.
- Justify security spending: Ground budget decisions in measurable exposure and support risk mitigation investments against competing capital priorities.
- Avoid black-box scoring: Trace every metric back to an open, industry-standard methodology with explanations a risk team can defend when challenged.
CRQ complements existing risk tiering by adding an objective financial layer to board and budget discussions. Now, organizations can put a clear financial value on third-party cyber risk and use it to drive investment decisions and meet growing requirements from regulators and cyber insurers.
About Panorays
Panorays is a global provider of third-party cybersecurity management software. Adopted by leading financial, healthcare, and enterprise organizations worldwide, Panorays helps businesses optimize defenses and proactively manage third-party cyber risk. Headquartered in New York and Israel, Panorays is backed by Aleph VC, Oak HC/FT, Greenfield Partners, and StepStone Group.