Skip to content

Compare · CyQuantiFi vs CyberCube

Two chairs at the same table. One of them is yours.

CyberCube tells insurers, reinsurers and brokers what your cyber risk is worth to their portfolio. CyQuantiFi tells you, the CISO, the CFO and the board, what it is worth to yours: a live Annual Loss Expectancy and Value-at-Risk in dollars, built from your own attack graph rather than an outside-in score.

Annual loss distribution · Monte Carlo ALE $3.9M / yr
P50 · $3.1M P95 · $8.1M P99 · $12.4M $0$3.5M$7M$10.5M$14M Simulated annual loss · 100,000 iterations
Mean (ALE)$3.9M
90% interval$1.2M – $8.1M
P99 VaR$12.4M

Illustrative output from the seeded demo tenant (a 15-node water-utility attack graph). Your figures come from your own graph, controls and threat feeds.

The short version

Same subject, opposite side of the desk

Both products put a dollar figure on cyber risk. The difference is who is asking, and what they can change once they have the number.

The insurer’s chair

CyberCube

Built for

Insurers, reinsurers and brokers. CyberCube describes itself as a cyber risk analytics provider for the insurance industry, and reports that its analytics are used by 75% of the top 40 US and European cyber carriers.

Unit of analysis

A book of insured accounts, or a single account at underwriting. The question is portfolio accumulation, treaty and capital decisions, and whether an account fits guidelines.

What it changes

Pricing, risk appetite, reinsurance purchase and reserving on the carrier’s side.

Your chair

CyQuantiFi

Built for

The organisation that carries the risk: CISOs, CFOs, boards, risk committees and the regulators they answer to under SOCI, CPS 234, PSPF, DORA and NIST 800-37.

Unit of analysis

Your own attack graph: assets, MITRE ATT&CK techniques, controls, third parties and impacts, priced with FAIR and Monte Carlo into a loss distribution per project and per portfolio.

What it changes

Which control to fund next, what to tell the board, what to put in front of your insurer and your regulator, and how the number moves when you act.

Side by side

The ledger

CyberCube entries are drawn from its public product pages and announcements. Where a capability is not a stated focus of CyberCube’s products we say so rather than guess.

Dimension CyQuantiFi CyberCube
Primary customer The insured organisation: security, finance and the board. The insurance value chain: carriers, reinsurers, brokers.
Named products One platform with a CISO journey and a CFO journey sharing the same data. Portfolio Manager, Account Manager, Broking Manager, Exposure Manager, SPoF Intelligence, CyberConnect.
Risk modelhow the number is produced Attack graphs with Beta-PERT edge probabilities, Bayesian propagation, and FAIR loss factors, simulated with Monte Carlo up to one billion iterations. Portfolio catastrophe and accumulation modelling; claims-validated predictive analytics for single-risk underwriting.
Inputs Your own asset register (Nmap XML, CSV, SBOM), infrastructure-as-code, NetFlow, SIEM and GRC connectors (Drata, Vanta, ServiceNow), CTI feeds (NVD/CVE, EPSS, KEV), and expert judgement for assets no scanner can see. Exposure and schedule data across the insurance value chain, combined with CyberCube’s external firm-level and market data.
Headline outputs Portfolio ALE, LEF, loss magnitude, P95/P99 Value-at-Risk with confidence intervals, critical attack paths, control ROI, and a correlated portfolio view via Gaussian or Clayton copula. Portfolio steering, reinsurance purchase, reserving and board reporting for carriers; underwriting-guideline fit for accounts.
Probability sourcing Cross-organisation base rates per technique, refined by LMSR prediction markets among your analysts. Brier scoring weights the best-calibrated forecasters over time. Proprietary analytics validated against claims data.
Unscannable and OT assets First-class. SCADA, field devices and process risk are modelled with elicited probabilities and market consensus, with the IT/OT boundary as an explicit control. Not a stated focus of the public product line.
Regulatory mapping SOCI, CPS 234, PSPF, Essential Eight, DORA, NIST CSF, ISO 27001, CIS Controls, with POA&M tracking. Not a stated focus of the public product line.
Board reporting One-click Word, PowerPoint and Excel packs with the dollar figure, risk register, top scenarios and compliance posture. Scheduled delivery. Board reporting is listed as a Portfolio Manager use case for primary insurers.
Continuous updates Scheduled recalculation (daily by default) as CTI, market trades and control changes land. The SAGE engine validates attack paths autonomously. Forward-looking portfolio view; update cadence is not published.
Deployment SaaS, or self-hosted with Docker Compose, CloudFormation and Terraform. Listed on the AWS, Azure and GCP marketplaces. SSO via SAML and OIDC. Not published.
Getting started Free Community tier (25 assets, 3 users, 10 graphs, up to $500K of managed risk). Self-serve Pro and Enterprise plans on the pricing page, with a 14-day trial. Contact CyberCube.

 

When each one is the right call

Most organisations will never buy CyberCube directly; their insurer already has. The real question is whether you want your own number, or only theirs.

Choose CyberCube if you are

  • A carrier or reinsurer managing accumulation, capital and treaty decisions across a cyber book.
  • An underwriter who needs to triage thousands of accounts against guidelines at quote time.
  • A broker advising clients on risk transfer and market benchmarks.
  • Modelling market-wide catastrophe scenarios such as a cloud or software single point of failure across many insureds.

Choose CyQuantiFi if you are

  • A CISO who needs to replace red-amber-green with a defensible dollar figure the board can budget against.
  • A CFO or audit committee deciding how much cyber to insure, retain, or fix, and wanting to see the trade-off in the same units as every other risk.
  • Regulated under SOCI, CPS 234, PSPF or DORA and asked to evidence a quantitative risk assessment, not a heatmap.
  • Running OT, ICS or other assets that no scanner or outside-in scorer can see.
  • Starting small: one project, one graph, one number, for free, this afternoon.

Use both, from opposite sides

  • Your insurer prices you with tools like CyberCube. Arriving with your own ALE, P95 and P99 and the attack paths behind them turns the renewal from a questionnaire into a negotiation.
  • CyQuantiFi’s FAIR-aligned exports (CSV, JSON, Excel) give an underwriter the inside-out evidence an outside-in scan cannot produce: which controls exist, what they cut, and by how much.
  • When the insurer’s model and yours disagree, the gap is the conversation. You will finally be able to have it in dollars.

What you get on day one

From asset scan to board slide in one workflow

This is the sequence a CISO runs in CyQuantiFi. Each step feeds the next, and the whole chain re-runs on a schedule so the number stays live.

1Import assetsNmap XML, CSV or SBOM. Hosts, services and software land in the register with type and criticality.~30 sec
2Generate the graphThe AI graph builder drafts threat, vulnerability, control and impact nodes, each edge tagged with an ATT&CK technique.~60 sec
3Set probabilitiesSeeded from cross-organisation base rates, then refined by your team through prediction markets.ongoing
4SimulateMonte Carlo traverses the graph and returns FAIR ALE, LEF and loss magnitude with full intervals.~10 sec
5Read the numberOne hero figure on the dashboard, with drill-down by project, path and business objective.instant
6Export the packWord, PowerPoint or Excel with the figure, register, top scenarios and compliance posture.~15 sec

Questions we get asked

Straight answers

Is CyQuantiFi a replacement for CyberCube?

Not for an insurer. CyberCube is built for portfolio and underwriting decisions inside carriers, reinsurers and brokers. CyQuantiFi is built for the organisation being insured. If you are a CISO or CFO, CyberCube was never a product you could buy for your own risk programme; CyQuantiFi is.

Do we need FAIR training or a consultant to use it?

No. FAIR is the methodology under the hood, but the workflow starts from a scan or a CSV, not a worksheet. The graph builder drafts the model, base rates seed the probabilities, and the outputs are already labelled in FAIR’s terms (ALE, LEF, loss magnitude) for anyone who wants to audit them.

Will our insurer accept the numbers?

They will recognise them. ALE, P95 and P99 Value-at-Risk are the same quantities their own models produce, and CyQuantiFi shows the attack paths and controls behind each one. Bring the export to renewal and compare it with what the carrier’s model assumes about you.

How does CyQuantiFi handle assets a scanner cannot reach?

You model them explicitly. OT networks, SCADA, field sensors and third-party dependencies become nodes with elicited probability ranges, and your team’s prediction market keeps those estimates honest over time. Brier scores show which forecasters are well calibrated, so the model learns whom to trust.

What does it cost?

The Community tier is free for small programmes. Pro and Enterprise plans are published on the pricing page, with a 14-day trial and a money-back first month through the cloud marketplaces. Enterprise is also available by private offer on AWS, Azure and Google Cloud

Stop guessing yout cyber risk, start quantifying

Book a demo today

CyberCube, Portfolio Manager, Account Manager, Broking Manager, Exposure Manager and SPoF Intelligence are trademarks of their respective owners. CyQuantiFi is not affiliated with, sponsored by or endorsed by CyberCube. Statements about CyberCube are based on its public website (cybcube.com) and press releases as of September 2026 and are provided for comparison only. Loss figures shown are illustrative outputs from a seeded demonstration tenant, not a customer’s data.