Risk Quantification

What does your current cloud attack surface actually cost if it is breached?

CVSS scores tell you severity. FAIR tells you the dollar amount on the table.

Onam's Risk engine applies the FAIR model to every finding — converting technical misconfigurations into business-language financial exposure estimates your board can act on.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

Security is asking for two more headcount and a bigger tooling budget.

The CFO asks: what does that spend actually prevent? Nobody has a number. A wall of 12,000 CVEs and a stack of CVSS scores is not an answer a board can approve. Without dollar-denominated risk, security lives on a hunch — and hunches lose budget fights every year.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Every finding in the Onam graph is scored using the FAIR (Factor Analysis of Information Risk) model — the ISO/IEC-approved standard for quantitative risk analysis.

  2. 2

    Loss estimates combine primary loss (response, downtime) with secondary loss (regulatory fines, brand impact) sized to your industry and data sensitivity.

  3. 3

    Regulatory exposure is projected against the frameworks that apply to your data — GDPR, HIPAA, PCI-DSS, SOX — using published fine bands, not hand-waved multipliers.

  4. 4

    Crown-jewel multipliers weight findings that touch high-value assets, so a public bucket over customer PII scores very differently from a public bucket in dev.

  5. 5

    The engine ranks remediations by dollar exposure reduced per engineering hour — so the security queue and the business case are the same list.

What do you actually get?

Specific outputs, measurable outcomes

FAIR model scoring
dollar-denominated primary and secondary loss per finding
Regulatory fine projection (GDPR, HIPAA, PCI-DSS, SOX)
Blast radius quantification
Risk reduction ranking
most dollar exposure reduced per engineering hour
Crown jewel risk multipliers
Trend analysis over time
Executive risk dashboard
board-ready top-10 by dollar value
Compliance cost mapping
See it live

Risk Quantification in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

Risk — FAIR Model
Export Risk Report
$0.0M
Annual Loss Exp.
0
Risk Score
0
Crown Jewels
$2.4M–$8.7M
95th pct ALE Range
Top Risk Scenarios (FAIR)
Risk in dollars, not scores
FAIR model: $5.1M annual loss expectancy across 6 scenarios and 3 crown jewels
Clip length
11s
Data
Demo account
FAQ

Questions we get a lot

FAIR (Factor Analysis of Information Risk) is the ISO/IEC 27005-aligned standard for quantitative cyber risk. It decomposes risk into loss event frequency and loss magnitude, each with defensible ranges. It is the language boards and CFOs already use for other business risk — so Onam speaks it too.
Ready to see it live

Ready to see Risk Quantification in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.