Security is asking for two more headcount and a bigger tooling budget.
The CFO asks: what does that spend actually prevent? Nobody has a number. A wall of 12,000 CVEs and a stack of CVSS scores is not an answer a board can approve. Without dollar-denominated risk, security lives on a hunch — and hunches lose budget fights every year.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
Every finding in the Onam graph is scored using the FAIR (Factor Analysis of Information Risk) model — the open standard for quantitative risk analysis, published by The Open Group as O-RT and O-RA.
- 2
FAIR states exposure as Loss Event Frequency × Loss Magnitude, which produces an Annualized Loss Expectancy — a dollar figure per year of exposure, not a proprietary score between 0 and 100.
- 3
Loss estimates combine primary loss (response, downtime) with secondary loss (regulatory fines, brand impact) sized to your industry and data sensitivity.
- 4
Magnitude is built from named, external inputs — a published per-record breach cost, a data-sensitivity multiplier, and the strictest applicable regime — so an auditor can follow the arithmetic instead of trusting a black box.
- 5
Regulatory exposure is projected against the frameworks that apply to your data — GDPR, HIPAA, PCI-DSS, SOX — using published fine bands, not hand-waved multipliers.
- 6
Crown-jewel multipliers weight findings that touch high-value assets, so a public bucket over customer PII scores very differently from a public bucket in dev.
- 7
Blast radius comes from the security graph rather than an assumption: a finding that sits on an attack path to a large sensitive store is priced above the identical finding on a resource that reaches nothing.
- 8
The engine ranks remediations by dollar exposure reduced per engineering hour — so the security queue and the business case are the same list.
Specific outputs, measurable outcomes
Risk Quantification in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see Risk Quantification in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.