Frequently asked questions
Questions, answered.
The things we hear most about Cordaata, cyber risk quantification, and compliance. If yours isn’t here, we’re happy to help.
What is Cordaata?
Cordaata is a cyber risk management platform. It combines elements of cyber risk quantification (CRQ) and governance, risk, and compliance (GRC), but it is a different kind of platform from the traditional ways teams have tried to manage risk. Traditional approaches lean on subjective heat maps, checklist compliance, and periodic assessments. Cordaata builds a living model of your actual business instead. It maps your processes, systems, and dependencies, calculates risk from what is really there, prices it in financial terms, and keeps it current as your environment changes.
What is cyber risk quantification (CRQ)?
Cyber risk quantification is the practice of expressing cyber risk as a financial value, calculating the probable financial impact of cyber incidents using actuarial and probabilistic methods. It lets security leaders communicate risk in language that boards and CFOs can act on.
What is the FAIR model?
FAIR (Factor Analysis of Information Risk) is the industry-standard framework for quantifying cyber risk in financial terms. It decomposes risk into loss event frequency and loss magnitude, enabling precise financial modelling of cyber threats. Cordaata is built natively on FAIR.
How does Cordaata translate cyber risk into financial terms?
Cordaata uses the FAIR model to analyse loss event frequency and loss magnitude for each risk scenario, then runs Monte Carlo simulations to generate a probabilistic distribution of outcomes. The result is an Annualised Loss Expectancy (ALE) for each risk scenario, and for each control, the amount of risk it reduces expressed as a monetary value.
Can Cordaata align to our risk appetite?
Yes. Because risk is expressed in financial terms, you can set a risk appetite as a number and measure exposure against it directly. Cordaata keeps that measure current, so you can see when you’re approaching your threshold and prioritise before it’s crossed.
How is Cordaata different from a traditional risk assessment?
A traditional assessment is a point-in-time snapshot against a checklist. Cordaata builds a living model of your business and keeps it current as your systems and risks change. You get continuous, quantified risk instead of a report that is out of date the day it is delivered.
Why does Cordaata start with your business processes?
Cordaata maps the business processes, systems, data, services, and dependencies that actually run your organisation. Risk is grounded in what each process relies on and what a disruption would cost, not in a generic control list. That business map is what makes the analysis specific to you, and it keeps it current as your organisation changes.
What is the difference between risk management and compliance?
Compliance confirms that a control or policy exists. Risk management tells you what is actually at stake if something fails, and what to fix first. You can answer every compliance question without knowing what you are protecting. Cordaata starts with the risk analysis, so compliance follows from getting risk right rather than the other way round.
Does Cordaata replace my existing GRC tool?
Cordaata can stand on its own or sit alongside what you already have. It focuses on quantifying risk in financial terms and automating the evidence behind multiple frameworks, so it complements control-tracking tools and typically replaces spreadsheets and manual assessment work.
Who is Cordaata designed for?
Cordaata is built for CISOs, vCISOs, CFOs, GRC analysts, business leaders, and board members who need to understand, communicate, and act on cyber risk in financial terms. It serves enterprise security teams and vCISOs managing multiple client environments alike.
Can partners and vCISOs use Cordaata across multiple clients?
Yes. Cordaata supports multi-client environments, so consultancies, MSSPs, and vCISOs can deliver quantified, business-grounded risk analysis to each client from a single platform.
How long does it take to see value?
Most teams get a first quantified view of their risk during onboarding, not months later. Because the model is built around your business rather than a generic template, early results are already specific to you.
Where is my data hosted?
You choose your hosting region at onboarding, EU or US. Your data is stored in the region you select and protected by the measures set out in our Data Processing Addendum.
Still have a question?
We’re happy to talk it through and show you Cordaata on your own business.