The 5×5 heat map cannot answer a board's most important question: what is our actual financial exposure? FAIR v3.0, NIST SP 800-30, and Probabilistic VaR give boards a number — in ₹ crore — not a colour.
4
CRQ models in RiskSage: FAIR v3.0, FAIR-MAM, NIST ALE, Probabilistic VaR
6
FAIR loss forms mapped to Indian regulatory liability: RBI, SEBI, IRDAI, CERT-In
₹18 Cr
P50 annual loss expectancy for ransomware — mid-size Indian bank (illustrative)
₹250 Cr
maximum DPDP Act penalty ceiling — quantifiable in the FAIR regulatory liability module
When a bank's board approves a ₹15 crore cyber insurance policy renewal, what is that decision based on? When the CISO requests a budget increase of ₹8 crore to deploy a privileged access management solution, how does the board evaluate whether that investment is justified? When a regulator asks the board to attest to the adequacy of the organisation's cybersecurity investment, what evidence supports that attestation?
In most Indian BFSI organisations today, these decisions are made on the basis of qualitative risk ratings and the CISO's recommendation. That is not adequate oversight — and India's regulators, having observed the same gap in overseas markets, are beginning to expect more.
₹250 Cr
Max DPDP penalty per breach
₹18–47 Cr
Typical ransomware ALE range (mid-size bank)
6 hrs
CERT-In reporting window before liability
4.2×
Typical ROI on MFA — ALE reduction vs cost