Cyber-Risk Quantification (FAIR-style ALE)
What is this agent's annualized loss exposure — in dollars?
Every other AgentSmack meta-lens emits a technical verdict — a kill-chain, an exploitability rating, a blast-radius band, an adversary-ROI score. NONE translate the findings into the one artifact an enterprise buyer puts in a budget request: a FAIR-style Annualized-Loss-Expectancy — Loss-Event-Frequency × Loss-Magnitude ⇒ a bounded USD range. This is that translation layer. It consumes the same cross-surface findings envelope every scan emits, inherits severity verbatim from the remediation generator and frequency from the exploitability rating (it re-authors no severity or exploitability table), and folds them into a closed, integer-only annualized-loss-exposure score. A single critical hard blocker floors the exposure at high; a confirmed end-to-end kill-chain floors it at critical — an adversary cannot launder a real critical down by adding clean surfaces, and a pile of low findings cannot inflate into a fabricated critical. And it is honestly humble: the dollar figure is always a bounded range band (scaled by your org-size profile), never a false-precise number. It adds no new surface and no new scorecard dimension.
Vulnerable sample — a confirmed end-to-end exfil chain (high ALE)
Annualized cyber-risk exposure (FAIR-style ALE)
CriticalEstimated annualized loss
$1M–$10M+
midmarket profile · score 100/100Top loss drivers (4)
- egress:canary_exfiltrated_to_unauthorized_sinkPrimary lossChain anchor100/100
- harness:privileged_tool_executed_without_approvalPrimary lossChain anchor100/100
- memory_lab:poisoned_memory_used_in_actionPrimary lossChain anchor100/100
- rag_scan:injectionPrimary lossChain anchor74/100
Annualized cyber-risk exposure critical (100/100): 4 failed finding(s), 3 critical, 4 on a confirmed chain ⇒ loss-event frequency frequent × loss magnitude catastrophic = an estimated annualized loss exposure of $1M–$10M+ (midmarket profile, reported as a bounded range — never a false-precise figure). A confirmed end-to-end kill-chain floors the exposure at critical (causally amplified frequency).
Benign sample — an all-clean run (zero ALE, no fabricated dollar)
Annualized cyber-risk exposure (FAIR-style ALE)
No exposureHonest-empty — no failed findings to quantify. There is no annualized loss exposure to report, and we never fabricate a dollar figure.
Honest-empty — no failed findings to quantify; there is no annualized loss exposure to report (no fabricated dollar figure).
Run it on your own findings
Related read-only meta-lenses over the same findings envelope: Risk Register · Attacker Economics / Adversary ROI · Blast-Radius / Impact · Attack-Path / Kill-Chain. POST the same { findings, exposureProfile? } envelope to /api/v1/risk-exposure to run it on your own findings.