Answers you can get without asking us
Two assessments that return a number about your own organisation, the write-ups behind the method, and a reference library you can search on your own terms. Nothing here is gated behind a sales call.
Start with a number of your own
Both are free, run in the browser, and ask nothing you would not put in a board pack. Neither one needs data you do not already have.
- Takes2 minutes
- Scores7 maturity dimensions
- You getYour weakest dimensions, each with a recommended action
- Takes5 minutes
- MethodFAIR loss-exposure model
- You getYour estimated annual exposure, as a PDF report
Write-ups from the practice
Long-form notes on quantifying cyber risk, modelling loss with FAIR, and meeting Indian regulatory expectations — written for the people who have to defend the numbers in the room.
“Reasonable Security Safeguards” Is Now a Number
The DPDP Act attaches its largest penalty to a duty it deliberately declines to define. That is not a drafting gap — it is an instruction to show your reasoning.
Read the write-up →FAIR Without the Folklore
Most objections to quantifying cyber risk are really objections to bad quantification. What separates a model that survives scrutiny from one that gets dismissed is a handful of disciplines — none of which need data you do not have.
Read the write-up →Your Board Doesn’t Want a Heat Map
The problem with the red-amber-green grid is not that it is imprecise. It is that it cannot be compared, aggregated, or acted on — which is everything a board needs a risk report to do.
Read the write-up →The questions we get asked
Answered once, properly, so you do not have to book a call to find out what FAIR needs as input or what the RBI actually expects to see.
Read up on a discipline
One guide per topic: what it is, why programmes fail at it, and what running it properly looks like. Each ends with its own four answered questions.
What practitioners say
4Sight’s FAIR-based quantification is one of the few I’ve seen that actually translates technical findings into numbers a risk committee can act on, not just another dashboard.
Partners taking 4sight into new markets, and independent advisors reviewing it for their own clients, on what it changed in the room.
Read all testimonialsKnow your cyber risk before it becomes a business crisis.
Start with a free assessment, or book a 30-minute walkthrough against your own environment.