Frequently Asked Questions

Every question we are asked most often about cyber risk quantification, GRC, threat intelligence and Indian regulatory readiness — 36 answers in one place.

Cyber Risk Quantification

Read the full cyber risk quantification page →

What is the difference between cyber risk quantification and a risk assessment?

A traditional risk assessment produces ordinal ratings — high, medium, low — which cannot be added, compared or budgeted against. Quantification produces a probable financial loss, expressed as a range, which can. Most organisations run both: the assessment identifies what could go wrong, quantification decides what to do about it first.

Do we need perfect data before we can quantify?

No. FAIR is built around estimation under uncertainty and expresses results as ranges rather than single figures. Better data narrows the range; it is not a precondition for producing a useful one. Waiting for perfect data is the most common reason quantification programmes never start.

How long does it take to get a first number?

Our free Lightweight Cyber Risk Quantification tool produces an indicative figure in about five minutes. A scoped engagement covering your material business services takes longer and depends on how many scenarios you want modelled and how accessible your telemetry is.

Does this replace our GRC platform?

No. TrustCore includes 8-module integrated GRC, but quantification is designed to work alongside whatever governance tooling you already have rather than force a replacement.

FAIR Risk Quantification

Read the full fair risk quantification page →

Is FAIR an official standard?

FAIR is maintained as an open standard and is widely used for quantitative cyber risk analysis. Being open is the point: the model can be reviewed independently rather than accepted on a vendor's assurance.

Can FAIR results be used in a regulatory filing?

FAIR produces defensible, decomposable estimates that can support regulatory and board reporting. Whether a specific figure satisfies a specific filing requirement depends on that regulator and that filing — confirm the requirement before relying on it.

Do our analysts need to be trained in FAIR to use this?

Using 4sight does not require your team to be FAIR practitioners. TrustSphere also runs cybersecurity and GRC training if you want the capability held in-house rather than supplied.

How does FAIR handle scenarios we have never experienced?

That is what FAIR is designed for. Estimates are calibrated from industry data, comparable events and expert judgement, expressed as ranges wide enough to reflect the genuine uncertainty.

Cybersecurity GRC

Read the full cybersecurity grc page →

Do we have to replace our existing GRC tool?

No. TrustCore is designed to connect to existing investments rather than force a rip-and-replace. Where an incumbent GRC platform is working, TrustCore can sit alongside it and supply the live risk and quantification layer it lacks.

Which frameworks are supported?

The compliance module is framework-agnostic and is commonly run against RBI, CERT-In, DPDP, ISO 27001 and NIST. Additional obligations can be mapped into the same model.

Can we start with one module?

Yes. Most programmes start with the module that hurts most — usually compliance or risk — and expand once the data model is proven.

How does this relate to 4sight?

TrustCore is the platform and the GRC data model. 4sight is the intelligence layer that predicts and quantifies on top of it. GRC gives you control state; 4sight tells you what that state is worth in financial terms.

AI Threat Intelligence

Read the full ai threat intelligence page →

Is this a replacement for our SIEM or EDR?

No, and it is designed not to be. 4sight sits above those tools and contextualises what they produce. TrustCore integrates with platforms including CrowdStrike, Palo Alto Networks, Microsoft Sentinel, Wiz, ServiceNow and Tenable, plus others via open API.

What does the AI actually do?

It is used for prediction and prioritisation — modelling which threats are likely to be relevant to your environment and ranking them by business consequence. It is not a substitute for analyst judgement; the design intent is to amplify it.

How is this different from a threat intelligence feed?

A feed delivers indicators. 4sight scores those indicators against your estate, maps them to affected business services and, where warranted, attaches a financial exposure figure.

Can we see the reasoning behind a prioritisation?

Yes. Prioritisation traces back to the asset, service and exposure inputs that produced it, which is what makes it defensible to an auditor or a board.

Attack Surface Management

Read the full attack surface management page →

Does ASM replace vulnerability management?

No. Vulnerability management tells you what is wrong on assets you know about. ASM tells you what is reachable, including assets that never made it onto the inventory. They are complementary, and TrustCore consolidates both.

How does this work across multi-cloud?

TrustCore integrates with cloud security platforms already in place, including Wiz, so multi-cloud exposure is consolidated into the same view as on-premise estate rather than reviewed separately.

How often is the surface re-checked?

Continuously, which is the distinction from a periodic scan. The cadence for any specific deployment is agreed during scoping.

What happens to findings after discovery?

They are mapped to affected business services, ranked by impact and, where the exposure is material, quantified so remediation priority can be defended.

RBI Cybersecurity Compliance

Read the full rbi cybersecurity compliance page →

Does TrustSphere guarantee RBI compliance?

No vendor can. Compliance is determined by your regulator against your specific circumstances. What TrustSphere provides is the control mapping, continuous evidence and quantified risk view that make a compliance position demonstrable and defensible.

Can this cover CERT-In requirements as well?

Yes. CERT-In obligations are mapped in the same integrated GRC model, which is deliberate — the value of one model is that overlapping obligations are reconciled rather than tracked separately.

We are an NBFC, not a bank. Is this relevant?

Yes. The integrated GRC model is framework-agnostic and is applied against whichever supervisory expectations apply to your entity type.

How does this help with the board's oversight duty?

By giving the board quantified residual exposure against named business services rather than a control-coverage figure, which is a materially different conversation.

DPDP Compliance

Read the full dpdp compliance page →

Is DPDP a security obligation or a privacy obligation?

Both, which is precisely why splitting them across two programmes causes trouble. The protection obligations are met by security controls; the governance obligations are met by privacy processes. One model covers both without duplicating the underlying inventory.

Can you model our DPDP penalty exposure?

4sight models breach exposure including regulatory consequence as one component alongside remediation and disclosure cost. The output is a modelled range, not a legal determination of liability.

How does this fit with our RBI obligations?

They are carried in the same integrated GRC model. Where a single control satisfies both, it is evidenced once rather than twice.

Do we need TrustCore to start?

No. TrustSphere also offers consulting engagements that assess data risk posture before any platform decision is made.

Third-Party Risk Management

Read the full third-party risk management page →

Does this replace our vendor questionnaires?

No — it puts them in proportion. Questionnaires remain useful evidence; the change is that assessment depth and follow-up are driven by what the relationship could cost rather than applied uniformly.

How do you handle fourth-party risk?

Subcontractor dependency is captured as part of mapping a supplier to the business services that rely on them, so concentration through a shared downstream provider becomes visible.

Can this integrate with our procurement or ITSM system?

TrustCore integrates with ITSM and workflow platforms including ServiceNow, and additional systems via open API, so vendor records are not maintained twice.

What if we only want this for our critical suppliers?

That is the recommended starting point. Tiering by modelled exposure is how the programme decides which suppliers are critical in the first place.

vCISO Services

Read the full vciso services page →

How is a vCISO different from a security consultant?

A consultant advises and departs. A vCISO holds the leadership function — owning the risk position, signing the board reporting and directing the programme — on a fractional basis.

What time commitment is typical?

It varies with regulatory exposure, estate complexity and reporting cadence. Commitment is agreed during scoping rather than sold as a fixed package.

Do we have to adopt TrustCore or 4sight?

No. The advisory engagement stands alone. Where quantification would materially improve decisions, it is available, but it is not a condition of the engagement.

Can a vCISO help us hire a permanent CISO?

Yes — shaping the role, the programme and the handover is a common reason organisations engage one in the first place.

Still have a question?

Ask it directly, or get a number of your own first with a free self-serve assessment.