
Governance, Risk & Compliance
Citalid
Quantifies enterprise cyber risk in financial terms using real-time threat intelligence.
Citalid Overview
What it does
Citalid is a Cyber-Risk Quantification (CRQ) platform that translates an organization's cyber exposure into monetary terms so security spending and insurance decisions can be weighed financially. It applies the Factor Analysis of Information Risk (FAIR) model, driven by patented Bayesian AI that simulates threat-actor behavior against an organization's current defense maturity. Real-time cyber threat intelligence continuously reshapes each risk estimate, and Monte Carlo simulations turn thousands of modeled attacks into probability-weighted loss distributions.
How it works
An in-house cyber threat intelligence team monitors 700 threat actors and maps their tactics, feeding proprietary algorithms that estimate how often each scenario would strike. The engine models 1,000 risk scenarios, prices their financial impact through Factor Analysis of Information Risk (FAIR) and Monte Carlo methods, and projects the return on proposed security and insurance investments. Delivery spans four modules: Citalid Core for enterprises, Citalid Portfolio for insurers aggregating cyber risk across books of business, Citalid TPRM for third-party exposure, and the underlying Citalid Engine. An API exposes results, and outside-in attack-surface scanning from Cysmo enriches ratings.
Credentials and traction
Citalid was featured in Gartner's 2023 Hype Cycle for Cyber Risk Quantification. Named customers span large European enterprises and insurers, including Allianz, Capgemini, Lagardere, Groupe Rocher, Fresenius, and Zurich Insurance Group. The company operates under the EU General Data Protection Regulation (GDPR) and keeps all customer data hosted within the European Union, serving large enterprises and cyber insurers.
Key Capabilities
mapped to solution categoriesProfiles each third party at intake, capturing criticality, data sensitivity, service type, geography and regulatory requirements, to determine which risk domains apply to it and to scope the depth and cadence of assessment accordingly.
Distributes, collects and scores third-party assessments and security questionnaires from a maintained template library that spans risk domains and standards, with evidence requests, reminders, reviewer collaboration and scoring rules; stronger implementations scope questionnaire depth and cadence dynamically from the third party's risk profile rather than sending one template to every vendor.
Assigns each third party to a risk tier from its inherent risk profile and business criticality, with tier definitions and thresholds the customer can change, and uses the tier to set assessment depth, review cadence, approval routing and monitoring intensity so that workflows adjust automatically when a third party's tier changes.
Watches third parties between assessments for new risk events, such as security incidents, financial distress, sanctions or adverse-media hits and regulatory actions, and surfaces them through dashboards, reports, alerts, reminders and notifications; stronger implementations re-score the third party and trigger escalation or corrective action when an event crosses a defined threshold instead of only updating a dashboard.
Reads third-party-supplied documents such as SOC 2 reports, ISO certificates, policies and prior questionnaires with AI, extracts the relevant answers and evidence to prepopulate assessment responses, and evaluates submitted responses for gaps or inconsistencies so reviewers work the exceptions rather than reading every document.
Links critical third parties to the business processes, products, geographies and recovery objectives that depend on them, identifies concentration where several critical services rely on the same provider or the same fourth party, and supports contingency and exit planning, typically to meet operational-resilience regulation such as DORA.
Brings risk-domain data subscriptions into each third party's record, such as outside-in cybersecurity ratings, external attack surface findings, financial health, sanctions and adverse media, and ESG data, whether produced natively or ingested from a ratings or data-aggregator provider, and uses that data in scoring and ongoing monitoring so an indicator crossing a threshold updates the risk score and starts a workflow rather than only refreshing a dashboard.
Expresses a third party's risk in measurable, decision-ready terms, such as a financial exposure range or a calibrated score built from likelihood and impact, instead of a qualitative heat map, so third parties can be compared, prioritized and reported to executives on estimated impact.
Scores each third party's inherent and residual risk and measures its potential impact on the business or supply chain to produce an impact estimate, aggregating domain-level results into a composite score that can be rolled up across the portfolio and correlated with enterprise objectives and control performance.
Defines and models specific cyber threat scenarios such as ransomware, data breach, business email compromise, or cloud outage as the unit of quantification, tying each scenario to a business decision rather than an enterprise-wide average. Scenario library breadth and support for custom scenario authoring vary across products.
Models the financial loss drivers that set the magnitude of each scenario, including incident response, business interruption, data recovery, regulatory fines, legal liability, and reputational harm. Coverage of secondary and long-tail losses varies across products.
Makes modeling assumptions, input data, and uncertainty explicit and auditable, so quantified results are defensible to executives and reviewers rather than an opaque figure. Products range from glass-box models with tunable assumptions to closed proprietary methods.
Quantifies exposure to inform insurance coverage adequacy, policy limits, and risk-transfer decisions, and to justify control effectiveness during underwriting and renewal. Dedicated insurance modules are a differentiator rather than a universal capability.
Ranks and optimizes prospective security investments by financial risk reduction per unit of spend, supporting capital allocation, risk acceptance, and control-optimization decisions. Prescriptive optimization is stronger in some products than others.
Quantifies how the organization's existing security controls reduce financial exposure, expressing the monetary value of controls in place and the residual risk they leave. Products vary in whether control effectiveness is derived from observed data or from maturity self-assessment.
Runs Monte Carlo or equivalent simulation to express exposure as probability distributions and ranges, such as annualized loss exposure and loss-exceedance curves, rather than a single-point figure. Some products report only point estimates.
Translates quantified exposure into board-ready, CFO-ready, and executive-ready reporting in financial terms, supporting capital trade-offs, oversight, and budgeting and strategic-planning cycles. Reporting depth and boardroom framing vary across products.
Estimates how likely or how often each modeled scenario is to occur, drawing on threat intelligence, historical incident data, or actuarial loss datasets to ground the likelihood side of the calculation. Products differ in whether frequency is threat-intelligence-driven, actuarial, or expert-estimated.
Expresses the monetary impact of material cyber events for regulatory and disclosure obligations, such as SEC cyber disclosure and materiality assessment. Dedicated disclosure workflows are present in some products and absent in others.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
See how Citalid fits your stack
Add Citalid to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.