top of page
riemann_logo_ocean_blue_bronze_accent.png
Cronin Methodologies
Cyber Risk Quantification

Turn your qualitative risk register into a quantified, harm-inclusive figure regulators expect.

AVI is a patent-pending quantitative risk-scoring methodology that plugs directly into the CIS RAM / DoCRA framework you already run — converting ordinal impact ratings into dollar-denominated, harm-to-others-inclusive figures ready for executives and regulators.

1
2
3
You already run CIS RAM
A qualitative risk register with ordinal scores - reasonable, but not quantified.
AVI layers on top
Our patent-pending methodology converts likelihood and impact ratings into probable-loss magnitude and harm-to-others exposure.
Regulator-ready output
A dollar-denominated report and plan; demonstrating reasonable investments and attention to duty of care for others.
THE PROBLEM

Two 2025-2026 rules ask for numbers CIS RAM was never built to produce.

Cybersecurity firms and their clients overwhelmingly run qualitative or semi-quantitative frameworks — CIS RAM, NIST CSF, ISO 27001 — built to demonstrate "reasonable and appropriate" safeguards. That's a strong foundation. It just isn't a quantified one, and two new regimes now require quantification.

Quantitative Risk Analysis
Estimate the probability of your financial impact.
Compare financial risks to the financial cost of controls to determine cost efficiency.
CIS RAM Risk Analysis
Estimate the likelihood and impacts of cyber risks to you and to others. Compare that risk to risks posed by safeguards to determine reasonability. 
AVI Risk Analysis
Estimate the probability of quantitative and qualitative harms. Determine cost efficiency and reasonability.
That translation is where Cronin Methodologies operates. 
WHAT AVI DOES

AVI + CIS RAM / DoCRA

AVI extends the CIS RAM framework by quantifying its risk register into the dollar-denominated figures CCPA and SEC Item 106 now demand. Delivered today through an Excel-based workbook that runs live risk assessments alongside your existing CIS RAM register.

1
Quantified Risk Scores
Evidence-based probabilities of quantitative and qualitative harm; loss magnitudes in dollar amounts; all in terms boards, auditors, and regulators expect. 
2
Harm-to-Others Modeling
Explicit mapping of who is harmed - customers, third parties, the business itself - and by how much, consistent with DoCRA's core principle and regulatory requirements.
3
Compliance-Mapped Outputs
Cyber risk reports made understandable for Executives who make budget decisions and sensible for enforcement regulators.
WHO USES AVI

Two client segments, one channel.

Segment 01
Cybersecurity & MSSP Firms
Firms already running CIS RAM or similar assessments for their clients but lacking a quantification methodology to layer on top. AVI can be white-labeled, co-delivered as a subcontracted specialty, or licensed to train staff directly.
Segment 02
Direct Enterprise Clients
California-facing businesses crossing CPPA audit/risk-assessment thresholds, and SEC-reporting companies needing a defensible Item 106 materiality methodology - whether or not they already have a cybersecurity firm engaged.
ABOUT US

We are cyber standards, methods, and consulting practice.

Cronin Methodologies sells the missing quantification layer for CIS RAM; the framework companies, regulators, insurance agencies, and courts already trust. AVI is a proprietary, patent-pending quantitative risk-scoring methodology, implemented as an Excel-based workbook extension to CIS RAM and DoCRA (Duty of Care Risk Analysis).

Already running CIS RAM?
You're one layer away.

bottom of page