Launch — QWYQ is open for the first 100 organisations. Your input shapes what comes next.
CYBER RISK

Beyond the threat

Know what cyber risk really costs you — and what to do first.

Cyber risk is usually sold with fear or buried in technical detail. QWYQ does neither: guided questions, in plain language, that end in a number you can take to the board — with everything underneath it to act on.

We're inviting the first 100 organisations.

Top priority

Who can access what?

Risk is still higher than the team wants until someone owns access — and the team has practised what to do when something breaks.

01 · Access · Owner unclear
What you get

More than an amount.

Six outcomes, from the amount to the roadmap. The amount gets the attention; everything underneath it tells you what to do about it.

The amount

EUR 3.9M / year

Expected annual loss from a Monte Carlo simulation on your maturity scores, sector profile and revenue — always with a range. Plus what a severe year looks like (VaR95: EUR 29M) and a catastrophic one (TVaR95: EUR 70M).

Chance of an incident

7.7% this year

The probability your organisation is hit this year — here roughly once per 13 years. A low annual chance with a high scenario impact means: rare but heavy. That combination calls for risk transfer alongside prevention.

Maturity per domain

Five domains, scored 1–5

Where you stand on identity, infrastructure, data, detection & response and compliance — set against your sector's benchmark, with each domain's contribution to the total risk made explicit.

Scenarios per incident

What one incident costs you

Ransomware, data breach, outage — each as a plain-language storyline in three severities: likely, severe and catastrophic. Including where the money goes: direct recovery, lost revenue and reputation, fines.

Compliance status

Where you comply — and where not

For every framework that applies to you: the status, the gaps and their priority. Compliance becomes a worklist instead of a worry — and the frameworks follow from your region and sector, not from a sales pitch.

The roadmap

Must / Should / Could

A prioritised list of measures with the projected risk reduction per measure, in euros. The 'Must do' items at the top deliver the largest reduction on the shortest term — your investment route, in order.

Figures shown are from a real, anonymised assessment (Technology · Scale-up) — your outcome is calculated from your answers.

These are model-based estimates, always shown with a range. They exist to prioritise — not to predict the future to the euro.

Two ways in

Quick scan or assessment — your choice.

Both are open to every organisation, from startup to enterprise. You choose; the product doesn't choose for you.

Cyber quick scan

  • Short — one person
  • An indicative picture of your biggest risks
  • The loose first step

Cyber assessment

  • ±86 questions across five domains
  • Monte Carlo simulation behind the amount
  • Full roadmap, and re-measurements over time
Domains

Five domains, one lens.

Each domain is scored on maturity 1–5; Governance weighs the outcome.

  • Identity & Access
  • Infrastructure & Network
  • Data Protection & Privacy
  • Detection, Response & Recovery
  • Compliance & Regulation
Governance

The lens, not a score — it weighs the outcome. Little documentation and audit means controls probably perform worse than you estimate yourself.

See it first

Read a real risk dashboard.

The clearest answer to “what do I actually get?” is a real one. We publish anonymised example reports — from startup to enterprise.

FAQ
How reliable is the amount?

It's a model-based estimate, always shown with a range — built from your maturity scores, sector profile and revenue via a Monte Carlo simulation. It's made to prioritise decisions, not to predict losses to the euro. That's also why we never show it without the range.

Is the quick scan a security audit?

No. An audit inspects systems; QWYQ asks guided questions and turns them into a leadership-level picture: what's at risk, what it could cost and what to tackle first.

Do I need technical knowledge to fill it in?

No. The questions are in plain business language. Where technical knowledge helps, involve the person who knows — the answers combine naturally.

What's the difference with hiring a consultant?

QWYQ is self-service: your own team answers, the model does the work, and the outcome is yours to act on — or to hand to an advisor with a much sharper brief.

How long does it take?

The quick scan takes minutes. The full assessment is ±86 questions in plain language — most organisations complete it comfortably within a working session.

Know where you stand — in euros, not adjectives.

Start with the quick scan, or go straight to the assessment.

Keep me posted