Who can access what?
Risk is still higher than the team wants until someone owns access — and the team has practised what to do when something breaks.
Beyond the threat
Cyber risk is usually sold with fear or buried in technical detail. QWYQ does neither: guided questions, in plain language, that end in a number you can take to the board — with everything underneath it to act on.
We're inviting the first 100 organisations.
Risk is still higher than the team wants until someone owns access — and the team has practised what to do when something breaks.
Six outcomes, from the amount to the roadmap. The amount gets the attention; everything underneath it tells you what to do about it.
Expected annual loss from a Monte Carlo simulation on your maturity scores, sector profile and revenue — always with a range. Plus what a severe year looks like (VaR95: EUR 29M) and a catastrophic one (TVaR95: EUR 70M).
The probability your organisation is hit this year — here roughly once per 13 years. A low annual chance with a high scenario impact means: rare but heavy. That combination calls for risk transfer alongside prevention.
Where you stand on identity, infrastructure, data, detection & response and compliance — set against your sector's benchmark, with each domain's contribution to the total risk made explicit.
Ransomware, data breach, outage — each as a plain-language storyline in three severities: likely, severe and catastrophic. Including where the money goes: direct recovery, lost revenue and reputation, fines.
For every framework that applies to you: the status, the gaps and their priority. Compliance becomes a worklist instead of a worry — and the frameworks follow from your region and sector, not from a sales pitch.
A prioritised list of measures with the projected risk reduction per measure, in euros. The 'Must do' items at the top deliver the largest reduction on the shortest term — your investment route, in order.
Figures shown are from a real, anonymised assessment (Technology · Scale-up) — your outcome is calculated from your answers.
These are model-based estimates, always shown with a range. They exist to prioritise — not to predict the future to the euro.
Both are open to every organisation, from startup to enterprise. You choose; the product doesn't choose for you.
Each domain is scored on maturity 1–5; Governance weighs the outcome.
The lens, not a score — it weighs the outcome. Little documentation and audit means controls probably perform worse than you estimate yourself.
The clearest answer to “what do I actually get?” is a real one. We publish anonymised example reports — from startup to enterprise.
It's a model-based estimate, always shown with a range — built from your maturity scores, sector profile and revenue via a Monte Carlo simulation. It's made to prioritise decisions, not to predict losses to the euro. That's also why we never show it without the range.
No. An audit inspects systems; QWYQ asks guided questions and turns them into a leadership-level picture: what's at risk, what it could cost and what to tackle first.
No. The questions are in plain business language. Where technical knowledge helps, involve the person who knows — the answers combine naturally.
QWYQ is self-service: your own team answers, the model does the work, and the outcome is yours to act on — or to hand to an advisor with a much sharper brief.
The quick scan takes minutes. The full assessment is ±86 questions in plain language — most organisations complete it comfortably within a working session.
Start with the quick scan, or go straight to the assessment.
Keep me posted