Security teams have become fluent at describing supplier risk in their own language: ratings, findings, severity levels. Boards and finance committees speak a different one. When a director asks "what could this supplier cost us if it goes wrong?", a Cyber Risk Rating of "Fair" is an honest answer, but not a particularly useful one.
On 17 August 2026, Panorays launched Cyber Risk Quantification (CRQ), which puts a financial estimate on the risk each supplier brings. Drystan Govender, Panorays lead at Cyber Retaliator Solutions (CRS), explains how it works, the four loss scenarios it models, and how CRS partners can use it to move third-party risk from the security team's dashboard into the boardroom.
💬 The Question Ratings Can't Answer
Ratings do an important job. Panorays' Cyber Posture Rating scores a supplier's external security from 0 to 100, and its Cyber Risk Rating places each supplier on one of five levels, from Bad to Excellent, based on impact and likelihood. For prioritising security work, that is exactly what practitioners need.
But ratings are relative and qualitative. They tell you a supplier is weaker than it should be. They do not tell you whether fixing that weakness justifies delaying a project, renegotiating a contract or changing supplier. Those are business decisions, and business decisions are made in financial terms.
🔍 What Gets Lost in Translation
- Boards struggle to compare supplier risk with other entries on the enterprise risk register that are already expressed financially.
- Security teams struggle to justify where continuous monitoring and remediation effort should go first.
- Risk appetite stays abstract, because it has no common unit of measure.
Panorays' 2025 CISO survey found that 81% of CISOs say their third-party risk management budget is insufficient. In CRS's view, one reason is that third-party risk is still presented to decision-makers as a colour or a grade rather than as financial exposure.
📐 What Panorays CRQ Does
Panorays CRQ is built on the Open FAIR™ v2.0 model. For each supplier, it calculates an Annualised Loss Expectancy (ALE): an estimate of the loss the relationship could be expected to generate over a year. That estimate is broken down across four loss scenarios, so every supplier carries a figure that can sit alongside the other financial risks an organisation already tracks, rather than a stand-alone score.
✅ What Changes for Risk Teams
- Per-supplier exposure: each supplier's risk is expressed as an annualised loss estimate, not only as a rating.
- A scenario breakdown: exposure is split across four scenarios, showing not just how much risk a supplier carries but what kind of risk it is.
- A published model: because CRQ is built on Open FAIR v2.0 rather than a proprietary formula, the approach can be explained to risk, finance and audit colleagues.
🎯 Four Ways a Supplier Can Hurt You
Panorays CRQ models four loss scenarios for each supplier. The descriptions below are CRS's plain-language reading of what each one represents.
- Availability Loss: the impact if a supplier's outage or compromise disrupts the services and processes that depend on it, such as a hosted platform your customers use every day becoming unavailable.
- Data Leak Loss: the impact if data you have shared with a supplier is exposed. For South African organisations handling personal information, this scenario carries obvious regulatory weight.
- Fraud Loss: the impact if a compromised supplier becomes a channel for fraud, for example a hijacked supplier mailbox used to send convincing payment-change requests.
- Supply Chain Attack Loss: the impact if attackers use a supplier's access, software or services as a route into your own environment.
Seeing exposure by scenario matters because the right response differs. A supplier with high availability exposure may call for continuity planning and alternatives. A supplier with high data-leak exposure may call for tighter data-sharing terms and stronger security controls. A single blended score hides that distinction.
🧮 Why the Quality of the Inputs Matters
Any quantification is only as trustworthy as the evidence underneath it. A loss estimate built on guesswork is still guesswork, however precise it looks. What makes CRQ interesting, in CRS's view, is that it sits in the same platform as the evidence Panorays already gathers on each supplier.
- Outside-in evidence: hundreds of non-intrusive tests across the Network & IT, Application and Human layers, with rating accuracy Panorays reports at 99.4% and disputed findings validated within 24 hours.
- Validated questionnaires: Smart Questionnaire answers are checked against posture data and supplier documents rather than taken on trust.
- Business context: Risk DNA captures business criticality, data sensitivity, risk appetite and compliance requirements for each relationship.
- Nth-party visibility: supply chain discovery maps fourth and Nth parties. That matters, given that Panorays' 2026 CISO survey found 50% of incidents originated beyond direct third parties.
For CRS, this is the difference between quantification as a once-off spreadsheet exercise and quantification grounded in continuously refreshed evidence.
🏛️ Taking Supplier Risk to the Board
CRQ gives security leaders a way to answer the board's question in the board's own terms. In CRS's view, that changes several conversations at once.
🗣️ Conversations CRQ Makes Easier
- Prioritisation: ranking suppliers by estimated exposure, not only by rating, makes it clearer which remediation plans to push first.
- Proportionate effort: exposure estimates help justify which suppliers belong in continuous monitoring and which can stay in Inventory. See risk-based supplier tiering with Panorays.
- Contract terms: quantified exposure gives procurement and legal teams evidence when agreeing contractual cyber clauses with high-exposure suppliers.
- Risk appetite: boards can express appetite in financial terms and see which suppliers sit outside it.
🌍 Speaking the Board's Language
For South African boards, the most persuasive version of supplier risk is one expressed in rand and set alongside the other financial risks they already oversee. CRS works with partners to help customers frame third-party exposure in exactly those terms, and to report it through Panorays' Board Member View and, within the managed service, a regular Management & Board report.
In CRS's view, this also supports good governance. King IV asks governing bodies to govern technology and information in a way that supports the organisation's strategic objectives, and that is far easier when technology risk held by suppliers is presented in a form the governing body can weigh against everything else on its agenda.
🚀 Getting Started
CRQ is one of Panorays' most recent additions, and in CRS's view it is most valuable once suppliers are properly inventoried, tiered and assessed. The fastest way to see Panorays working on your own supplier base is a proof of concept on up to five critical suppliers. All Panorays needs to begin is the names and domains of those third parties.
Ready to put a number on supplier risk that your board will act on? Explore Panorays on the CRS solution page, or, if you are a reseller, MSP or MSSP, become a CRS partner and bring board-level third-party risk reporting to your customers.
