enterprise-risk-assessment

Quantify enterprise cyber risk with FAIR methodology and ALE estimates.

3|3|Updated Mar 8, 2026
One-click install
npx skills add https://github.com/jaskaranhundal/usap-skills --skill enterprise-risk-assessment-jaskaranhundal
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: enterprise-risk-assessment
Source: https://github.com/jaskaranhundal/usap-skills/tree/main/risk-compliance/enterprise-risk-assessment
Command: npx skills add https://github.com/jaskaranhundal/usap-skills --skill enterprise-risk-assessment-jaskaranhundal

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill quantifies enterprise cyber risk using the FAIR methodology, producing financial estimates of potential losses and actionable insights for board-level decision-making.

Core Features & Use Cases

  • FAIR Methodology Application: Quantifies risk scenarios with Annualized Loss Expectancy (ALE) ranges.
  • Risk Heat Map Generation: Visualizes inherent and residual risk across different tiers.
  • Board Reporting: Provides concise, financial-focused summaries for executive review.
  • Use Case: Assess the financial impact of a ransomware attack, identify key controls, and present the ALE to the board to justify security investments.

Quick Start

Quantify the enterprise risk for a ransomware attack scenario using the FAIR methodology.

Frequently Asked Questions about enterprise-risk-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I quantify cyber risk in dollar terms for board reporting?

The FAIR methodology quantifies risk scenarios by calculating Annualized Loss Expectancy (ALE) ranges, translating cyber threats like ransomware and data breaches into financial loss estimates for executive review.

How do I calculate Annualized Loss Expectancy for a ransomware attack scenario?

Calculating Annualized Loss Expectancy (ALE) for a ransomware attack involves applying FAIR methodology principles to assess the scenario, estimate financial losses, and identify control gaps for risk acceptance decisions.

Can I generate a risk heat map showing inherent and residual risk tiers?

Yes, the skill generates risk heat maps that visualize inherent and residual risk across different tiers, providing actionable insights and concise financial-focused summaries for executive review.

What is the best way to identify control gaps using FAIR methodology?

Identifying control gaps using FAIR methodology involves quantifying enterprise risk scenarios to produce ALE ranges, highlighting where security investments are needed to reduce financial loss estimates and justify expenditures.

Does enterprise risk assessment require specific prerequisite knowledge of FAIR principles?

Yes, effective enterprise risk assessment requires adherence to FAIR principles, meaning users should understand how to define risk scenarios and apply the framework to generate accurate financial loss estimates.