What is our primary use case?
The main use case for ThreatConnect Risk Quantifier is cyber risk quantification, where we translate technical vulnerabilities into business impact and potential financial loss. We also use it for prioritization remediation. It helps the security team focus on high-impact first risk, and another use case is executive reporting, where RQ dashboards and reporting make it easy to represent risk metrics to management and boards. Additionally, we integrated it with Splunk to automate risk scoring and incident tracking.
We use ThreatConnect Risk Quantifier daily in our day-to-day life. On a daily basis, we use RQ to monitor and qualify ongoing risk across our system. Each morning, I check the dashboards to see updated risk scores from integrating tools such as ServiceNow and Splunk. The team uses it to prioritize remediation tasks, focusing on high-impact vulnerabilities first. I also run scenario analysis or test the effect of new security controls and generate reports for leadership.
Overall, it's a part of our daily workflow for risk tracking, decision-making, and automation of repetitive reporting tasks.
What is most valuable?
Some of the best features ThreatConnect Risk Quantifier offers and that we use daily are risk scoring, which converts technical vulnerabilities into business-level financial impact. Another feature is risk reporting and dashboards; the dashboards and reports provide clear visualization for leadership and stakeholders. Also, the risk assessment and analysis help prioritize remediation based on actual business risk, while scenario analysis allows for what-if modeling to see the impact of potential threats or security investments.
The integration and automation with ServiceNow, Splunk, and Qualys connect to automate data collection and scoring, and the data visualization consists of interactive charts and dashboards that make insights easy to interpret. Overall, all these features save time, improve accuracy, and help align security decisions with business priorities.
With ThreatConnect Risk Quantifier, our team can respond much faster because risks are quantified and prioritized automatically, so we know what to tackle first. Leadership also views security differently now. The dashboards and reports translate technical risk into business impact, which helps them make informed decisions and support the right security investment. Overall, it's improved both our operational speed and executive confidence in risk management.
ThreatConnect Risk Quantifier definitely saves our time and money. For example, manual risk reporting time dropped by around 60% to 70% since the dashboard and automated scoring handle most calculations. We also prioritize remediation more effectively, focusing on high-impact risks first, which helps avoid unnecessary spending. Leadership reports are generated in hours instead of days, and overall, the team can handle more risk with the same resources, improving efficiency and decision-making.
What needs improvement?
Overall, ThreatConnect Risk Quantifier is powerful, but there are some areas for improvement. A few areas could be better; first, the learning curve is steep for new users, and a guided onboarding or tutorial would help. Second, report customization could be more flexible so different teams can see exactly what they need. Additionally, handling very large data sets can slow down occasionally, so performance optimization would be helpful. Finally, adding more predictive analytics or AI-driven insights could automatically highlight unusual risks or trends without manual analysis.
We mostly work on data, so we face many challenges with large data sets when using ThreatConnect Risk Quantifier. When you feed very large data sets into RQ, such as hundreds of applications and thousands of vulnerabilities, the performance can sometimes slow down during scoring or dashboard updates. It doesn't break, but processing can take longer than expected. This is mostly unnoticeable during bulk imports or complex scenario analysis, so planning updates during off-peak hours or breaking data into smaller batches can help. Overall, it's reliable, but performance could be improved for very large-scale data and environments.
It would be great to have more interactive dashboards that let users drill down easily without leaving the main view. Another useful addition could be automated alerts or notifications when risk scores change significantly, so the team doesn't have to check a dashboard constantly. Lastly, more built-in guidance or AI tips for interpreting FAIR-based metrics could help new users to get up to speed faster. Overall, the tool is strong, but these additions would make it even more efficient and user-friendly.
For how long have I used the solution?
I have been using ThreatConnect Risk Quantifier for about eight to nine months.
What do I think about the stability of the solution?
ThreatConnect Risk Quantifier is very stable. As it is a cloud-based solution, it is very scalable, and we haven't experienced any downtime or major reliability issues. The platform performs consistently over time, even when handling multiple integrations and large data sets.
Overall, it's reliable for daily risk quantification and reporting.
What do I think about the scalability of the solution?
ThreatConnect Risk Quantifier is very scalable since it is a cloud-based solution on AWS. It easily handles growing data sets, more applications, and additional users without extra infrastructure. As our organization expanded, we could add new integrations and track more risks without impacting performance. It definitely grows with our needs.
How are customer service and support?
The customer support for ThreatConnect Risk Quantifier was very supportive, and they definitely solve our problems. Customer support is excellent; the team is responsive, knowledgeable, and provides clear guidance. Whenever we had questions about integration or configuration, they helped us quickly without the need for lengthy tickets. Overall, support is reliable and makes using the platform much easier.
I would rate the customer support for ThreatConnect Risk Quantifier nine out of 10 because they are very responsive and have a helping nature. They always solve our problems for deployment, integration, and configuration, and they are very knowledgeable and help resolve issues quickly. The reason it's not a 10 is that sometimes response times vary depending on the complexity of the questions, but overall, it's excellent.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Before I joined my company, they were using RiskLens. When I joined my company, they had already shifted to ThreatConnect Risk Quantifier, so they previously used RiskLens and also relied on manual Excel-based models for risk quantification. RiskLens was strong in financial modeling but lacked smooth integration with our tools, and Excel was too manual and error-prone. They switched to ThreatConnect Risk Quantifier because it automates risk scoring, integrates seamlessly with ServiceNow and Splunk, and provides clear dashboards, which saves them a lot of time and improves accuracy.
How was the initial setup?
The deployment of ThreatConnect Risk Quantifier is straightforward since it is a cloud-based SaaS solution hosted on AWS. There's no need to manage servers or worry about updates, and it scales automatically. We connected it with tools such as ServiceNow, Splunk, and Qualys for automated data collection and risk scoring. Overall, it was smooth, and the cloud setup made integration and scaling much easier.
What was our ROI?
ThreatConnect Risk Quantifier is very profitable for our organization, for my ex-organization. We have definitely seen ROI; for example, manual risk reporting time dropped by around 60% to 70% thanks to automated scoring and dashboards. We also prioritize high-impact risks more effectively, which avoids unnecessary spending on low-priority issues. Overall, the team can handle more risk with the same resources, and leadership gets actionable insights faster. It definitely improves decision-making and efficiency.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for ThreatConnect Risk Quantifier is overall good because the pricing is reasonable for the value it provides. Though it's not the cheapest option, there wasn't any significant setup cost since it's a cloud-based solution, and most of the work involved integration and onboarding. The licensing is flexible; we got a subscription model that scales with the number of users and integration, which works well for organizations of different sizes.
What other advice do I have?
My advice for others looking into using ThreatConnect Risk Quantifier would be to invest time in training on the FAIR model before fully using the platform and make sure your data is clean and structured for accurate risk scoring. Also, leverage the integration with tools such as ServiceNow and Splunk to get the most value and automate workflows. It's a strong tool for organizations that want to quantify risk in business terms and improve decision-making.
ThreatConnect Risk Quantifier is a very powerful and reliable tool for quantifying and managing cyber risk. It's especially strong in automation, integrations, dashboard, and scenario analysis. My main suggestion would be to improve onboarding, report customization, and performance with very large data sets. But otherwise, it really helps our team make faster, more informed decisions and communicate risk effectively to leadership. It's the best tool for risk management. I rate this solution 8 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)