AegisIntel Advisory · Exposure Engine · Nigeria

Cyber risk,
priced in Naira.

The AegisIntel Exposure Engine is a cyber loss quantification framework built for CBN-regulated institutions that need more than a risk rating. It models your threat environment, runs scenario simulations, and produces outputs your BRMC, audit committee, and external examiners can interrogate.

What It Is

Most Nigerian financial institutions know they have cyber risk. Few can say what it costs. The Exposure Engine converts your control environment and threat profile into quantified loss scenarios — denominated in Naira, mapped to business lines, and structured for board and risk committee consumption. No black box. No vendor lock-in. One accountable advisor who built it and runs it with you.

I.

How It Works

Four-stage engagement model
01
Scoping & Asset Inventory

We define the scope — critical systems, data assets, business lines — and map the threat actors most relevant to your institution's profile. CBN-regulated institutions have a distinct threat landscape; we start there, not with a generic framework.

02
Control Environment Assessment

We assess your existing controls against the scenarios defined — not to audit compliance, but to calibrate how much your controls actually reduce loss frequency and magnitude. This feeds directly into the simulation inputs.

03
Monte Carlo Loss Simulation

Using FAIR methodology and PERT distributions, we run 10,000 loss simulations across your defined scenarios. Outputs are Naira-denominated and FX-adjusted where relevant. You see a loss exceedance curve, not a single number that hides uncertainty.

04
Board-Ready Reporting

We produce a structured report calibrated for three audiences: the BRMC or board (narrative and loss ranges), the audit committee (methodology and assumptions), and management (scenario breakdown and control recommendations). Each version is standalone.

II.

What You Receive

Structured deliverables, not slide decks
Deliverable 01
Loss Exposure Report

Naira-denominated loss ranges for each defined scenario, with annualised loss expectancy and 90th-percentile exposure figures your finance committee can act on.

Deliverable 02
BRMC Narrative Brief

A standalone board-level document presenting risk exposure in plain language — designed to satisfy CBN examination questions on cyber risk governance.

Deliverable 03
Control Prioritisation Matrix

A ranked list of control investments by their modelled impact on loss reduction — so your next security budget conversation is grounded in numbers, not instinct.

Deliverable 04
Simulation Model

The underlying Python Monte Carlo model, documented and transferable. You own it. Run updated scenarios as your environment changes without re-engaging from scratch.

Deliverable 05
Methodology Statement

A formal methodology document suitable for submission to external auditors, the audit committee, or CBN examiners who ask how cyber risk is being quantified.

Deliverable 06
Annual Refresh Option

A scoped re-run engagement each year to update assumptions, incorporate new threat intelligence, and reflect control changes — keeping your exposure figures current.

III.

When Institutions Use It

Commercial & Merchant Banks
Board cyber risk reporting under CBN guidelines

Satisfying BRMC and audit committee requirements for quantified cyber risk without building an internal model from scratch.

Fintechs & Payment Institutions
Pre-licensing or pre-audit risk quantification

Demonstrating a credible cyber risk management framework to CBN examiners during licensing, renewal, or regulatory review.

Microfinance Banks
Right-sized exposure modelling on a constrained budget

Getting board-quality risk figures without the cost of a Big Four engagement — the model scales to the institution's complexity.

Insurance & Capital Markets
Cyber insurance underwriting support

Providing underwriters with a structured, methodology-backed loss exposure statement to support cyber insurance applications or renewals.

IV.

Methodology

Built on recognised international standards
Foundation
Factor Analysis of Information Risk (FAIR)

FAIR is the only internationally recognised standard for cyber risk quantification. It decomposes risk into frequency and magnitude components, forcing precision about what you actually know versus what you're assuming.

  • Threat event frequency modelling
  • Vulnerability and control strength calibration
  • Primary and secondary loss magnitude estimation
  • Scenario-based rather than asset-based framing
Simulation Engine
Monte Carlo Simulation — 10,000 Trials

Each scenario runs 10,000 simulated loss events using PERT distributions calibrated to your institution's environment. The output is a loss distribution — not a single point estimate — giving your board an honest picture of the range of outcomes.

  • PERT distributions on all input variables
  • Naira-denominated outputs with FX adjustment
  • Loss exceedance curves for board presentation
  • Annualised loss expectancy (ALE) per scenario
V.

Request an Engagement

Start the conversation.

Whether you're preparing for a board presentation, a CBN examination, or simply want to understand your institution's true cyber exposure — reach out directly. Engagements are scoped individually; no off-the-shelf packages.

Enquiries are reviewed personally. Responses within 24 hours.
Base
Lagos, Nigeria