Tel Aviv, Israel
2017
  |  By Kovrr
Compliance content answers the question of when an obligation starts. For the serious incident reporting duty in the AI Act, the honest answer is that it is disputed, and the dispute is not a failure of research. ‍ Two readings of the text point in different directions, neither is obviously wrong, and no authority has resolved it. What follows is the reasoning on both sides and what to do without picking one. ‍
  |  By Kovrr
An outage is normally modeled as deferred revenue. Production stops, orders wait, operations resume and some of the backlog is recovered by running longer. ‍ Where the inventory perishes, none of that applies. The stock is destroyed during the incident, restoring the systems does not bring it back, and running longer afterward produces new product rather than recovering the old. ‍
  |  By Kovrr
A trained model is expensive to produce, cheap to copy and impossible to recall. Where one is taken, the organization still holds it, and the loss is not that the asset is gone. ‍ What ends is exclusivity. Lost exclusivity is a different quantity from a destroyed asset, it carries no notification obligation, it appears in no breach cost dataset, and most estimates therefore put it at zero by omission rather than by judgment. ‍
  |  By Kovrr
Transitional relief normally works one way. A new rule arrives, existing products are carved out or given years, and anything built afterwards complies from the start. ‍ The marking obligation for synthetic content inverts that. Article 50 has applied since 2 August 2026, and a targeted transitional period gives extra time to systems that were already on the market rather than to new ones.
  |  By Kovrr
A session to a sanctioned AI provider looks the same on the network whichever account it ran under and whatever was in it. Transport encryption means a proxy sees a connection to an approved domain and a payload size. ‍ Which is fine until somebody asks whether an exposure is reportable. The question turns on three facts the network never held, and none of them can be reconstructed from a log afterward. ‍
  |  By Kovrr
Cyber risk in transport is usually framed around a collision. Signals manipulated, a train sent onto occupied track, an accident caused deliberately. ‍ Signalling is built to make that outcome unavailable. Any failure forces the system into its most restrictive state, so a compromise produces a halt rather than a crash. The loss is the halt, and rail is unusual in already having a published price for one. ‍
  |  By Kovrr
A cyber loss model has dozens of inputs and every one of them can be argued about. Record counts, downtime costs, control effectiveness, secondary loss factors, event likelihoods. ‍ A few of them determine the answer and the rest barely move it. Knowing which is which tells you where estimation effort belongs, and more usefully which disagreements about the model are not worth having. ‍
  |  By Kovrr
A model produces a figure, an event happens, and somebody asks whether the figure was right. It is the obvious question and it has almost no published answer, because the comparison is harder than it looks. ‍ A single realized loss cannot falsify a distribution. If a model puts a one percent chance on exceeding a threshold and the threshold is exceeded, the one percent case occurred, which is what the model said would sometimes happen. ‍
  |  By Kovrr
A correlation rule joins several telemetry sources and fires when they agree. Guidance on writing them concentrates on thresholds, ordering and tuning for noise. ‍ The decision that determines whether a rule works is upstream of all of that. Each source in a rule plays one of three roles, and treating them interchangeably is what produces a rule that misses real events or fires on ones nobody can act on. ‍
  |  By Kovrr
A breach response begins with a record count and a notification assessment. How many individuals, in which jurisdictions, under which statute. ‍ Some organizations hold almost no personal data and enormous quantities of other companies' commercial confidences. An insurer's claims files contain policyholders' loss histories, control failures and settlement amounts. The statutory machinery may not engage at all, and what engages instead is a contract portfolio. ‍
AI is merging into the modern workplace at roughly the pace computers did in the 1980s, and the risks are evolving just as fast. IBM and Ponemon found that 97% of organizations hit by an AI-related security incident lacked basic access controls, and 63% had no AI governance policy at all. In this video, Yakir breaks down the seven categories of AI risk every GRC leader needs to understand, and what separates knowing you have a control gap from knowing what it will cost you.
Ransomware has shut down hospitals and data breaches have exposed millions of patient records. But healthcare organizations still struggle to manage cyber risk, because decisions get made on compliance checklists and generic threat scores that reveal nothing about real business impact. In this video, Kovrr breaks down how cyber risk quantification turns healthcare threats into financial terms, and why that changes the conversation between CISOs, compliance leads, and the board.
AI adoption inside the enterprise has outpaced the governance built to contain it — 57% of employees have used AI tools for work without telling their manager. Policies get written and committees get formed, but exposure keeps accumulating, because data governance, AI oversight, and security are almost always run as three separate programs. In this video, Kovrr breaks down the three pillars that need to connect, and what separates a durable AI governance program from a documented one.
By now, most organizations have invested in AI governance. Far fewer have solved the problem that makes governance possible in the first place: knowing what AI they are actually running — and with 57% of employees using AI tools at work without telling their manager, the gap is wider than most inventories admit. In this video, Kovrr breaks down what an AI asset inventory actually is, why traditional asset management never catches shadow AI, and what it takes to keep the record accurate.
For years, security and risk managers have relied on spreadsheets to track their cyber risk. But as regulatory expectations tighten and threats grow more sophisticated, manual tracking cannot keep up. In this video, Kovrr walks through what a modern cyber risk register looks like when cyber risk quantification is built into its foundation. We cover.
For years, CISOs have walked into boardrooms with technical data dumps that don't land. In this video, Kovrr breaks down the 7 cybersecurity metrics that actually resonate with board directors, all framed in the financial and business terms they use to govern the enterprise. We cover: Generated with the help of AI.
  |  By Kovrr - Cyber Risk Quantification
live webinar with Aaron Turner, IANS Faculty, who presents findings from his recent IANS research, 7 Steps to Securing Multi-AI Deployments, and explain how security teams can apply proven principles to modern AI systems.
  |  By Kovrr - Cyber Risk Quantification
Kovrr’s new AI Risk Governance Suite gives enterprises the visibility, structure, and measurable control needed to manage GenAI responsibly across its full lifecycle. Join us for Office Hours: Part 1, where Or Amir will walk through the first three modules of the suite—showing how enterprises can gain real-time oversight and quantifiable insight into their AI landscape: Discover how these capabilities help enterprises align innovation with accountability—building a defensible foundation for responsible GenAI adoption.
  |  By Kovrr - Cyber Risk Quantification
In this session, Or Amir, Product Manager at Kovrr, showcases our new AI Risk Assessment and AI Risk Quantification modules — helping enterprises gain visibility, benchmark maturity, identify shadow AI, and turn exposure into measurable outcomes.
  |  By Kovrr - Cyber Risk Quantification
Explore Kovrr’s brand-new CRQ-Powered Cyber Risk Register — a first-of-its-kind solution that’s redefining the way organizations build cyber GRC programs and manage cyber risk. Led by Or Amir, Product Manager at Kovrr, this session will offer a hands-on deep dive into the risk register’s extensive capabilities and show you why moving beyond static, spreadsheet-based registers to a fully quantified, dynamic risk intelligence framework is necessary for achieving resilience in today’s landscape.
  |  By Kovrr
By its nature, cyber risk is dynamic. New events happen and evolve all the time, making it difficult for enterprises to financially quantify their financial exposure to cyber attacks. Around two years ago, for example, distributed denial-of-service (DDoS) attacks were making headlines, and now ransomware has come into heightened focus. It's reasonable to believe that other types of attacks will emerge in another two years and continue to change thereafter.
  |  By Kovrr
The number of data breaches reported in the first 6 months of 2022 has put this year on track to be the lowest year of reports in the last 5 years for large US corporations. By looking at the rate at which data breach events have been reported so far this year, we predict that the number of events reported is expected to be 15-20% of the number of breaches reported in 2021
  |  By Kovrr
The 2022 Verizon Data Breach Investigations Report (DBIR), the fifteenth such report in as many years, leads off with a startling statistic: Credentials are the number one overall attack vector hackers use in data breaches. Use of stolen credentials accounts for nearly half the breaches studied by Verizon, far ahead of phishing and exploit vulnerabilities, which account for 19% and 8% of attacks, respectively. Botnets, the fourth most common entry path for hackers, represent a mere 1% of attacks.

Kovrr financially quantifies cyber risk on demand. Our technology enables decision makers to seamlessly drive actionable cyber risk management decisions.

Kovrr's Quantum Cyber Risk Quantification platform enables decision makers to understand and financially quantify the changing profile of their cyber risk exposure.

Cyber Risk Management Made Easy:

  • Communicate Cyber Risk in Financial Terms: Enhance the board and C-Suite’s decision-making process by financially quantifying cyber risk.
  • Cybersecurity Investment Optimization: Prioritize and justify cybersecurity investments based on business impacts and risk reduction.
  • Measure Cyber Security Programs’ Effectiveness: Assess the ROI of your cybersecurity program and stress test it based on potential risk mitigation actions, thereby supporting better resource allocation.
  • 3rd Party Vendors Cyber Risk Exposure Analysis: Financially quantify cyber risk within your supply chain. Gain insights Into 3rd and 4th party exposure.
  • Regulatory Compliance and Governance Reporting: Meet increased demands from regulators to continuously quantify and manage cyber risk exposure.
  • Cyber Insurance Coverage and Price Optimization: Identify gaps between risk mitigation impact versus risk cyber insurance spending and needed coverage for 1st party and 3rd party.
  • Quantitatively Benchmark and Compare your Cyber Risk Exposure: Benchmark to your industry peers and internally compare between different business entities in a consistent, measurable and accurate way.

A cyber risk management platform to quantify custom cyber risk scenarios.