Technical documentation for interpreting report output and communicating it to clients
The Axio Severity Report translates cyber risk into financial terms using a set of realistic, company-specific attack scenarios rather than a single generic score or peer benchmarking. This document has two parts: Part 1 explains how the report's methodology and figures should be interpreted; Part 2 provides guidance on communicating the report's findings to a client or prospective client.
Part 1: How to Read This Report
1. Scenario-based modeling
Each scenario in the report is a specific, plausible attack narrative constructed around the subject company's business, systems, and industry — not an abstract industry-wide average. Each scenario addresses a single question: if this specific event occurred at this specific company, what would it cost?
Every scenario is built around a defined threat actor, a specific system or vulnerability, and a chain of consequences that follows logically from it. Because the narrative is concrete, each component of the loss estimate can be traced back to a specific cause rather than an undifferentiated aggregate figure.
2. Impact decomposition
Rather than estimating a single total-loss figure directly, each scenario's loss estimate is constructed by summing a set of individually estimated cost categories, referred to as impact classes (for example: forensics expenses, incident response, lost income from an outage, legal costs, regulatory fines, cost of stolen intellectual property, and notification costs). These impact classes are organized under impact quadrants: 1st Party Financial, 3rd Party Financial, 1st Party Tangible, and 3rd Party Tangible.
This method is referred to as impact decomposition. It is presented on each scenario's Loss Contributions slide, and it is more defensible than a single top-down estimate because each component driving the total can be individually identified and reviewed. The full calculation for every impact class — including the underlying formula and variables — is available for review in the Axio360 platform.
3. The Severity Distribution chart
Each scenario includes a Severity Distribution slide. The underlying model produces a full simulated loss distribution for the scenario — many thousands of hypothetical versions of the same event, varying assumptions such as incident duration or the volume of data affected. The chart plots this distribution directly, beginning at the 40th percentile and extending through the more severe, less likely outcomes in the tail.
To make specific points on the curve easy to reference, the chart includes markers at the 50th, 75th, 90th, 95th, 99th, and 99.5th percentiles. Each marker reports the loss value at that percentile — the loss that the corresponding share of modeled outcomes fell at or below. A full explanation of how to interpret a percentile is provided in Section 6.
The slide also highlights three headline figures alongside the chart: the median loss (the 50th percentile) and the 95th percentile loss, both of which are specific points on the plotted curve, and the mean loss (the probability-weighted average of all modeled outcomes), which is not a percentile but is included for additional context.
4. Likelihood
Alongside the severity figures, the Severity Distribution slide also reports a “chance of at least minimum loss” — a likelihood estimate sourced from the Cyentia Institute, an independent cyber risk research firm. This is an estimate, derived from empirical loss event data, of how often companies of a similar profile actually experience this type of event in a given year.
Likelihood is a distinct measure from severity, and the two answer different questions:
- Severity — “If the event occurs, how large is the loss at a given percentile of modeled outcomes?” — is derived from the simulation.
- Likelihood — “How often does this type of event actually occur?” — is derived from Cyentia's independent, empirical data.
These two measures move independently and should not be conflated: a given scenario may have a low likelihood of occurring but high percentile loss values if it does, while another scenario may occur more frequently but carry comparatively lower percentile loss values. Both dimensions should be considered together when evaluating a scenario's overall significance.
5. The Collection Summary — aggregation across scenarios
The Collection Risk Exposure Summary, near the front of the report, is not an additional scenario — it is the combination of every individual scenario into a single aggregate risk picture. Its loss percentiles describe the company's total cyber loss profile across the full set of modeled scenarios, rather than any single narrative.
Scenarios are not simply added together or averaged, as either approach would distort the resulting picture. Instead, the aggregation is weighted by each scenario's likelihood: a scenario that is more likely to occur carries more weight in shaping the combined loss curve, while a less likely scenario contributes proportionally less to that curve even if its individual severity is high. The result is a single, blended view of overall risk that reflects both the potential severity and the likelihood of each contributing scenario.
6. Interpreting percentiles
Percentiles are the most common source of confusion in reading this type of output, so the definition is stated plainly here:
A percentile answers the question: “X% of modeled outcomes were at or below this value.”
For illustration, using a hypothetical loss value of X:
- A median loss of X is the 50th percentile — half of the modeled outcomes were below X, half were above.
- A 95th percentile loss of X means that in 95 out of 100 modeled versions of the event, the loss was X or less. Only 1 in 20 modeled outcomes exceeded X.
Mean vs. median: the mean (average) can be pulled upward by a relatively small number of extreme, high-cost outcomes. When the mean is noticeably higher than the median for a given scenario, it indicates that a subset of severe outcomes in the tail of the distribution is driving the average upward — relevant context when evaluating excess limits.
7. Slide-by-slide guide
A quick reference for what each recurring slide type shows and the question it's meant to answer:
| Slide type | What it shows | How to read it |
| Table of Contents | List of scenarios covered in the report. | Orientation only — shows what's included. |
| Collection Risk Exposure Summary | The aggregate loss picture across all scenarios combined, weighted by how likely each one is. | “What does my overall cyber loss exposure look like, across everything we modeled?” |
| Severity Distribution | One scenario's simulated loss range (mean, median, 95th percentile) plus its likelihood (“chance of at least minimum loss”). | “If this specific scenario happened, what would it cost — and how often does something like this actually occur?” |
| Loss Contributions | The scenario's total loss broken into individual cost categories (impact decomposition). | “What's actually driving this number?” |
| Scenario Narrative | A plain-language story of how the attack would unfold at this company. | “Does this sound like something that could really happen here?” |
| Systems/Assets and Privacy Risk Validation | Research findings showing the systems and technology described are plausible for this company, based on publicly available information. | “Is the technical setup in this story realistic?” |
| Attack Path Plausibility | Validation that the attack technique itself is realistic — grounded in industry reports, real incidents, proof-of-concept research, MITRE ATT&CK techniques, and CISA advisories. | “Could an attacker actually pull this off?” |
| Impact Reasonableness | Initial scoping of how the consequences would play out for this organization, grounded in comparable events and what would become inoperable. | “Does the scale of the loss estimate make sense?” |
| Precedents | Real-world incidents that resemble the scenario. | “Has something like this actually happened before?” |
Part 2: Positioning This Report With Clients
This section provides guidance for presenting this report to a client or prospective client. Its purpose is to ensure the report's analytical output is communicated accurately and functions as a productive risk conversation rather than a presentation of unexplained statistics.
1. Present the scenario narrative before the quantitative output
Non-technical stakeholders engage more readily with the Scenario Narrative than with a percentile table. The narrative should be presented first, establishing how the attack would unfold at the client's organization, followed by the associated figures to quantify the financial implications of that narrative.
2. Substantiating plausibility through the validation sections
Clients and prospects frequently ask how a given scenario's plausibility for their organization was determined. The Systems/Assets and Privacy Risk Validation, Attack Path Plausibility, and Precedents sections address this directly and should be referenced when the question arises. These sections ground the scenario in the company's technology footprint where that information is publicly confirmable, in close industry analogs where it is not, in documented attacker techniques, and in precedent incidents at comparable organizations.
3. Distinguishing plausibility from severity
Attack Path Plausibility and Precedents address whether a scenario could occur; the severity figures and percentiles address the magnitude of loss if it does. These two dimensions should remain distinct in discussion. A scenario with a low likelihood of occurrence may still carry sufficient severity to warrant coverage consideration, and the two should not be collapsed into a single judgment of relevance.
4. Applying percentiles to limit and retention decisions
Percentile figures are most useful to clients when tied directly to a coverage decision rather than presented as a standalone statistic. For example: a limit selected to respond at the 95th-percentile outcome for a given scenario corresponds to adequate coverage in 95 out of 100 modeled outcomes for that scenario. Framing the figures this way connects the analysis to the decision the client is being asked to make.
5. Terminology for client communication
Technical terminology should be translated into plain-language equivalents in client-facing discussion. Recommended substitutions include:
- In place of “the 95th percentile is X,” use “in the worst 1-in-20 modeled version of this scenario, losses reach approximately X.”
- Terms such as “distribution,” “simulation output,” and “percentile” should be reserved for discussions where the client has requested the underlying technical detail.
6. Aligning slide selection to the discussion objective
The Collection Summary should be used for discussions concerning overall program size, limits, and retention. The individual scenario slides should be used for discussions concerning the specific drivers of exposure and the prioritization of security investment.