Secure the front door. Email is where most attacks arrive — RELIQ turns your cyber risk into a real rupee figure (FAIR-based, grounded in your live posture) — so you can prioritise by exposure, justify security ROI, right-size insurance, and give your board a number they can actually govern.
Buy through TechBag
Same software. Better outcome — at no extra cost.
Free, vendor-neutral, 30 minutes
How it’s rated
Full scoreboard ↓Quick answer
RELIQ is Mitigata's cyber-risk quantification engine — it turns your cyber risk into a real financial number, in rupees, so you can measure, prioritise, insure and govern it like any other business risk, from India's full-stack cyber resilience company. Here's the problem it solves: most organisations talk about cyber risk in vague, qualitative terms — 'high', 'medium', 'low', a red-amber-green heatmap — which is nearly useless for actual decisions. You can't compare a 'high' risk to a 'medium' one in any meaningful way, you can't tell whether a security investment is worth its cost, you can't right-size your insurance, and your board can't govern a risk expressed in colours rather than money. Cyber risk is treated completely differently from every other business risk (which is measured in financial terms) — which is exactly why it's so hard to manage and fund. RELIQ fixes this by quantifying cyber risk financially, using the FAIR methodology (Factor Analysis of Information Risk — the recognised standard for cyber-risk quantification). It analyses your actual exposure — your assets, your threats, your vulnerabilities (informed by the live security Mitigata runs) — and expresses your cyber risk as a financial figure: how much you stand to lose, with what likelihood, in rupee terms. This transforms cyber risk from a vague worry into a measurable, comparable, fundable, insurable, governable number. You can prioritise the risks that carry the biggest financial exposure; justify security investments by the risk-reduction they buy (ROI); right-size your cyber insurance to your actual quantified exposure; and give your board a clear, business-terms figure they can actually govern. And because RELIQ is part of Mitigata's connected stack, the quantified risk directly informs your security priorities and your security-linked insurance. The result is cyber risk you can finally manage like a real business risk — measured in money, not colours. TechBag scopes, deploys and quotes it in INR/GST.
This page covers RELIQ — risk quantification. The rest of the stack:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Mitigata’s cyber-risk quantification engine — turns your cyber risk into a real rupee figure (FAIR-based) you can actually manage.
What consolidation actually replaces, dimension by dimension.
| Dimension | Unprotected / signature email | Mitigata RELIQ (Mitigata) |
|---|---|---|
| How risk is expressed | High/medium/low, colours | A rupee figure |
| Comparing risks | Meaningless | By financial exposure |
| Justifying spend | Guesswork / politics | Risk-reduction ROI |
| Sizing insurance | A guess | To real quantified exposure |
| Board governance | Ungovernable colours | A governable number |
| Method | Arbitrary / gut | FAIR (the standard) |
| Inputs | Static questionnaire | Live real posture |
| Connection | Standalone report | Drives security & insurance |
Cyber risk in high/medium/low colours is useless — you can't prioritise, fund, insure or govern it. RELIQ makes it a defensible rupee figure (FAIR-based) that drives your security and insurance.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Analyses your actual exposure — your assets and their value, the threats you face, and your vulnerabilities (informed by the live security Mitigata runs) — the real basis for quantification.
Applies the FAIR methodology (Factor Analysis of Information Risk — the recognised cyber-risk-quantification standard) to express your risk as loss magnitude × likelihood, in financial terms.
Produces a real financial figure for your cyber risk — how much you stand to lose, with what likelihood — turning vague qualitative risk into a measurable, comparable rupee number.
Lets you prioritise the risks with the biggest financial exposure, and justify security investments by the risk-reduction (ROI) they buy — funding decisions grounded in money, not hunches.
The quantified exposure right-sizes your cyber insurance (to your real figure, not a guess) and informs your security-linked cover — so risk, security and insurance connect through one number.
One agent on every machine, one console over all of them — modules attach without a second operational world.
RELIQ quantifies your cyber risk financially (FAIR) and connects it to real decisions. What it delivers:
One accountable partner — not a dozen point vendors. TechBag scopes exactly what you need in INR/GST.
Cyber risk in colours is useless — RELIQ makes it a rupee figure you can manage — part of the portfolio, and paired with the human firewall.
Uses the FAIR methodology — the recognised standard for cyber-risk quantification — so your risk figure is grounded in a rigorous, defensible, industry-accepted method, not a made-up number.
Expresses your cyber risk as a real financial figure — how much you stand to lose, with what likelihood — replacing vague high/medium/low ratings with a measurable, comparable number.
Grounds the quantification in the live security Mitigata actually runs (via Gordon) — so the risk figure reflects your real, current posture, not a static questionnaire or generic assumptions.
Model specific risk scenarios (a ransomware hit, a data breach, a specific system compromise) in financial terms — so you understand the exposure of the events that actually worry you.
Prioritise by financial exposure — so effort and budget go to the risks that carry the biggest potential loss, not to whatever's loudest or most recently in the news.
Justify security investments by the risk-reduction (in rupees) they buy — so you can defend spending with a clear return, and choose the controls that reduce the most risk per rupee.
Size your cyber insurance to your actual quantified exposure — so you're neither over-insured (wasting money) nor under-covered (dangerously exposed), grounded in a real figure.
Because risk is a number, you can compare risks meaningfully, and track your risk trending down over time as you remediate — measurable progress, not vague reassurance.
Give your board a clear, business-terms financial figure for cyber risk — so they can govern it like any other business risk, meeting the board-governance expectations of DPDP and SEBI.
Because it's FAIR-based and grounded in real posture, the figure is defensible — you can stand behind it with regulators, auditors, insurers and your board, not just assert a colour.
Distinctively, the quantified exposure feeds Mitigata's security-linked cyber insurance — so your risk figure directly informs, and right-sizes, the cover you buy through the same partner.
Runs within the Gordon console alongside your security, compliance and insurance — so your quantified risk, your controls, your compliance and your cover are one connected picture.
The overview, getting started, and protecting M365 email.
Quantified risk driving insurance & security.
Want a live, India-context walkthrough on your own fleet?
Book a guided demo →Here’s what genuinely sets RELIQ apart.
The fundamental reason RELIQ exists is that most organisations express cyber risk in vague qualitative terms — high/medium/low, red/amber/green heatmaps — which is nearly useless for actual decisions, and RELIQ fixes this by turning cyber risk into a real financial number you can genuinely manage. Consider how cyber risk is usually communicated: qualitatively. A risk is 'high' or 'medium' or 'low'; a heatmap shows red, amber and green cells; a risk register has severity ratings. This qualitative approach feels like risk management but is nearly useless for real decisions, for several concrete reasons. You can't compare: what does a 'high' risk mean versus another 'high' risk, or versus a 'medium'? Two 'high' risks might differ by orders of magnitude in real terms, but the colour hides that — so you can't meaningfully prioritise. You can't evaluate investments: is a security control worth its cost? With qualitative risk, you can't tell — you don't know how much risk it actually reduces in comparable terms, so security spending is guesswork or politics. You can't size insurance: how much cyber cover do you need? A heatmap can't tell you — you need a financial figure. And your board can't govern it: boards manage the business in financial terms (revenue, cost, risk in money), but cyber risk arrives as colours they can't relate to the business — so it's hard to govern, fund, or take seriously at board level. The root problem is that cyber risk is treated completely differently from every other business risk, all of which are measured financially — which is exactly why cyber risk is so hard to manage, prioritise and fund. RELIQ fixes this by quantifying cyber risk in financial terms. Using the FAIR methodology (the recognised cyber-risk-quantification standard), it analyses your real exposure and expresses your cyber risk as a rupee figure: how much you stand to lose, with what likelihood. Suddenly cyber risk is like any other business risk — measurable, comparable, fundable, insurable, governable. You can compare risks (by their financial exposure), evaluate investments (by risk-reduction ROI), size insurance (to your real figure), and give your board a number they can govern. This transformation — from useless colours to a manageable number — is what makes cyber risk finally manageable as a business risk. For any organisation that struggles to prioritise, fund, insure or govern its cyber risk (which is most, because they're stuck with colours), quantifying it financially is a genuine breakthrough. TechBag helps organisations quantify their cyber risk with RELIQ.
A crucial strength of RELIQ is that its quantification is both methodologically rigorous (FAIR-based) and grounded in your real security posture — so the financial figure it produces is defensible and accurate, not a made-up number, which is what makes it trustworthy enough to actually use for decisions. Consider what could undermine cyber-risk quantification: a number that's either methodologically unsound or based on bad inputs. If the method is arbitrary, the figure is just a guess dressed up as precision — and everyone will (rightly) distrust it. If the inputs (your actual exposure) are wrong or generic, even a good method produces a wrong figure. RELIQ addresses both. Methodological rigour (FAIR): RELIQ uses the FAIR methodology — Factor Analysis of Information Risk — which is the recognised, established standard for cyber-risk quantification, used and respected across the industry. FAIR provides a rigorous, structured way to decompose risk into its factors (threat frequency, vulnerability, loss magnitude) and quantify it defensibly. So the figure isn't arbitrary — it's produced by a recognised, rigorous method you can stand behind with regulators, auditors, insurers and your board. Grounded in real posture: critically, RELIQ grounds the quantification in your actual, live security posture — informed by the security Mitigata runs (the SOC, VAPT, monitoring via Gordon) — rather than a static questionnaire or generic industry assumptions. So the inputs reflect your real exposure (your real assets, threats and vulnerabilities), making the resulting figure accurate to your actual situation. Together, rigorous method + real inputs produce a figure that is both defensible (methodologically sound) and accurate (based on your reality) — which is exactly what's needed for the figure to be trustworthy enough to base real decisions on (prioritisation, investment, insurance, board governance). A quantification that's arbitrary or based on bad inputs would be worse than useless (false precision); RELIQ's rigour and grounding make its figure genuinely usable. This defensibility matters especially for board and regulatory contexts, where you need to justify your risk figure, not just assert it. For organisations that want a cyber-risk figure they can actually trust and defend, RELIQ's FAIR-based, posture-grounded approach is what delivers it. TechBag helps organisations get a defensible cyber-risk figure with RELIQ. The honest scope follows.
The practical payoff of RELIQ is that it enables genuinely better decisions across three areas that qualitative risk can't support — prioritising your risks, justifying your security spending, and right-sizing your insurance — all grounded in real financial figures. Consider each. Prioritisation: with qualitative risk, you can't truly prioritise (all your 'high' risks look the same). With RELIQ's financial figures, you can prioritise by real exposure — directing effort and budget to the risks that carry the biggest potential loss, rather than to whatever's loudest, most recent, or most politically visible. This means your limited security resources go where they reduce the most actual risk — a far more effective allocation. Security-investment justification (ROI): with qualitative risk, you can't evaluate whether a security investment is worth its cost — so spending is guesswork or politics, and good investments may be under-funded while poor ones proceed. With RELIQ, you can justify investments by the risk-reduction (in rupees) they buy — calculating a genuine ROI (this control costs X and reduces risk by Y), so you can defend spending to finance, choose the controls that reduce the most risk per rupee, and fund security rationally. This is transformative for getting security properly funded. Insurance sizing: with qualitative risk, you can't tell how much cyber insurance you need — leading to over-insurance (wasted premium) or under-insurance (dangerous exposure). With RELIQ's quantified exposure, you can size your cover to your actual figure — buying the right amount of cover for your real risk. And because RELIQ is part of Mitigata's connected stack, this feeds directly into Mitigata's security-linked cyber insurance, right-sizing your cover through the same partner. So RELIQ turns cyber-risk management from qualitative hand-waving into quantitative decision-making: prioritise by financial exposure, justify spending by ROI, size insurance to real risk. These are exactly the decisions that matter — where to focus, what to fund, how much to insure — and RELIQ makes them possible by grounding them in money. For organisations that want to make cyber decisions rationally rather than by hunch or politics, RELIQ's financial grounding is genuinely enabling. TechBag helps organisations make money-grounded cyber decisions with RELIQ. The honest scope follows.
A significant value of RELIQ is that it makes cyber risk governable at board level — by expressing it in the financial, business terms boards understand and manage — which matters increasingly as cyber-risk governance becomes a board obligation under regulations like DPDP and SEBI. Consider the board's relationship with cyber risk. Boards govern the business in financial and business terms: revenue, costs, margins, and risks measured in money (a market risk, a credit risk, an operational risk — all quantified). But cyber risk has traditionally arrived at the board as colours (high/medium/low, heatmaps) or dense technical detail — neither of which the board can relate to the business or govern effectively. So cyber risk has been hard for boards to genuinely govern: they can't compare it to other business risks, can't judge whether the investment is proportionate, and can't hold it accountable in the terms they use for everything else. This is a real governance gap, and it's becoming a real problem, because cyber-risk governance is increasingly a board obligation: DPDP places data-protection accountability at the leadership level, SEBI's framework requires board oversight of cyber resilience for regulated entities, and boards are increasingly expected (by regulators, investors and stakeholders) to govern cyber risk properly. But you can't govern what you can't measure in the terms you govern by. RELIQ closes this gap. By expressing cyber risk as a financial figure, it gives the board cyber risk in the terms they understand and govern by — a rupee figure they can compare to other business risks, judge investments against, track over time, and hold accountable, just like any other business risk. So cyber risk moves from an ungovernable colour to a governable number. This makes board governance of cyber risk actually possible — meeting the growing regulatory and stakeholder expectations, and letting boards do their job on cyber risk rather than nodding at a heatmap they can't really evaluate. And because the figure is FAIR-based and defensible, it's credible enough for board and regulatory use. For organisations where cyber risk needs to be genuinely governed at board level (increasingly all, under tightening regulation), RELIQ's financial expression is exactly what makes that possible. TechBag helps boards govern cyber risk with RELIQ. The honest scope follows.
RELIQ's quantified risk figure isn't an isolated calculation — because RELIQ is part of Mitigata's connected stack, the number ties together your security, your risk decisions and your insurance, making it far more valuable than a standalone quantification. Consider how a standalone risk-quantification tool relates to the rest of your cyber programme: loosely, if at all. It produces a figure, but that figure sits apart from your actual security operations and your insurance — so it informs a report but doesn't connect to action. RELIQ is different because it's woven into Mitigata's stack. Grounded in real security: as covered, RELIQ's quantification is informed by the live security Mitigata runs — so the figure reflects your real posture, and as your security changes, your risk figure updates. Drives security priorities: the quantified risks feed back into your security priorities (via Gordon) — so the figure doesn't just sit in a report, it directs where security effort goes (to the biggest financial exposures). Right-sizes insurance: distinctively, the quantified exposure feeds Mitigata's security-linked cyber insurance — so your risk figure directly right-sizes the cover you buy through the same partner, connecting risk quantification to actual risk transfer. So the RELIQ figure is the number that ties your cyber programme together: it's grounded in your real security, it directs your security priorities, and it right-sizes your insurance — all connected, one number linking posture, decisions and cover. This is genuinely more valuable than a standalone quantification that produces a figure disconnected from action: RELIQ's figure is actionable and connected, because it lives in the same stack as your security and insurance. And it embodies Mitigata's thesis: security, risk and insurance are connected, and one quantified figure can tie them together. For organisations that want their risk quantification to actually drive their security and insurance (not just produce a report), RELIQ's connected model is the difference. TechBag helps organisations connect risk quantification to action with RELIQ. The honest scope follows.
RELIQ is Mitigata's cyber-risk quantification engine — turning cyber risk into a defensible financial figure using the FAIR methodology, grounded in your real security posture, so you can prioritise by financial exposure, justify security ROI, right-size insurance, and give your board a governable number — distinctively connected, within Mitigata's stack, to your security priorities and your security-linked cyber insurance. The honest framing: cyber-risk quantification (CRQ) is an established discipline with dedicated specialists — RiskLens (the company most associated with FAIR, and its co-creators), Safe Security, and other CRQ platforms — that are deep, mature specialists in quantification specifically. For an organisation whose need is purely the deepest, most sophisticated standalone quantification (complex modelling, extensive scenario libraries), a dedicated CRQ specialist may go deeper on quantification methodology alone. RELIQ's distinctive value is not necessarily being the single deepest CRQ engine, but delivering solid, FAIR-based, posture-grounded quantification that is connected — informed by the live security Mitigata runs, driving your security priorities, and feeding your security-linked cyber insurance (right-sizing your cover through the same partner) — plus India-native context and rupee-denominated figures. It's most compelling for organisations (especially Indian ones) that want cyber-risk quantification that actually connects to their security and insurance and drives real decisions, as part of one accountable stack, rather than a standalone figure disconnected from action. For the deepest pure-play CRQ modelling alone, a specialist may complement it. TechBag scopes RELIQ honestly against CRQ specialists and quotes it in INR/GST.
How you express risk today (colours?), the decisions you struggle to make (prioritise, fund, insure), and your board's governance needs. TechBag scopes it free.
RELIQ analyses your exposure (assets, threats, vulnerabilities — informed by your live posture) and produces a FAIR-based rupee figure for your cyber risk.
Prioritise by financial exposure, justify security ROI, and right-size your insurance to your quantified figure — decisions grounded in money.
Give your board a governable figure, track risk trending down as you remediate, and feed the number into your security and insurance. TechBag models it in INR/GST.
Trusted across regulated industries in 100+ countries
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Turning our cyber risk into a rupee figure changed everything — we could finally prioritise by real exposure and justify security spend with actual ROI. High/medium/low never let us do that.”
“For our board, a financial figure they could govern like any other business risk was transformative — especially now that DPDP and SEBI make cyber governance a board obligation. Colours were ungovernable.”
“That it's FAIR-based and grounded in our real posture made the figure defensible — we could stand behind it with auditors, regulators and our insurer, not just assert a heatmap colour.”
“RELIQ right-sized our cyber insurance to our actual quantified exposure — no more guessing at cover. And because it feeds Mitigata's insurance directly, the connection was seamless.”
“We justified a security investment to finance by the risk-reduction in rupees it bought — a real ROI, not a plea. Quantification got our security properly funded.”
“That the figure connects to our live security AND our insurance — one number tying posture, priorities and cover together — is far more useful than a standalone quantification report.”
“Tracking our quantified risk trending down over time as we remediated gave us measurable proof of progress — not vague reassurance. Real, comparable numbers.”
“The honest note: for the very deepest standalone modelling, a pure CRQ specialist might go further — but RELIQ's connected, actionable figure fit our need to actually drive decisions. TechBag scoped it.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the email security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Connected FAIR CRQ — drives security & insurance. This page's product.
The grid nobody publishes — how strong the email detection is vs how integrated with the wider security portfolio.
Connected + posture-grounded + India-native.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
RiskLens, Safe Security, qualitative heatmaps and none — honest lanes; the edge is FAIR-based CRQ grounded in your live security, that drives your security priorities AND right-sizes your insurance.
| Dimension | RELIQ (Mitigata) | RiskLens | Safe Security | Qualitative heatmaps | No quantification |
|---|---|---|---|---|---|
| Position | FAIR CRQ in a connected stack | The FAIR CRQ pioneer | CRQ platform | Colours on a grid | The gap |
| Financial figure (money, not colours) | Rupee figure | Yes (its core) | Yes | No | No |
| FAIR methodology (defensible) | Yes | FAIR co-creators | FAIR-based | No method | N/A |
| Grounded in LIVE security you run | Yes — from Mitigata's ops | Data inputs / integrations | Integrations | Questionnaire | No |
| Drives security priorities | Feeds Gordon / the SOC | Informs, separately | Informs | No | No |
| Right-sizes your INSURANCE | Feeds Mitigata's cyber cover | Informs (separate insurer) | Informs | No | No |
| Board-ready & defensible | Yes | Yes (deep) | Yes | Simple but vague | No |
| India-native (rupees, context) | India-native | Global | Global | Generic | N/A |
| Part of one accountable stack | Security + compliance + insurance | Standalone CRQ | Standalone CRQ | A tool/spreadsheet | None |
| Best fit | Orgs wanting connected, actionable CRQ that drives security & insurance | Deepest standalone FAIR CRQ | Standalone CRQ platform | Nobody serious — colours don't enable decisions | Nobody — unmeasured risk is unmanageable |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Drag the sliders (count users; IT-hour cost as loaded incident rate). Estimates assume ~1.5 hours per user per year handling email threats that reach the inbox without AI filtering, with ~70% removed by stopping the mass at the gateway — the avoided-breach value (most attacks start here) is the larger, unpriced win. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models actual device counts and modules.
RELIQ is typically scoped within the Gordon platform (so the figure is grounded in your live security and feeds your insurance) — priced by your organisation and quantification depth. TechBag scopes it and quotes in INR/GST.
Best for risk quantification
Best for a broader rollout
Best complete
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your device counts and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Are you stuck with high/medium/low colours that can't support real decisions?
Turn your cyber risk into a defensible FAIR-based rupee figure with RELIQ.
Base the figure on your real, live posture — not a static questionnaire.
Prioritise your risks by financial exposure, not by what's loudest.
Justify security investments by the risk-reduction (₹) they buy.
Right-size your cyber insurance to your quantified exposure.
Give your board a governable cyber-risk figure (DPDP/SEBI governance).
Feed the figure into your security priorities and insurance — TechBag quotes in INR/GST.
Scope RELIQ (FAIR-based cyber-risk quantification in rupees, grounded in your live posture, that drives security priorities and right-sizes insurance), give your board a governable figure, or let a TechBag advisor plan your risk quantification.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.