RAV Risk Measurement
The one thing the adversary doesn't get to author.
Coming soon.
An operational risk measurement built on OSSTMM 4's Risk Assessment Value (RAV) formula. Ratio-scaled, vendor-neutral, defender-focused.
What this is
A public calculator that produces a ratio-scaled RAV score from empirically observed inputs: porosities, controls, and limitations across the five OSSTMM dimensions.
Not a heatmap. Not a Monte Carlo simulation. Not a telemetry index. RAV measures what your controls actually establish against what your system actually exposes.
Why not Likelihood times Impact
Three eras of the same broken axiom:
- Heatmap era. Ordinal-scale multiplication treated as ratio-scale arithmetic. Cox 2008 formally proved rank inversion.
- Calibrated-probability era. Monte Carlo simulation on estimated three-point tuples. Still speculative modeling, still measuring the attacker side.
- Telemetry-AI era. Cyber Risk Indices reduce to
sqrt(Likelihood × Impact)with a square-root sticker over the same ordinal math, vendor-locked to an XDR platform.
All three measure the attacker. A capable adversary controls what's observed, so watching the attacker cannot measure defender trustworthiness. RAV escapes by measuring the defender's own operational state, which is the one thing the adversary doesn't get to author.
How the RAV works
Inputs the tester supplies:
- Porosity counts (P1 through P5) across the five dimensions: Visibility, Induction, Interactions, Intervention, Inquest
- Security Controls deployed at each (Dimension, Phase) coordinate: 15 total across Intent, React, and Resolve phases
- Limitations observed per dimension: Anomaly, Weakness, Vulnerability, Concern, Exposure
Output is a single ratio-scaled score expressing operational balance between deployed controls and observed limitations. Comparable across successive assessments to measure real change.