RAV Risk Measurement

The one thing the adversary doesn't get to author.

Coming soon.

An operational risk measurement built on OSSTMM 4's Risk Assessment Value (RAV) formula. Ratio-scaled, vendor-neutral, defender-focused.

What this is

A public calculator that produces a ratio-scaled RAV score from empirically observed inputs: porosities, controls, and limitations across the five OSSTMM dimensions.

Not a heatmap. Not a Monte Carlo simulation. Not a telemetry index. RAV measures what your controls actually establish against what your system actually exposes.

Why not Likelihood times Impact

Three eras of the same broken axiom:

All three measure the attacker. A capable adversary controls what's observed, so watching the attacker cannot measure defender trustworthiness. RAV escapes by measuring the defender's own operational state, which is the one thing the adversary doesn't get to author.

How the RAV works

Inputs the tester supplies:

Output is a single ratio-scaled score expressing operational balance between deployed controls and observed limitations. Comparable across successive assessments to measure real change.