You have three proposals on your desk and the numbers are thousands of dollars apart for what each vendor calls the same thing: an IT risk assessment. Your CFO wants to know why you would not just take the cheapest one. This post gives you the honest answer, including the cases where the cheapest one is the right call.
I run a company that sells risk assessments, so you should read this knowing that. I will make up for the bias with specifics.
For a credit union or community bank, IT risk assessment proposals mostly land between about $5,000 and $30,000, with a few above that for large or complex institutions. We compete in this market every week, and we are frequently not the cheapest option. More than one credit union has told us a CPA firm came in a couple thousand dollars under us, and some of them took that offer. A few came back later, and I will get to why.
The spread is not vendors being greedy at the top or desperate at the bottom. The proposals are priced differently because they are different products wearing the same name.
Check out the Cyber Risk Management Model that examiners reference below
Four things move the number, and you can read any proposal through them.
Scope: how many systems. An assessment covering 20 systems costs less than one covering 60. Watch this one closely, because scope is where budget negotiations quietly hollow out an assessment. Cutting from 60 systems to 40 saves money, and it might be fine. But the decision should be made on criticality, meaning which systems hold member data or move money, not on which count makes the proposal fit the budget. A risk assessment that skips the systems where the risk lives is a receipt, not an assessment.
Method: interviews or evidence. The cheapest assessments are interview-only. Someone asks your team questions, writes down the answers, and scores the risk. The problem is not that your team lies. The problem is that self-reported control performance is untested, and examiners and boards both know it. Assessments cost more when the answers get validated against control testing, audit evidence, or compliance data. That validation is most of the difference between a number you can defend and a number you hope nobody questions.
Output: colors or dollars. Most assessments at every price point still deliver a heat map: high, medium, low, red, yellow, green. You already know how that lands in a board meeting. Someone asks what "high" costs the institution, and the room goes quiet. Quantified assessments model risk as expected annual loss in dollars, using breach data and simulation rather than adjectives. That takes more sophisticated machinery, and it is the single biggest driver of the difference in what the assessment is worth after it is delivered.
What happens after delivery. A PDF assessment starts aging the day you receive it. An assessment that lives in a platform keeps working: risks stay tagged to systems, updates roll in as controls change, and the same data feeds next year's assessment and this quarter's board report. Part of what you are pricing is whether you are buying a document or a capability.
Here is the pattern I have watched play out. A credit union takes the lower-priced, interview-based assessment. The work is professionally done and the binder looks fine. Then one of two people asks a question the binder cannot answer.
The first is the examiner, who increasingly wants risk assessments that reflect real threats and tested controls, not self-reported scores. An assessment that cannot show where its likelihood numbers came from turns into a finding, and remediating a finding costs far more than the difference between any two proposals on your desk.
The second is your own board, when you ask for budget. A heat map gives the board nothing to weigh your request against. A quantified assessment does the opposite: when you can say this control costs $50,000 and removes half a million dollars in expected annual loss, the approval conversation gets short. Our clients identify an average of $3 million in risk reduction in their first year, and that number is the real economics of this decision. Against decisions of that size, the few thousand dollars between proposals is a rounding error.
So here is my honest framing, the one I give prospects who tell me a competitor is cheaper. You will not get better, faster, and cheaper from anyone, including us. We are not the cheapest. What the extra money buys is an assessment that quantifies risk in dollars and holds up when the two people above start asking questions. If neither of those matters at your institution this year, the cheaper assessment might genuinely be the right buy, and I would rather tell you that here than have you find out the difference during an exam.
This is also why we built the platform the way we did. The Rivial platform runs the quantified model, tags every risk to a system during the assessment, and turns the result into a board report denominated in dollars, so the assessment you buy in the spring is still earning its cost in the winter budget meeting. Assessments that used to take 30 hours of meetings take a working session.
Check out the Cyber Risk Management Model that examiners reference below
Ask each vendor five questions and write the answers side by side.
The cheapest proposal that answers all five well is the one to take. Usually, the answers explain the price gap better than any sales pitch could.
The fastest way to know whether a quantified assessment is worth the difference is to see one run on your own systems. Our free cyber risk assessment covers five of your critical systems with the full dollar-denominated model, and we guarantee it will identify at least $100,000 in risk reduction or we assess a sixth system free. It takes about two hours of your team's time, the report is yours either way, and there is no sales call required.
Here are the key takeaways from this blog:
Check out the Cyber Risk Management Model that examiners reference below