Derive
Derive is a SaaS cybersecurity risk and operations platform that quantifies cyber risk in financial terms and ranks actions by loss-reduction-per-dollar. It serves organizations from startups to enterprises with an integrated Risk, Governance, and Operations platform powered by a 100,000+ incident benchmark dataset.
- Company typePrivate
- Founded2024
- HeadquartersRichmond, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Derive does
Derive is a SaaS cybersecurity risk and operations platform that quantifies cyber risk in financial terms and ranks operational actions by expected loss reduction per dollar. The platform is organized around three modules — Risk (quantification and forecasting), Governance (controls, ownership, and framework mapping), and Operations (workflows for user access reviews, third-party risk, AI risk, and incident response) — that share real-time data synchronization so completing or missing an operational task updates the financial risk picture automatically. Underpinning the system is Peer Risk Benchmarks, a proprietary dataset built from over 100,000 verified cyber incidents and continuously refreshed threat intelligence, combined with a patent-pending AI-driven risk modeling methodology (US 2024/0370569 A1).
The product is sold as a single annual subscription priced by company headcount across four tiers: Startup (under 250 employees) at $12,000/year, Growth (250–1,000) at $44,400/year, Professional (1,001–3,999) at $88,800/year, and Enterprise (4,000+) at $134,400/year, with all plans including unlimited seats and assessments. Distribution runs through a hybrid motion: enterprise field sales with demos, peer benchmarking, and custom SLAs for larger tiers, paired with a self-serve purchasing path and a free quantitative cyber risk assessment spreadsheet for smaller customers. Professional services add-ons (Risk Support and Operations Augmentation) provide expert-led assessments and embedded cyber operations staff on a flexible basis.
Derive is privately held, operating as Quant, LLC (a Virginia LLC, DBA Derive), headquartered in Richmond, VA, and led by co-founders Alex Nette (CEO, formerly CEO of Hive Systems), Corey Neskey (CTO), and Michael Cardman (CAO). The team size is reported as 1–10 employees, no institutional funding is disclosed, and the disclosed customer base is extremely thin (Aireon is the only named logo). The company received an Innovation in Cybersecurity award at rvatech/Gala in 2022 and was recognized in Forrester's Q2 2025 CRQ Report.
Derive firmographics
Firmographics- Name
- Derive
- Legal name
- Quant, LLC
- Website
- https://deriverisk.com
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Derive is a SaaS cybersecurity risk and operations platform that quantifies cyber risk in financial terms and ranks actions by loss-reduction-per-dollar. It serves organizations from startups to enterprises with an integrated Risk, Governance, and Operations platform powered by a 100,000+ incident benchmark dataset.
- Ownership category
- akta.pro rank
Derive industry classification
Industry- Product category
- Cybersecurity Risk Quantification (CRQ) / Cyber Risk Operations Software
- NAICS
- Software Publishers (5132)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Third-Party/Vendor Risk Management (TPRM/VRM) (HDADAIAE)
Keywords
Where Derive is headquartered
LocationHeadquarters
- HQ city
- Richmond
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Derive business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Platform Subscription: Annual SaaS subscription priced by company headcount (FTE). Four tiers: Startup (under 250 employees), Growth (250-1,000), Professional (1,001-3,999), and Enterprise (4,000+). All plans include full platform access with unlimited seats and assessments. Annual billing required.
- Professional Services Add-ons: Risk Support add-on provides expert-led risk assessments, control framework setup, ongoing program advisory, and board/executive reporting support. Operations Augmentation provides embedded cyber operations staff for TPRM, UAR, and IR execution on a flexible time-and-materials basis.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Startup: Under 250 employees - $1,000/mo or $12,000 billed annually |
| Subscription | Annual | Growth: 250-1,000 employees - $3,700/mo or $44,400 billed annually |
| Subscription | Annual | Professional: 1,001-3,999 employees - $7,400/mo or $88,800 billed annually |
| Subscription | Annual | Enterprise: 4,000+ employees - $11,200/mo or $134,400 billed annually |
| Other | Pay-as-you-go | Risk Support Add-on - Expert-led risk program building |
| Other | Pay-as-you-go | Operations Augmentation Add-on - Embedded cyber operations staff |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels8 records
Derive product offering
Product offeringCore offering
Derive sells a SaaS cybersecurity risk and operations platform that quantifies cyber risk in real financial terms and prioritizes remediation actions by greatest loss reduction per dollar. The platform combines three integrated modules — Risk (quantification and forecasting), Governance (control tracking), and Operations (prioritized workflows for UAR, TPRM, AI risk, IR) — all powered by the proprietary Peer Risk Benchmarks dataset of 100,000+ verified cyber incidents and a patent-pending AI risk methodology. Customers buy per-headcount annual subscriptions spanning four tiers (Startup, Growth, Professional, Enterprise) and may add Risk Support advisory or Operations Augmentation T&M services.
Product overview
Derive is a unified cybersecurity risk and operations SaaS platform structured around three integrated modules: the Risk Module (the core quantification and forecasting engine), the Governance Module (control tracking and accountability), and the Operations Module (prioritized workflows tied to measurable loss reduction). All three modules share data in real time and are powered by the proprietary Peer Risk Benchmarks dataset of over 100,000+ real-world cyber incidents. The platform is delivered as a single subscription with unlimited seats; no module-level upsells exist. Derive also offers a free Basic Quantitative Cyber Risk Assessment spreadsheet as a lead-in tool.
Differentiator
Problem solved
Functional benefit
Products and services
- Risk Module Core quantification and forecasting engine that models and forecasts cyber risk in real financial terms using Peer Risk Benchmarks. Includes a Risk Register, dynamic fan chart forecasting, and interactive data flow diagrams that translate complex cyber risk into measurable financial outcomes for CISOs and security teams.
- Governance Module Centralized controls tracking system that monitors control maturity, ownership, dependencies, and evidence in real time. Maps controls to frameworks including NIST, MITRE, ISO, DORA, NIS2, and SOC 2 and connects every control to financial risk and operational workflows.
- Operations Module Workflow management system for cybersecurity operations including user access reviews, third-party risk management (TPRM), AI risk assessments, incident response, and BC/DR planning. Tasks are ranked by expected loss reduction per dollar and feed back into Risk and Governance modules in real time.
- Peer Risk Benchmarks (PRB) Proprietary benchmark dataset of 100,000+ verified cyber incidents and loss data combined with continuously updated threat intelligence. Serves as the statistical foundation for all risk quantification, forecasting, and peer comparison within the Derive platform, allowing customers to compare modeled risk against industry peers in financial terms.
- Basic Quantitative Cyber Risk Assessment (Free Tool) Free spreadsheet-based version of Derive's risk modeling methodology that enables users to estimate potential cyber losses, assign probabilities, and generate an overall risk picture without committing to the full platform. Used as a product-led growth funnel entry point.
- Risk Support Add-on (Professional Services) Expert-led risk program building add-on offering risk assessments, control framework setup, ongoing program advisory, and board/executive reporting support. Priced as a pay-as-you-go add-on to any subscription tier.
- Operations Augmentation Add-on (Professional Services) Embedded cyber operations staff add-on providing TPRM, UAR, and incident response execution on a flexible time-and-materials engagement model that scales up or down with customer need. Priced as a pay-as-you-go add-on to any subscription tier.
Quantifiable outcome
- 28% cyber budget increase justified for 2025 risk reduction
- +1 more outcomes
Companies that use Derive
Customer profileNamed customers1 record
Segments4 records
Ideal customer profiles4 records
Derive technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability3 records
Feature5 records
Derive partnerships and signals
Strategic signalScale indicators3 records
Recent moves5 records
Expansion highlights5 records
Derive competitors and assessment
Company assessmentBroad incumbents
- ServiceNow GRC: ServiceNow's Integrated Risk Management / GRC suite offers governance, risk, and compliance workflows at large enterprises. It competes with Derive's Governance and Operations Modules from a broad platform incumbent position rather than as a CRQ specialist.
- SecurityScorecard: SecurityScorecard is an established cyber risk ratings and third-party risk management platform used widely across enterprises. It overlaps with Derive on peer benchmarking, third-party risk workflows, and board-level reporting, but as a broader incumbent rather than a CRQ specialist.
- Bitsight: Bitsight is a broader cyber risk management platform providing external attack-surface ratings, benchmarking, and now third-party risk and CRQ capabilities. It overlaps with Derive on peer benchmarking and risk quantification but at a much larger enterprise scale.
- RSA Archer: RSA Archer is a long-standing enterprise GRC and integrated risk management platform with controls and compliance workflows. It competes with Derive's Governance Module as part of a broader GRC incumbent suite.
- Tenable: Tenable is a major exposure-management and vulnerability-management platform with growing risk quantification capabilities (Tenable One). It competes broadly with Derive's prioritization and benchmarking use cases as part of a wider enterprise security portfolio.
Direct peers
- Axio: Axio is a cyber risk quantification platform that helps organizations quantify and manage cyber risk in financial terms, having acquired RiskLens to anchor its CRQ offering. It is the most direct competitor to Derive in the CRQ category with similar financial-quantification methodology and board-reporting positioning.
- Balbix: Balbix offers an AI-driven platform for cyber risk quantification and prioritization across an organization's attack surface. It overlaps directly with Derive's Risk Module on quantifying risk, prioritizing remediation, and benchmarking against industry peers.
- Safe Security (SAFE): SAFE Security provides a cyber risk quantification and management platform that scores and forecasts breach likelihood and financial impact using external telemetry and threat intelligence. It directly competes with Derive on real-time financial cyber-risk modeling and CISO-level reporting.
- Kovrr: Kovrr delivers a cyber risk quantification platform that models enterprise cyber exposure in financial terms using global incident data. It is a direct peer to Derive on financial cyber-risk modeling and supports CISOs and insurance underwriters.
Others
- Hive Systems: Hive Systems is a cybersecurity services and advisory firm whose former CEO (Alex Nette) now leads Derive. It is thematically adjacent — providing cyber-risk consulting that often overlaps with Derive's buyer use cases — though it does not sell a competing CRQ platform.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Derive social profiles
Digital presenceDerive financial estimates
Financial estimateRevenue estimate
Valuation estimate
Derive leadership team
Management profileNumber of profiles
Profiles3 records
Derive funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Derive M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Derive
What does Derive do?
Derive sells a SaaS cybersecurity risk and operations platform that quantifies cyber risk in real financial terms and prioritizes remediation actions by greatest loss reduction per dollar. The platform combines three integrated modules — Risk (quantification and forecasting), Governance (control tracking), and Operations (prioritized workflows for UAR, TPRM, AI risk, IR) — all powered by the proprietary Peer Risk Benchmarks dataset of 100,000+ verified cyber incidents and a patent-pending AI risk methodology. Customers buy per-headcount annual subscriptions spanning four tiers (Startup, Growth, Professional, Enterprise) and may add Risk Support advisory or Operations Augmentation T&M services.
Is Derive a public or private company?
Derive is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Derive founded?
Derive was founded in 2024. It employs 1 to 10 people.
Where is Derive based?
Derive is headquartered in Richmond, United States, in the North America region.
How does Derive make money?
Two revenue lines are on record. Platform Subscription is the primary driver. The others are professional Services Add-ons.
Who are Derive's main competitors?
Broad incumbents on record are ServiceNow GRC, SecurityScorecard, Bitsight, RSA Archer and Tenable. Direct peers are Axio, Balbix, Safe Security (SAFE) and Kovrr. Hive Systems is listed as an others.
Does Derive have an API?
No public API is recorded for Derive.
What industry is Derive in?
Derive's product category is Cybersecurity Risk Quantification (CRQ) / Cyber Risk Operations Software. Its primary akta.pro industry code is HDADAIAE, Third-Party/Vendor Risk Management (TPRM/VRM). Its NAICS code is 5132 and its SIC code is 7372.