Cyber Risk GRC
Cyber risk connected to threats, vulnerabilities, and controls
A cyber risk carries the threat actors and vulnerabilities behind it, the assets exposed, and the controls that reduce it, with effectiveness scored separately for design, operation, and implementation.
- Threats classified by actor type, sophistication, intent, and source confidence
- Vulnerabilities with severity, discovery source, and SLA buckets
- Security event ingestion with tokens, import jobs, and automation rules
- Control effectiveness scored across three dimensions, not one
- Threat
Organised crime group
- Sophistication: high
- Intent: financial
- Confidence: corroborated
exploits - Vulnerability
Unpatched edge appliance
- Severity: critical
- Found by: external scan
- SLA bucket: 7 days
affects - Exposure
3 asset instances
- Internet-facing
- Confidentiality: high
- Owner: Network Ops
Control effectiveness is scored separately for design, operation, and implementation, so a well-designed control that is not operating does not quietly reduce the score.
Threat and vulnerability
The reasoning behind the score is on the record
Risks link to the threats and vulnerabilities that justify them, and vulnerabilities link to the specific asset instances affected.
- Threat actor type, sophistication level, intent, and source confidence
- Vulnerability severity, discovery source, remediation status, SLA bucket
- Vulnerability-to-asset-instance links for exposure analysis
- Typed risk-to-threat and risk-to-vulnerability relationships
Control
Privileged access is reviewed each quarter by the system owner
PPTDF applicability
One owner · one procedure · one evidence trail
Automation
Events in, risk signals out
Security events arrive through scoped ingestion tokens and import jobs. Automation and trigger rules turn qualifying events into risk activity, with every execution logged.
- Scoped ingestion tokens per source, with import job status
- Automation rules and risk trigger rules with recorded executions
- Cyber taxonomy packs and tenant scoring schemes
- Remediation SLAs applied to cyber treatment actions
Privileged accounts without review
KRI · monthly · owner: Security Operations
Framework alignment
Works with your control frameworks
This module shares the platform control library. Map national frameworks and global standards alongside jurisdiction-specific authorities.
Solutions by role
Built for your team
See cyber risk in your environment
A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.