Strategy & Objectives
A strategy is a governed record, not a slide deck
It carries its themes, objectives and expected outcomes, and every objective knows which initiatives deliver it, which metrics measure it, which risks threaten it, and whether anything is delivering it at all.
- Typed strategies with planning horizon, review cadence and version history
- Weighted objective tree with success criteria, baseline and target
- Governance rules per strategy type decide what may change after publication
- Coverage and orphan views: objectives nothing delivers, initiatives serving nothing
In the application · Govern
- Strategies & themes
- Objectives
- Outcomes
- Coverage & orphans
- Risk links
- Executive
- StrategyTechnology & cyber resiliencev3 · published
- ObjectiveResidual cyber risk within appetiteweight 10% · 2 risks
- InitiativeCyber defence modernisationfunded · on track
- ProjectPAM completionmilestone 31 Oct
- TaskMigrate service accountsdue Friday
- PersonSarah Whitfieldassignee
Strategies and themes
Versions supersede; they never overwrite
A new version of a strategy supersedes the old rather than replacing it, so what the board approved last year is still readable. Themes group objectives under one narrative, and the draft → review → published lifecycle is enforced by the workflow engine.
- Draft → review → published lifecycle with role-gated transitions
- Governance rules per strategy type
- Themes group objectives under one narrative
- Objectives linked to the capabilities and processes they depend on
Treatment decision
- 1Treatment planActions with owners, priority, and due dates
- 2Action trackingStatus per action, SLA where defined
- 3ReassessmentResidual score recalculated after closure
Objectives and outcomes
Realisation is read from measurements, not typed in
Each expected outcome is tied to a live metric with baseline, target and actual, so progress on an objective is computed from readings. Risks link to objectives with a role and a materiality weight, so exposure is computed from the links too.
- Baseline, target and actual per outcome
- Risks linked as primary threat, contributing factor or knock-on impact
- Inherent and residual scores against appetite, per objective
- KRI, KPI and KCI metrics with owner, source and frequency
Privileged accounts without review
KRI · monthly · owner: Security Operations
Coverage and orphans
Is anything actually delivering this?
One snapshot per strategy and objective shows what has an initiative, a metric, funding and a benefit, and what has nothing. Orphan checks list objectives nothing delivers, risks no control mitigates and controls mitigating no risk, refreshed on demand.
- Coverage per objective, per strategy and per entity
- Orphan initiatives flagged for a decision
- Every card opens to its rows; same figures in the dashboard and the report
- Group roll-up across every entity in the tenant
- InitiativeCyber defence modernisation58%
- ProgramIdentity, PAM & SOC automation64%
- ProjectPAM completion & secrets migration71%
- TaskMigrate service accounts100%
- TaskVault break-glass procedure40%
- ProjectSOC runbook automation—
Computed from tasks and milestones. Unknown until something earns a colour; manual override only with a recorded reason.
Framework alignment
Works with your control frameworks
This module shares the platform control library. International standards, sector regulations and your own internal standard are loaded the same way and mapped to one another, wherever you operate.
See strategy and objectives in your environment
A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.