Risk & Resilience

Turn operational evidence into governed risk decisions.

Connect advisory findings, accountable review, shared remediation, validation, and residual-risk outcomes—with control lineage and customer-approved appetite attached.

Portfolio decisions

See which risks need ownership, review, evidence, or action.

The dashboard brings portfolio priorities and lifecycle state together without turning advisory scores into automatic acceptance decisions.

  • Draft, review, approved, awaiting-validation, and residual-risk states
  • Top risks, accountable owners, due remediation, and expiring decisions
  • Clear separation between current score, customer appetite, and human approval
  • Drill-through to the evidence and work supporting each portfolio signal

Governed risk lifecycle

Keep the human decision and its evidence together.

A risk can begin with high-confidence operational evidence, but it becomes authoritative only through governed review.

01EvidenceFinding, hunt, detection, exposure
02ReviewScope, owner, likelihood, impact
03TreatMitigate, avoid, transfer, accept
04ValidateImplementation and effectiveness
05DecideResidual risk and review date
Customer-approved appetite

Tenant policy defines appetite thresholds and their approval context. Threshold indicators support prioritization; they do not replace an accountable risk decision.

Risk Register

Move from advisory record to validated residual risk.

Governed intake preserves the source evidence and proposed treatment. Reviewers can approve the risk assessment and only the remediation actions that belong in the decision, then follow shared work through implementation and validation.

  • Source evidence, rationale, owner, affected scope, and scoring method
  • Selected treatment actions with individual lifecycle and evidence
  • Implementation, validation, and reassessment history
  • Time-bounded acceptance and residual-risk review where applicable

CREF-to-control lineage

Trace a candidate mitigation to the controls a customer uses.

Start with a MITRE CREF candidate mitigation and follow its lineage into NIST SP 800-53 Rev. 5. Selecting a NIST control reveals its statement and supplemental guidance where published; choose one relevant framework to inspect associated controls below the graph.

  • Focused CREF candidate → NIST control graph
  • Published control identifier, statement, and supplemental guidance when available
  • Framework selector integrated with graph controls
  • Associated framework controls shown on demand instead of crowding the graph

D3FEND resilience view

Relate defensive techniques to observed program evidence.

The D3FEND dashboard provides a defensive-technique lens alongside ATT&CK-oriented operations. Coverage views support investigation and prioritization; they remain tied to current evidence rather than implying that a mapped technique is implemented or effective.

  • D3FEND technique heatmap and drill-down
  • Evidence-aware differentiation between mapped, implemented, and validated state
  • Pivots into relevant detections, hunts, controls, remediation, and validation
  • Program gaps carried into governed work instead of treated as automatic findings

One resilience system

Bring threat, exposure, detection, and control evidence into the same decision.

TM

Threat Modeling

Move design threats, attack paths, assumptions, and remediations into reviewable risk context.

EX

Exposure

Connect evidence-backed external findings, asset importance, ownership, and retest results.

DE

Detection

Use exact-version validation, health, and gaps as evidence—not as automatic risk decisions.

OP

Operations

Carry hunts, cases, tasks, exceptions, and implementation evidence through accountable work.

Start with the workflow

See how your operational evidence becomes a governed risk decision.

Bring your current intelligence, exposure, telemetry, architecture, detection content, and analyst or service process. We will map the fastest path to a useful outcome.