CAPABILITY · BUSINESS CENTRIC
Cyber risk, measured where the business makes money.
Model your value chains, from primary functions to the activities that carry them, and attach risk where it means something: to business activities with an owner and a criticality. Not to a list of servers.
7 functions 26 activities 21 risk links 8 incident links 6 supplier links 7 critical
Operations
3 risks · 1 incident
2 risks
Outbound
2 risks · 2 suppliers
1 risk · 1 supplier
Marketing & Sales
4 risks · 1 supplier
1 risk
Customer Service
2 risks · 1 incident
1 risk
Each activity carries its criticality and its risk links: exposure reads in business activities, not in CVEs.
THE SITUATION
Your register speaks CVE. Your board speaks revenue.
Hover a finding: the chain shows the activity it threatens. That is the whole translation.
What the register says
What the board hears
- Critical
E-Commerce Platform
Marketing & Sales
2 risks · 1 supplier
- Critical
Cold Chain Monitoring
Operations
3 risks · 1 incident
- Critical
Identity & Access
Support function
4 risks · 6 activities depend on it
- Medium
AI Chatbot
Customer Service
1 risk
WHAT YOU DO WITH IT
Six things you actually do with the value chain.
Open one. The scene beside it shows what changes on the chain.
01 Model the chain
Primary and support functions broken into activities, Porter style, each with an owner, a criticality level and an estimated financial impact.
- Functions and activities in business language
- An owner and a criticality on every activity
- Support functions under the whole chain
02 Attach risk where it lands
Risks, incidents, suppliers and test engagements link to the activities they threaten, so exposure aggregates by what the business does, not by hostname.
- Risks, incidents, suppliers and TLPT on the activity
- Exposure rolls up from activity to function
- A finding traces to the value it threatens
03 Run the impact analysis
BIA on the critical activities: loss horizons, recovery objectives, minimum resources, rolled up from the activity to the function.
- Loss horizons and recovery objectives per activity
- Minimum resources to restart
- Consolidated at function level
04 Read the chain three ways
A board view by function, a dependency map, and a risk heatmap: the same model read as planning, architecture or exposure.
- Board view: functions and their activities
- Dependency map: what breaks what
- Heatmap: where exposure concentrates
05 See suppliers in the chain
Third parties appear on the activities they operate or host, and concentration becomes visible exactly where it would hurt.
- Each supplier on the activities it runs
- Concentration flagged on the chain
- Straight into third-party risk management
06 Report in business terms
Criticality per activity, exposure by function, and the security conversation anchored to the value the company defends.
- Exposure by function, risks one click behind
- Criticality the business owns
- The board pack starts from value at stake
BUSINESS FIRST
From technical findings to business exposure.
The value chain is the translation layer: technical risk goes in, business exposure comes out. When a finding lands, you see the activity it threatens, the value that activity carries and what depends on it, and the discussion starts where it should: what does the business stand to lose?
- 01
Map the chain
Functions and activities, primary and support: the business as it creates value, described in business language.
- 02
Attach the context
Criticality, financial impact, BIA, suppliers, risks and incidents land on the activities they concern.
- 03
Read and decide
Exposure by activity and by function: prioritize, invest and report in the terms the board already uses.
UNDER THE HOOD
Where the chain lives.
Board-Ready Reporting
The command view where the value chain sits, next to the organization map and the Control Atlas.
Learn more
Risk Intelligence
The register, analyses and KRIs that feed the chain with risk.
Learn more
Third-Party Risk Management
The suppliers that operate and host your activities.
Learn more
FAQ
The value chain, in practice
Who maintains the value chain?
The business, in business language: functions and activities, not systems. Security enriches it with risk, incident and supplier links; activity owners keep criticality current.
Is this a CMDB?
No, deliberately. The chain models macro activities and the systems that serve them, not instances, hostnames or versions. It answers “what does the business lose?”, not “which server is this?”.
How does this change board reporting?
Exposure reads by activity and by function, with the risks behind each one a click away. The security conversation starts from the value at stake, which is the starting point boards accept.
GLOSSARY
Terms to know
VALUE, DEFENDED
Bring one business line. Watch its chain light up.
A live session: functions, activities, impacts and the risks that land on them.