MODULE · RISK INTELLIGENCE
From project to governed risk, one lifecycle.
Risk Intelligence covers the whole lifecycle: security requirements attached to a project the day it starts, the feared events and business impact that frame the analysis, scoring in inherent, residual and target, and the appetite your board approves, with incidents and policies to answer for it. Ernest proposes; your team decides.
Every risk carries all three score sets: the distance from residual to target is the treatment commitment, on the matrix you govern.
WHAT YOU DO WITH IT
Eight surfaces, one lifecycle.
Open one. The scene beside it shows what changes in the module.
01 Attach security to the project, not to its delivery
Every initiative, a project, a tender, a new application, declares itself once in business words. Criticality and exposure decide the path: an AI-assisted fast track for the standard ones, an analyst-led review for the critical ones. A human validates on both.
- An initiative declared once, in business words
- A path proportionate to risk: assisted fast track or analyst review
- Exceptions that carry an expiry date
02 Name what you fear, once and for all
The catalogue of your organization’s feared events: what must not happen, written from the business side, reusable in every analysis instead of being reinvented in each workshop.
- A catalogue of feared events specific to your organization
- Risk sources and consequences tied to every event
- Reusable from one analysis to the next, instead of rewritten
03 Give the analysis its impact scale
The BIA says what an interruption does to the business: loss horizons, recovery objectives and minimum resources per critical activity, rolled up from the activity to the function. Analyses read that scale instead of estimating it each time.
- Loss horizons and recovery objectives per critical activity
- The minimum resources that keep the activity running
- An impact scale your analyses read directly
04 Run the workshops with the method you practice
EBIOS Risk Manager in five guided workshops (framing and feared events, risk sources, strategic scenarios, operational scenarios, risk treatment), ISO/IEC 27005, or the NIST baseline. Scales and matrices are configurable per organization, with inheritance.
- EBIOS RM in five guided workshops, end to end
- Strategic and operational scenarios, as a bowtie (ISO 31010)
- MITRE ATT&CK attribution, weighted by analyst confidence
05 Score three ways, and keep the register alive
Inherent, residual and target each carry a full score set, and the gap from residual to target is the treatment commitment. Every risk carries an owner, a review cadence and a next-review date; overdue reviews surface on their own.
- Inherent, residual and target on one record
- An owner and a review cadence on every risk
- Links to suppliers, controls, incidents and the value chain
06 Govern appetite, and know the day it is breached
Appetite statements carry an approval, an expiry and breach alerts. Key risk indicators read against those thresholds, and a breach opens the acceptance request, escalated to the authority the residual band requires.
- An appetite approved, dated, with breach alerts
- KRIs with green, amber and red thresholds, read against appetite
- An authority ladder by residual band, time-bound
07 Qualify the incident against the criteria, not under pressure
An incident is recorded and qualified once, against the criteria of each applicable regime. The cascade assesses, prepares the notification file and logs it; your entity remains the one that files it. GRC scope: the governance of the incident, not the technical response.
- One qualification, read by every applicable regime
- The notification file prepared, your entity still files it
- The incident tied to the risk, supplier and control it touches
08 Keep the policies that frame the posture alive
Draft, approve and publish policies, then have them attested by the people they bind. Every version is dated, and the attestation says who read what, and when.
- Drafting, approval and publication, versioned
- An attestation by the people the policy binds
- The cyber-risk policy the management body adopts
PROPOSED, NOT IMPOSED
Ernest proposes. Your team decides. The register remembers.
Ernest drafts likelihoods with weighted factors, full scenarios with their attack chain, treatment strategies with estimated residual, and even the acceptance rationale. Every suggestion carries a confidence score and an explicit accept-or-reject that is recorded: each risk keeps its provenance, human, AI-suggested or hybrid.
- 01
Design
The initiative declares itself, its criticality decides the path, and security requirements ship with the project instead of chasing it.
- 02
Analyze and score
Feared events, business impact, EBIOS RM workshops: the scenario becomes a risk scored inherent, residual and target, with its treatment plan. Ernest proposes; analysts accept or reject.
- 03
Govern
Appetite, KRIs and acceptances hold the posture; incidents and policies document it when someone asks for an account. Board packs export straight from the live register.
UNDER THE HOOD
Where the register connects.
Board-Ready Reporting
Where posture, appetite trends and the committee view surface for the executive.
Learn more
GRCOps
Where the register’s actions and exceptions get worked: owned, dated, driven to verified closure, derogations included.
Learn more
Ernest - AI engine
The governed engine behind every suggestion: confidence scores, human final word, full audit trail.
Learn more
FAQ
Risk Intelligence, in practice
Which methodologies does it support?
Three ship ready to use: NIST 5×5 as a baseline, ISO/IEC 27005, and EBIOS Risk Manager as five guided workshops (framing and feared events, risk sources, strategic scenarios, operational scenarios, treatment). Scales and matrices are configurable per organization, with inheritance.
What do inherent, residual and target mean?
Inherent is the worst case before any control; residual is your current exposure after controls; target is the tolerance ceiling the team commits to. Each carries its own full score set, and the treatment strategy (avoid, mitigate, transfer or accept) is what moves residual toward target.
Are cyber incidents a SOC feature?
No. The scope is GRC, not SecOps: Mindlapse does not detect the attack and does not drive the technical remediation. It records the incident, qualifies it once against the criteria of each applicable regime, prepares the notification file, and ties it to the risk, the supplier and the control it touches. Your entity remains the one that files.
What exactly does Security by Design do?
Every initiative declares itself once in business words; its criticality and exposure decide the path, an AI-assisted fast track or an analyst-led review, with a human validating on both. Security requirements are attached to the project, and exceptions carry an expiry date. The product has no CI/CD integration and no code scanning: nothing runs in your pipeline.
RISK, GOVERNED
Bring a project that is starting. Leave with its risk scored.
Thirty minutes on a case of yours: the Security by Design path, the analysis, the scoring and the appetite beside it.