Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

USE CASE · GROUP RISK

Steer group cyber risk like a P&L.

Entities, business units, countries: one consolidated risk picture along the structures you actually govern, with the autonomy each subsidiary needs and the visibility the group cannot do without.

Dimension maturity · group view Illustrative data
Organization Score Risk AnalysisThird partiesExceptionsBusiness ImpactRemediation
France 86 4.6 4.4 4.1 4.5 4.2
Germany 78 4.3 3.6 3.4 4.1 4.0
Retail BU 71 3.8 3.9 3.1 3.6 3.5
Industrial BU 64 3.4 3.2 2.6 3.3 2.8
North America 47 2.9 1.6 2.2 2.7 2.4
Group average · 3.83.33.13.63.4

Third-party maturity flagged on a recent acquisition: exactly what a group view is for.

THE SITUATION

Twelve local registers do not make a group view.

  1. Every entity keeps its own register

    Different scales, different methods, different tools. Consolidation means a quarterly spreadsheet merge that nobody fully trusts.

  2. The board asks for one number

    You have twelve methodologies. The answer changes with whoever compiled it, and the meeting debates the figure instead of the risk.

  3. Acceptance without a chain

    Local risks get accepted locally, silently. Nobody can show who had the authority to accept what, or when that acceptance expires.

  4. Autonomy versus visibility

    Subsidiaries want to run their own program. The group needs to see across all of them. Most tooling forces you to pick one.

CAPABILITIES

One method. Every entity. Roll-up and drill-down.

  1. Model the group as it is

    Entities, business units and geographies are first-class objects in a hierarchy, with access scoped by role: an entity works its perimeter, the group sees across.

  2. A consolidated risk picture

    The group view rolls cyber posture up across entities and drills down to the risks behind it, with equal or weighted aggregation, stated on the dashboard.

  3. Scores that compare

    EBIOS RM, ISO/IEC 27005 and NIST in the same register: scenarios, scores and treatment plans expressed the same way in every entity.

  4. Appetite and KRIs where risk lives

    Risk appetite statements and KRIs are set per entity, and threshold breaches surface as they happen, at entity and group level.

  5. Acceptance with an authority ladder

    Risk acceptance follows an explicit approval ladder: the higher the residual risk, the higher it escalates in the organization. Owned, justified, time-bound.

  6. Board-ready in one export

    Board packs in PDF or PowerPoint, generated from the live register: the figures on the slide are the figures in the platform.

ROLL-UP, VERIFIED

A group view you can drill into is a group view you can trust.

Consolidation that ends in a static slide dies in the meeting. Every consolidated figure in Mindlapse opens onto the entities, risks and evidence behind it, so the discussion moves from “where does this number come from?” to “what do we decide?”.

  1. 01

    Model the group

    Load your organization: entities, business units, countries, roles and scopes. The structure you govern becomes the structure of the platform.

  2. 02

    Align the method

    One register, shared scales, appetite and KRIs per entity. Each subsidiary keeps its program; the group gains comparability.

  3. 03

    Steer and decide

    Consolidated posture, breach alerts, acceptance ladders and board packs: risk decisions with a paper trail.

FAQ

Group risk, in practice

Can subsidiaries keep their autonomy?

Yes. Access is scoped by organization: an entity manages its own risks, appetite and acceptances inside its perimeter, while group roles see across entities. Autonomy is a permission model, not a promise.

What if entities use different methods today?

The register carries EBIOS RM, ISO/IEC 27005 and NIST analyses side by side. Entities converge on shared scales without abandoning how they work: comparability comes from the model, not from imposing one method overnight.

How does consolidated reporting work?

The group view aggregates residual exposure across entities, with equal or weighted aggregation, and every figure drills down to the underlying risks. Board packs export the same data to PDF or PowerPoint.

Who can accept a risk?

An acceptance ladder you configure: by residual level, approval escalates through the hierarchy, up to group level when the exposure warrants it. Every acceptance is owned, justified and expires.

GROUP VIEW, VERIFIED

Bring your org chart. Leave with a consolidation model.

A live session on your structure: entities, scopes, roll-up and the board view.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.