Cyber risk approaches lean on generic scenarios and a generic view of your business. Cordaata runs deeper, at scale.
What goes in
Home-grown vs commercial
System to system dependencies
Safeguard coverage
+more
Downtime tolerance
Revenue-generating status
Regulatory obligations
+more
Business criticality
Revenue contribution
Ownership of processes & services
+more
A sample of what goes in
Exposure purpose and access context
Sensitivity: volume, scope, transformation, freshness
Data classification
+more
Implementation maturity
Coverage per system
Control type: policy, settings, tools, process
+more
External vs internal designation
Disruption impact
Dependency strength on information systems
+more
+ More entity types, inputs, and relationships
Downtime tolerance
Revenue-generating status
Regulatory obligations
+more
Home-grown vs commercial
System to system dependencies
Safeguard coverage
+more
Exposure purpose and access context
Sensitivity: volume, scope, transformation, freshness
Data classification
+more
Implementation maturity
Coverage per system
Control type: policy, settings, tools, process
+more
External vs internal designation
Disruption impact
Dependency strength on information systems
+more
Business criticality
Revenue contribution
Ownership of processes & services
+more
Cordaata captures data points across every business process, system, data asset, service, and dependency in your organisation.
What the model does with it
Financial. Operational. Reputational. Regulatory. IP and Data. Each entity is profiled across each dimension. We call it FORRI.
For each system, the most relevant risk scenarios are identified. Not generic. Specific to how the system is used, what it depends on, and what it holds.
Each scenario is run through a structured quantification engine, calibrated against published, sector-specific incident data. Thousands of calculations. Varying inputs. A probability distribution of outcomes for each scenario.
Each control is assessed for maturity and effectiveness. Individually and in combination. Risk reduction is calibrated to a specific threat type.
Per-system risk is combined across the organisation using a methodology to avoid risk aggregation issues. The result is a defensible organisation-level risk picture.
What comes out