Deeper than generic frameworks.
Practical at scale.

Cyber risk approaches lean on generic scenarios and a generic view of your business. Cordaata runs deeper, at scale.

What goes in

What Cordaata knows about your organisation before a single scenario is run.

Information
System

Home-grown vs commercial
System to system dependencies
Safeguard coverage
+more

Business
Process

Downtime tolerance
Revenue-generating status
Regulatory obligations
+more

Organisational
Unit

Business criticality
Revenue contribution
Ownership of processes & services
+more

A sample of what goes in: business process, information system, data asset, controls, customer-facing service, and organisational unit

A sample of what goes in

Data Asset

Exposure purpose and access context
Sensitivity: volume, scope, transformation, freshness
Data classification
+more

Controls

Implementation maturity
Coverage per system
Control type: policy, settings, tools, process
+more

Customer-Facing
Service

External vs internal designation
Disruption impact
Dependency strength on information systems
+more

+ More entity types, inputs, and relationships

  1. Business Process

    Downtime tolerance
    Revenue-generating status
    Regulatory obligations
    +more

  2. Information System

    Home-grown vs commercial
    System to system dependencies
    Safeguard coverage
    +more

  3. Data Asset

    Exposure purpose and access context
    Sensitivity: volume, scope, transformation, freshness
    Data classification
    +more

  4. Controls

    Implementation maturity
    Coverage per system
    Control type: policy, settings, tools, process
    +more

  5. Customer-Facing Service

    External vs internal designation
    Disruption impact
    Dependency strength on information systems
    +more

  6. Organisational Unit

    Business criticality
    Revenue contribution
    Ownership of processes & services
    +more

Cordaata captures data points across every business process, system, data asset, service, and dependency in your organisation.

What the model does with it

01

Impact profiling

Financial. Operational. Reputational. Regulatory. IP and Data. Each entity is profiled across each dimension. We call it FORRI.

02

Scenario identification

For each system, the most relevant risk scenarios are identified. Not generic. Specific to how the system is used, what it depends on, and what it holds.

03

Risk quantification

Each scenario is run through a structured quantification engine, calibrated against published, sector-specific incident data. Thousands of calculations. Varying inputs. A probability distribution of outcomes for each scenario.

04

Control adjustment

Each control is assessed for maturity and effectiveness. Individually and in combination. Risk reduction is calibrated to a specific threat type.

05

Aggregation

Per-system risk is combined across the organisation using a methodology to avoid risk aggregation issues. The result is a defensible organisation-level risk picture.

What comes out

Per scenario

  • Gross and net ALE
  • Loss exceedance curve
  • Breach cost breakdown by category
  • Threat type and threat actor
  • Full factor values

Per system

  • FORRI impact profile
  • Scenario list with headline ALE
  • System level total ALE
  • Position in the dependency graph

Per entity

  • Process risk analysis
  • Projection and partition views
  • Top contributing scenarios
  • Per system contribution breakdown

Organisation level

  • Annualised loss expectancy, gross and net
  • Top scenarios and systems by risk
  • Concentration by business process, service, and data asset
  • Threat type breakdown
  • Coverage and freshness

The methodology is one thing.
Seeing it work is another.

Book a Demo