Aranisdocs
aranis.ai

Assets

What to register as an asset, what exposure means in the calculation, and why the chain to the BIA matters.

Updated on August 18, 2026

What counts as an asset here

An asset is whatever sustains the operation and can be attacked: systems, databases, services, infrastructure. It is the unit of Cyber Risk — each asset becomes a matrix row — and it is also where cyber risk meets the rest of the platform.

Exposure

Each asset declares whether it is exposed or internal, and that enters the calculation as a multiplier: exposed is 1.0, internal is 0.7. It is not an arbitrary discount — it recognizes that the same vulnerability reachable from the internet and reachable only from inside are not the same risk, without going so far as to treat the internal asset as safe.

The chain to impact

An asset's impact is not entered on the asset: it is inherited. The asset sustains business processes, processes sustain products and services, and it is the product whose impact is measured in the BIA. The asset receives the worst case along that chain.

The practical consequence is direct: an asset linked to no process, or whose process never reaches an assessed product, has no known impact — and therefore produces no matrix row. It appears in the list of assets outside the matrix, with the missing link named, so the gap is addressable instead of invisible.

Owner

The asset belongs to an area, and that is what makes cyber risk show up in the per-area view. An asset with no area is still calculated, but disappears from the organizational view — the risk exists and nobody is named for it.