Aranisdocs
aranis.ai
Docs/Cyber Risk/Cyber risk matrix

Cyber risk matrix

How to read the matrix, what each state means, and why it uses the same size configured platform-wide.

Updated on August 17, 2026

What the matrix shows

The matrix positions each asset at the crossing of computed likelihood and impact inherited from the BIA. It is the portfolio view of Cyber Risk: instead of walking asset by asset, you see where the mass of exposure sits.

The size is your organization's

The grid uses the same size configured for the organizational register — 3×3, 4×4, or 5×5. This is not a layout detail: when a register pinned its own grid, a risk plotted at a level the organization's grid does not draw simply vanished from the screen, with no empty state admitting the absence.

Axis labels are ranges, not points, and the last band is open at the top for the same reason as in the organizational register: printing a single number there would assert a ceiling the configuration never declared.

States that are not a position

Not every asset occupies a cell. An asset with no mapped threat shows as uncalculated — and is rendered worse than the floor, sorting above it, so that examining an asset is never what worsens its relative position.

An asset with no chain to a BIA-assessed object produces no row at all, and so lives in a separate list on the same screen, with the missing link named. That list's count sits next to the matrix on purpose: it is the only way for the screen not to claim coverage it does not have.

When it is recalculated

The matrix is materialized by a periodic job, not recomputed on every screen load. The list of assets outside it, by contrast, is derived at read time — because the chain to the BIA changes when someone links a process to a product, with nothing notifying the matrix.