Cyber Risk overview
Cyber risk per asset: the formula, where each input comes from, and why no cell is left blank.
The unit is the asset
Cyber Risk measures cyber exposure per asset. Each asset becomes a row in a matrix recalculated periodically. It complements the other domains rather than repeating them: supplier maturity comes from TPRM, impact comes from the BIA and is not redefined here, and the consolidated result rises into the corporate register as the CR child risk.
The formula
An asset's risk is the average of vulnerability and threat, multiplied by exposure and by impact.
Input | Where it comes from |
|---|---|
Vulnerability | The organization's own self-assessment |
Threat | p95 of the severity of threats mapped to the asset |
Exposure | Multiplier: exposed 1.0 · internal 0.7 |
Impact | From the BIA, along asset → process → product |
Why p95 and not an average
Threat severity for an asset is aggregated at the 95th percentile, not the mean. An average dilutes: five threats, four minor and one critical and open, would produce a calm number for an asset that has a severe problem. p95 preserves the tail, which is exactly where the risk lives.
Zero is not a valid result
The database holds known threats. The absence of a known open threat is not the absence of threat — so an asset whose threats have all been treated goes to a floor, never to zero and never to blank. The floor is the smallest step on the scale and is deliberately not configurable: a tunable floor would be a door back to zero, and would become the easy way to improve the number without treating the threat.
The floor applies to threat only. Impact has no floor, because an impact floor would assert that the asset harms the business by some amount — and that is something the model does not know: impact comes from the BIA, and an asset outside that chain has an impact nobody declared.
Assets that fall outside the matrix
An asset with no chain reaching a BIA object produces no matrix row — but it does not vanish either. It appears in its own list, on the same screen, with the missing link named: no process, no product, or no BIA. Trading a missing number for a silent omission would be worse than the original problem, so that list is neither optional nor tucked into a secondary tab.