Skip to content
FortaRisks
All pillars

Five pillars, one risk score

One understandable risk score across 9 IT risk domains and 51 categories. The engine correlates posture, threats, exposure and third-party risk automatically, with inherent and residual scoring, a living risk register and board-ready reporting, in math you can trace and customize.

5

Pillars correlated

30 sec

Board briefing

30/60/90

Day trajectory

A black box does not hold up in front of a CFO.

If you cannot show how a risk score was built, you cannot defend the budget that depends on it.

Value you can see

Outcomes your team will feel.

  • 2,000 alerts to 5 actions

    One ranked Action Feed across five pillars.

  • 30-second board briefing

    Walk into the committee with the answer ready.

  • No black box

    Every score decomposable and traceable.

Key capabilities

  • Posture across 9 IT risk domains, 51 categories

    A structured, understandable taxonomy of your IT risk, not a black box: 9 domains broken into 51 categories you can read, defend and act on.

  • Automatic assessment, integration and evidence

    Signals from all five pillars are pulled in and scored automatically, with evidence collected per control, no manual re-entry or spreadsheet wrangling.

  • Living risk register

    Every risk is identified, owned and treated (accept, mitigate, transfer or avoid) and tracked to closure, not buried in a static report.

  • Inherent and residual scoring

    Assign controls to each risk to compute both inherent and residual scores, and see exactly what your controls buy you.

  • Transparent, decomposable calculations

    Every score breaks down to its inputs and the exact math (CVSS, EPSS, KEV, exposure, sector targeting, control coverage, asset criticality), defendable line by line to a CFO.

  • Fully customizable to your business

    Tailor domains, categories, weights, thresholds and board-ready reports to your organization's specific needs. The engine adapts to you, not the other way around.

One Action Feed across all five pillars.

The engine merges every pillar into a single ranked Action Feed, so your team always knows the next move.

Three moments. Three different uses of the engine.

  • Case 1

    The CISO's morning (8:00 AM)

    You arrive at the office. You open the Action Feed. You see 7 prioritized actions for today. First one: "Patch CVE-2025-XXXX on frontend-prod-01.acme.ca. Actor: BlackBasta targeting your sector. Estimated effort: 3 hours. Risk reduction: 12 points." You assign to your team. You move to the second one. In 15 minutes, your day is framed.

  • Case 2

    The day before the board (monthly meeting)

    You ask the copilot: "Generate this month's board briefing." The copilot produces an 8-page PDF in 30 seconds: global risk score decomposed per pillar, 90-day trajectory, top 5 executed actions, top 3 upcoming, estimated avoided cost. Each figure sourced in the platform. You arrive at the board with a document you can defend line by line.

  • Case 3

    Threat pivot (CISA alert overnight)

    CISA publishes a new KEV at 2:00 AM. At 2:15, the AI Risk Engine automatically recalculates scores for affected assets. At 2:20, your Slack webhook receives the alert with the list of vulnerable assets, their exposure, their owners. At 8:00 AM when you arrive, the day's Action Feed already integrates the new priority. You didn't wait for the weekly report.

What's included

Inputs

  • Posture & compliance
  • Threat intelligence
  • Attack surface
  • Third-party risk
  • CVSS, EPSS, CISA KEV, MITRE ATT&CK

Outputs

  • Decomposable risk score
  • 8-page board briefing in 30 seconds
  • 30 / 60 / 90 day trajectory
  • 5-level relationship graph

The AI Risk Engine is useless without the other 4 pillars.

That's what differentiates it from a standalone scoring engine. Prioritization quality depends directly on the quality, freshness, and correlation of feeding signals. Here's what each pillar brings to the engine.

  • CTI → AI Risk Engine

    The engine receives the 30M+ signals/day, the 1,500+ tracked actors, the enriched CVEs (CVSS + EPSS + KEV). Without this signal, the AI doesn't know if a CVE is being actively exploited. It would treat an unexploited CVSS 9.8 as a CVSS 6.5 in CISA KEV.

  • EASM → AI Risk Engine

    The engine receives the 100+ finding types, the OT/ICS scanner, the external exposure mapping. Without this signal, the AI doesn't know if the vulnerable asset is exposed on the Internet. It can't distinguish a theoretical risk from a tomorrow-morning exploitable risk.

  • TPRM → AI Risk Engine

    The engine receives the continuous score of each critical third party, their drift, their alerts. Without this signal, the AI only sees your direct assets. It misses the 30-60% of cyber risk that comes through your supply chain.

  • Posture → AI Risk Engine

    The engine receives the CMM maturity of each control, alignment to 30 frameworks, coverage per asset category. Without this signal, the AI doesn't know if the asset is defended. It would prioritize a critical CVE on an already well-protected asset at the bottom of the list.

See your real risk in a 30-minute demo.

A member of our team walks you through FortaRisks on threats relevant to your sector. No chatbot.

Frequently asked questions

How does the engine correlate the five pillars?

Each pillar produces structured signals, ingested into a five-level relationship graph: asset to exposed service to vulnerability to available exploit to active threat actor. Each score combines CVSS, EPSS, KEV, real exposure and sector targeting, and is fully decomposable.

Is the scoring methodology a black box?

No. Every factor is documented, the per-pillar weights are configurable, and each calculation is exportable with its full breakdown.

What AI model powers the copilot?

The conversational copilot uses a leading LLM for understanding, with retrieval over your risk graph. The model never sees your raw data, only structured query results, and your data stays in Canada.

How often is the score recalculated?

Incrementally on each incoming event, with a daily global recompute. Critical alerts like CISA KEV trigger an immediate recompute notified within 15 minutes.