Five pillars, one risk score
One understandable risk score across 9 IT risk domains and 51 categories. The engine correlates posture, threats, exposure and third-party risk automatically, with inherent and residual scoring, a living risk register and board-ready reporting, in math you can trace and customize.
5
Pillars correlated
30 sec
Board briefing
30/60/90
Day trajectory
A black box does not hold up in front of a CFO.
If you cannot show how a risk score was built, you cannot defend the budget that depends on it.
Outcomes your team will feel.
2,000 alerts to 5 actions
One ranked Action Feed across five pillars.
30-second board briefing
Walk into the committee with the answer ready.
No black box
Every score decomposable and traceable.
Key capabilities
Posture across 9 IT risk domains, 51 categories
A structured, understandable taxonomy of your IT risk, not a black box: 9 domains broken into 51 categories you can read, defend and act on.
Automatic assessment, integration and evidence
Signals from all five pillars are pulled in and scored automatically, with evidence collected per control, no manual re-entry or spreadsheet wrangling.
Living risk register
Every risk is identified, owned and treated (accept, mitigate, transfer or avoid) and tracked to closure, not buried in a static report.
Inherent and residual scoring
Assign controls to each risk to compute both inherent and residual scores, and see exactly what your controls buy you.
Transparent, decomposable calculations
Every score breaks down to its inputs and the exact math (CVSS, EPSS, KEV, exposure, sector targeting, control coverage, asset criticality), defendable line by line to a CFO.
Fully customizable to your business
Tailor domains, categories, weights, thresholds and board-ready reports to your organization's specific needs. The engine adapts to you, not the other way around.
One Action Feed across all five pillars.
The engine merges every pillar into a single ranked Action Feed, so your team always knows the next move.
Three moments. Three different uses of the engine.
- Case 1
The CISO's morning (8:00 AM)
You arrive at the office. You open the Action Feed. You see 7 prioritized actions for today. First one: "Patch CVE-2025-XXXX on frontend-prod-01.acme.ca. Actor: BlackBasta targeting your sector. Estimated effort: 3 hours. Risk reduction: 12 points." You assign to your team. You move to the second one. In 15 minutes, your day is framed.
- Case 2
The day before the board (monthly meeting)
You ask the copilot: "Generate this month's board briefing." The copilot produces an 8-page PDF in 30 seconds: global risk score decomposed per pillar, 90-day trajectory, top 5 executed actions, top 3 upcoming, estimated avoided cost. Each figure sourced in the platform. You arrive at the board with a document you can defend line by line.
- Case 3
Threat pivot (CISA alert overnight)
CISA publishes a new KEV at 2:00 AM. At 2:15, the AI Risk Engine automatically recalculates scores for affected assets. At 2:20, your Slack webhook receives the alert with the list of vulnerable assets, their exposure, their owners. At 8:00 AM when you arrive, the day's Action Feed already integrates the new priority. You didn't wait for the weekly report.
What's included
Inputs
- Posture & compliance
- Threat intelligence
- Attack surface
- Third-party risk
- CVSS, EPSS, CISA KEV, MITRE ATT&CK
Outputs
- Decomposable risk score
- 8-page board briefing in 30 seconds
- 30 / 60 / 90 day trajectory
- 5-level relationship graph
The AI Risk Engine is useless without the other 4 pillars.
That's what differentiates it from a standalone scoring engine. Prioritization quality depends directly on the quality, freshness, and correlation of feeding signals. Here's what each pillar brings to the engine.
CTI → AI Risk Engine
The engine receives the 30M+ signals/day, the 1,500+ tracked actors, the enriched CVEs (CVSS + EPSS + KEV). Without this signal, the AI doesn't know if a CVE is being actively exploited. It would treat an unexploited CVSS 9.8 as a CVSS 6.5 in CISA KEV.
EASM → AI Risk Engine
The engine receives the 100+ finding types, the OT/ICS scanner, the external exposure mapping. Without this signal, the AI doesn't know if the vulnerable asset is exposed on the Internet. It can't distinguish a theoretical risk from a tomorrow-morning exploitable risk.
TPRM → AI Risk Engine
The engine receives the continuous score of each critical third party, their drift, their alerts. Without this signal, the AI only sees your direct assets. It misses the 30-60% of cyber risk that comes through your supply chain.
Posture → AI Risk Engine
The engine receives the CMM maturity of each control, alignment to 30 frameworks, coverage per asset category. Without this signal, the AI doesn't know if the asset is defended. It would prioritize a critical CVE on an already well-protected asset at the bottom of the list.
Explore the other pillars.
See your real risk in a 30-minute demo.
A member of our team walks you through FortaRisks on threats relevant to your sector. No chatbot.
Frequently asked questions
How does the engine correlate the five pillars?
Each pillar produces structured signals, ingested into a five-level relationship graph: asset to exposed service to vulnerability to available exploit to active threat actor. Each score combines CVSS, EPSS, KEV, real exposure and sector targeting, and is fully decomposable.
Is the scoring methodology a black box?
No. Every factor is documented, the per-pillar weights are configurable, and each calculation is exportable with its full breakdown.
What AI model powers the copilot?
The conversational copilot uses a leading LLM for understanding, with retrieval over your risk graph. The model never sees your raw data, only structured query results, and your data stays in Canada.
How often is the score recalculated?
Incrementally on each incoming event, with a daily global recompute. Critical alerts like CISA KEV trigger an immediate recompute notified within 15 minutes.