Skip to content
FortaRisks
The whole platform

Forta Cockpit

Risk register, for decision-makers

The risk register that fills itself in

No questionnaire to get started: the register feeds continuously from the four detecting modules and from your integrations, across a taxonomy of 9 domains and 52 sub-domains. Every risk carries its inherent and residual level, and the residual is derived from controls instead of being typed in by hand.

Forta Cockpit

5

Modules correlated

30 sec

Board briefing

30/60/90

Day trajectory

A black box does not hold up in front of a CFO.

If you cannot show how a risk score was built, you cannot defend the budget that depends on it.

Value you can see

Outcomes your team will feel.

  • A methodical register that feeds itself

    Self-feeding tools do ratings or vulnerabilities without a methodological register; methodological registers stay manual. Here the two meet.

  • 30-second board briefing

    Walk into the committee with the answer ready.

  • No unknown coverage dressed up

    When coverage is unknown the register shows "—", never a zero. An unmeasured domain must not look like a risk-free one.

Key capabilities

  • Risk across 9 IT risk domains, 52 sub-domains

    A structured, understandable taxonomy of your IT risk, not a black box: 9 domains broken into 52 sub-domains you can read, defend and act on.

  • Fed by the modules and by your integrations

    Signals from the modules are pulled in and scored automatically, with evidence collected per control, no manual re-entry or spreadsheet wrangling. Integrations with your own environment open a second inlet: a Microsoft 365 tenant connected read-only reports its configuration and its alerts, and the matching risk is created in the register instead of waiting for the annual workshop.

  • A living register, never an annual document

    The calculation runs hourly, and re-runs on events: a validated remediation, a vendor score drop or a changed compliance evidence immediately re-scores the sub-domain concerned. An annual register is obsolete the day it is published; this one follows reality.

  • Inherent and residual, derived from controls

    Residual risk is never a manual entry: it comes down from the SCF control model, and when no control is recorded on a sub-domain, an implicit defence credit is derived from your posture maturity rather than leaving a hole. Treatment follows ISO 27005, accept, reduce, transfer or avoid, with a dated acceptance that reopens automatically when it expires.

  • Transparent, decomposable calculations

    Every score breaks down to its inputs and the exact math (CVSS, EPSS, KEV, exposure, sector targeting, control coverage, asset criticality), defendable line by line to a CFO.

  • Fully customizable to your business

    Tailor domains, categories, weights, thresholds and board-ready reports to your organization's specific needs. The engine adapts to you, not the other way around.

A degradation becomes an action, not one more row.

When a sub-domain's grade degrades, an "understand the degradation" action goes to Forta Actions with its context. Calibration by organization profile, five risk tolerance levels based on your size, sector and appetite, automatically adjusts perceived severity: the same raw risk does not weigh the same everywhere.

Risk taxonomy

Nine domains: IT risk in full, not just cyber.

A security tool grades what it can scan, so it stops at information security, one domain out of nine. The register works the other way round: the IT risk taxonomy first, the sensors second. The modules continuously fill what they can observe; the domains no scanner sees stay on the board, marked to assess, instead of disappearing from it.

  • Information security

    Identity and access, vulnerabilities and patching, detection and response, network, cloud and endpoints, cryptography, application security, security governance.

    Posture · EASM · CTI · Compliance
  • Operational resilience

    Service availability and performance, continuity and recovery, change management, capacity and obsolescence, incident handling.

    Posture · EASM
  • Third-party risk

    Pre-contract due diligence, contractual and SLA obligations, continuous monitoring, concentration and dependency across your supply chain.

    TPRM · CTI
  • Regulatory risk

    Inventory of applicable obligations, control effectiveness testing, audit findings and remediation, privacy and sovereignty.

    Compliance · Posture
  • Financial risk, IT view

    Budget variance, cloud and licence optimization, asset lifecycle and depreciation, return on investment.

    Assessed by your teams
  • Data & AI

    Data quality and integrity, governance and classification, ethical use and privacy, model reliability, shadow AI.

    Compliance · Posture
  • IT project risk

    Schedule performance, budget and resources, scope and benefits realization, governance and adoption of digital initiatives.

    Assessed by your teams
  • Talent & culture

    Team capacity and skills gaps, retention and succession, key-person dependency, engagement and security culture.

    Assessed by your teams
  • Physical security

    Access control and perimeter, surveillance, environmental and facility safety of your premises and technical rooms.

    Assessed by your teams

A domain with no sensor is still a visible domain.

None of these nine domains is hidden for lack of an automatic source. Until you have assessed it, it shows “to assess” and a low confidence badge, never a reassuring zero. That is what makes the register defendable to an auditor and to a board alike: what is not measured is visible, and can be planned.

Three examples, three situations

  • Example · Manufacturer

    The chair's question: where do we stand?

    Before the board meeting, you open Forta Cockpit: risks ranked by domain, what has gone down since last quarter, what remains open and why. Every figure points to its source.

  • Example · Multi-site company

    An acquisition joins the scope

    You add the domain names of an acquired company. The register updates as the modules observe the new scope: risks appear ranked by domain, without waiting for the annual review.

  • Example · Prime contractor

    Cyber insurance renewal

    Your insurer or your customer asks what has changed in a year. You export the trajectory: risks treated, actions closed and the evidence attached.

What's included

The register feeds itself

  • No questionnaire to fill in before you start
  • The register feeds from posture, compliance, threat, attack surface and third parties
  • Environment integrations: Microsoft 365, Entra ID, Defender
  • Nine IT risk domains, from cyber to financial, project and physical
  • Inherent and residual computed as probability × impact, not typed in
  • The residual comes down from your controls, never from an opinion
  • A sub-domain with no control on file inherits your posture maturity instead of a hole
  • Recalculated hourly, and immediately whenever a signal changes
  • ISO 27005 treatment: accept, reduce, transfer, avoid
  • Dated acceptance that reopens on its own at expiry
  • EBIOS RM workshops pre-filled from your data
  • Scenarios structured on the FAIR taxonomy for cyber risk

Decisions you can defend to a board

  • An A+ to F grade per sub-domain, per domain and for the organization
  • Every score breaks down to its inputs, line by line
  • Confidence badge showing how much was actually assessed
  • “—” when coverage is unknown, never a reassuring zero
  • 5×5 matrix to arbitrate in committee
  • 30, 60 and 90 day trajectory
  • Board briefing in 30 seconds, every figure sourced in the platform
  • Five tolerance levels calibrated to your size, sector and geography
  • Five-level relationship graph, from asset to active threat actor
  • A degradation leaves as an action in Forta Actions, with its context
  • Domains, categories, weightings and thresholds adjustable to your organization

On the roadmap

  • Cyber risk quantification (CRQ)

Optional AI enrichment

AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.

In the risk register, AI targets the narrative: explaining a score movement, drafting the trend commentary, preparing the board update. The inherent and residual risk calculation stays an explicit model, decomposable and exportable, never a model output.

Sovereignty: the platform is built and hosted in Canada, by a Canadian company. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.

Forta Cockpit feeds on the four detecting modules.

That's what differentiates it from a standalone scoring engine. Prioritization quality depends directly on the quality, freshness, and correlation of feeding signals. Here's what each pillar brings to the engine.

  • Forta Radar → Forta Cockpit

    The engine receives the 50M+ signals/day, the 2,000+ tracked actors, the enriched CVEs (CVSS + EPSS + KEV). Without this signal, the AI doesn't know if a CVE is being actively exploited. It would treat an unexploited CVSS 9.8 as a CVSS 6.5 in CISA KEV.

  • Forta Exposure → Forta Cockpit

    The engine receives the 500+ finding types, the OT/ICS scanner, the external exposure mapping. Without this signal, the AI doesn't know if the vulnerable asset is exposed on the Internet. It can't distinguish a theoretical risk from a tomorrow-morning exploitable risk.

  • Forta Suppliers → Forta Cockpit

    The engine receives the continuous score of each critical third party, their drift, their alerts. Without this signal, the AI only sees your direct assets. It misses the 30-60% of cyber risk that comes through your supply chain.

  • Forta Compliance → Forta Cockpit

    The engine receives the CMMI maturity of each control, alignment to 40+ frameworks, coverage per asset category. Without this signal, the AI doesn't know if the asset is defended. It would prioritize a critical CVE on an already well-protected asset at the bottom of the list.

30 minutes to know what to fix first.

A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities.

Frequently asked questions

How does Forta Cockpit connect the modules?

Each module produces structured signals, ingested into a five-level relationship graph: asset to exposed service to vulnerability to available exploit to active threat actor. Each score combines CVSS, EPSS, KEV, real exposure and sector targeting, and is fully decomposable.

Is the scoring methodology a black box?

No. Every factor is documented, the per-module weights are configurable, and each calculation is exportable with its full breakdown. Residual risk reads control by control, and the share actually assessed is shown as a confidence badge next to the grade.

What AI model powers the copilot?

The conversational copilot uses a leading LLM for understanding, with retrieval over your risk graph. The model never sees your raw data, only structured query results, and your data stays in Canada.

How often is the score recalculated?

An hourly job sweeps the whole set, and a targeted recompute fires on every significant event. In practice, a remediation validated this afternoon changes the sub-domain's grade without waiting for the next day.

Which risk methodologies do you follow?

The model rests on ISO 27005 today: probability × impact, inherent and residual, treatment as accept, reduce, transfer or avoid. Risk scenarios are built to satisfy the two grammars your counterparts expect. EBIOS RM workshops first, whose security baseline, ecosystem, risk sources and strategic scenarios arrive pre-filled from your data instead of being reconstructed from a blank page. The FAIR taxonomy for cyber risk second, which forces you to name the threat actor, the asset at risk and the loss effect rather than writing “cyberattack risk”. One scenario reads in both grammars, with no double entry.