The risk register that fills itself in
No questionnaire to get started: the register feeds continuously from the five modules and from your integrations, across a taxonomy of 9 domains and 52 sub-domains. Every risk carries its inherent and residual level, and the residual is derived from controls instead of being typed in by hand.
5
Modules correlated
30 sec
Board briefing
30/60/90
Day trajectory
A black box does not hold up in front of a CFO.
If you cannot show how a risk score was built, you cannot defend the budget that depends on it.
Outcomes your team will feel.
Nobody occupies this bridge
Self-feeding tools do ratings or vulnerabilities without a methodological register; methodological registers stay manual. Here the two meet.
30-second board briefing
Walk into the committee with the answer ready.
No unknown coverage dressed up
When coverage is unknown the register shows "—", never a zero. An unmeasured domain must not look like a risk-free one.
Key capabilities
Posture across 9 IT risk domains, 52 sub-domains
A structured, understandable taxonomy of your IT risk, not a black box: 9 domains broken into 52 sub-domains you can read, defend and act on.
Fed by the modules and by your integrations
Signals from all five modules are pulled in and scored automatically, with evidence collected per control, no manual re-entry or spreadsheet wrangling. Integrations with your own environment open a second inlet: a Microsoft 365 tenant connected read-only reports its configuration and its alerts, and the matching risk is created in the register instead of waiting for the annual workshop.
A living register, never an annual document
The calculation runs hourly, and re-runs on events: a validated remediation, a vendor score drop or a changed compliance evidence immediately re-scores the sub-domain concerned. An annual register is obsolete the day it is published; this one follows reality.
Inherent and residual, derived from controls
Residual risk is never a manual entry: it comes down from the SCF control model, and when no control is recorded on a sub-domain, an implicit defense credit is derived from your posture maturity rather than leaving a hole. Treatment follows ISO 27005, accept, reduce, transfer or avoid, with a dated acceptance that reopens automatically when it expires.
Transparent, decomposable calculations
Every score breaks down to its inputs and the exact math (CVSS, EPSS, KEV, exposure, sector targeting, control coverage, asset criticality), defendable line by line to a CFO.
Fully customizable to your business
Tailor domains, categories, weights, thresholds and board-ready reports to your organization's specific needs. The engine adapts to you, not the other way around.
A degradation becomes an action, not one more row.
When a sub-domain's grade degrades, an "understand the degradation" action goes to the Action Center with its context. Calibration by organization profile, five risk tolerance levels based on your size, sector and appetite, automatically adjusts perceived severity: the same raw risk does not weigh the same everywhere.
Nine domains: IT risk in full, not just cyber.
A security tool grades what it can scan, so it stops at information security — one domain out of nine. The register works the other way round: the IT risk taxonomy first, the sensors second. The five modules continuously fill what they can observe; the domains no scanner sees stay on the board, marked to assess, instead of disappearing from it.
Information security
Identity and access, vulnerabilities and patching, detection and response, network, cloud and endpoints, cryptography, application security, security governance.
Posture · EASM · CTI · ComplianceOperational resilience
Service availability and performance, continuity and recovery, change management, capacity and obsolescence, incident handling.
Posture · EASMThird-party risk
Pre-contract due diligence, contractual and SLA obligations, continuous monitoring, concentration and dependency across your supply chain.
TPRM · CTIRegulatory risk
Inventory of applicable obligations, control effectiveness testing, audit findings and remediation, privacy and sovereignty.
Compliance · PostureFinancial risk, IT view
Budget variance, cloud and licence optimization, asset lifecycle and depreciation, return on investment.
Assessed by your teamsData & AI
Data quality and integrity, governance and classification, ethical use and privacy, model reliability, shadow AI.
Compliance · PostureIT project risk
Schedule performance, budget and resources, scope and benefits realization, governance and adoption of digital initiatives.
Assessed by your teamsTalent & culture
Team capacity and skills gaps, retention and succession, key-person dependency, engagement and security culture.
Assessed by your teamsPhysical security
Access control and perimeter, surveillance, environmental and facility safety of your premises and technical rooms.
Assessed by your teams
A domain with no sensor is still a visible domain.
None of these nine domains is hidden for lack of an automatic source. Until you have assessed it, it shows “to assess” and a low confidence badge, never a reassuring zero. That is what makes the register defendable to an auditor and to a board alike: what is not measured is visible, and can be planned.
Three moments. Three different uses of the engine.
- Case 1
The CISO's morning (8:00 AM)
You arrive at the office. You open the Action Feed. You see 7 prioritized actions for today. First one: "Patch CVE-2025-XXXX on frontend-prod-01.acme.ca. Actor: BlackBasta targeting your sector. Estimated effort: 3 hours. Risk reduction: 12 points." You assign to your team. You move to the second one. In 15 minutes, your day is framed.
- Case 2
The day before the board (monthly meeting)
You ask the copilot: "Generate this month's board briefing." The copilot produces an 8-page PDF in 30 seconds: global risk score decomposed per pillar, 90-day trajectory, top 5 executed actions, top 3 upcoming, estimated avoided cost. Each figure sourced in the platform. You arrive at the board with a document you can defend line by line.
- Case 3
Threat pivot (CISA alert overnight)
CISA publishes a new KEV at 2:00 AM. At 2:15, the Risk Engine automatically recalculates scores for affected assets. At 2:20, your Slack webhook receives the alert with the list of vulnerable assets, their exposure, their owners. At 8:00 AM when you arrive, the day's Action Feed already integrates the new priority. You didn't wait for the weekly report.
What's included
The register feeds itself
- No questionnaire to fill in before you start
- The register feeds from posture, compliance, threat, attack surface and third parties
- Environment integrations: Microsoft 365, Entra ID, Defender
- Nine IT risk domains, from cyber to financial, project and physical
- Inherent and residual computed as probability × impact, not typed in
- The residual comes down from your controls, never from an opinion
- A sub-domain with no control on file inherits your posture maturity instead of a hole
- Recalculated hourly, and immediately whenever a signal changes
- ISO 27005 treatment: accept, reduce, transfer, avoid
- Dated acceptance that reopens on its own at expiry
- EBIOS RM workshops pre-filled from your data
- Scenarios structured on the FAIR taxonomy for cyber risk
Decisions you can defend to a board
- An A+ to F grade per sub-domain, per domain and for the organisation
- Every score breaks down to its inputs, line by line
- Confidence badge showing how much was actually assessed
- “—” when coverage is unknown, never a reassuring zero
- 5×5 matrix to arbitrate in committee
- 30, 60 and 90 day trajectory
- Board briefing in 30 seconds, every figure sourced in the platform
- Five tolerance levels calibrated to your size, sector and geography
- Five-level relationship graph, from asset to active threat actor
- A degradation leaves as an action in the Action Center, with its context
- Domains, categories, weightings and thresholds adjustable to your organisation
Optional AI enrichment
AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.
In the risk register, AI targets the narrative: explaining a score movement, drafting the trend commentary, preparing the board update. The inherent and residual risk calculation stays an explicit model, decomposable and exportable, never a model output.
Sovereignty: the platform is built and hosted in Canada, beyond the reach of the US CLOUD Act. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.
The Risk Engine is useless without the modules that feed it.
That's what differentiates it from a standalone scoring engine. Prioritization quality depends directly on the quality, freshness, and correlation of feeding signals. Here's what each pillar brings to the engine.
CTI → Risk Engine
The engine receives the 50M+ signals/day, the 1,500+ tracked actors, the enriched CVEs (CVSS + EPSS + KEV). Without this signal, the AI doesn't know if a CVE is being actively exploited. It would treat an unexploited CVSS 9.8 as a CVSS 6.5 in CISA KEV.
EASM → Risk Engine
The engine receives the 110+ finding types, the OT/ICS scanner, the external exposure mapping. Without this signal, the AI doesn't know if the vulnerable asset is exposed on the Internet. It can't distinguish a theoretical risk from a tomorrow-morning exploitable risk.
TPRM → Risk Engine
The engine receives the continuous score of each critical third party, their drift, their alerts. Without this signal, the AI only sees your direct assets. It misses the 30-60% of cyber risk that comes through your supply chain.
Posture → Risk Engine
The engine receives the CMM maturity of each control, alignment to 31 frameworks, coverage per asset category. Without this signal, the AI doesn't know if the asset is defended. It would prioritize a critical CVE on an already well-protected asset at the bottom of the list.
Explore the other modules.
30 minutes to know what to fix first.
A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.
Frequently asked questions
How does the engine correlate the five modules?
Each module produces structured signals, ingested into a five-level relationship graph: asset to exposed service to vulnerability to available exploit to active threat actor. Each score combines CVSS, EPSS, KEV, real exposure and sector targeting, and is fully decomposable.
Is the scoring methodology a black box?
No. Every factor is documented, the per-module weights are configurable, and each calculation is exportable with its full breakdown. Residual risk reads control by control, and the share actually assessed is shown as a confidence badge next to the grade.
What AI model powers the copilot?
The conversational copilot uses a leading LLM for understanding, with retrieval over your risk graph. The model never sees your raw data, only structured query results, and your data stays in Canada.
How often is the score recalculated?
An hourly job sweeps the whole set, and a targeted recompute fires on every significant event. In practice, a remediation validated this afternoon changes the sub-domain's grade without waiting for the next day.
Which risk methodologies do you follow?
The model rests on ISO 27005 today: probability × impact, inherent and residual, treatment as accept, reduce, transfer or avoid. Risk scenarios are built to satisfy the two grammars your counterparts expect. EBIOS RM workshops first, whose security baseline, ecosystem, risk sources and strategic scenarios arrive pre-filled from your data instead of being reconstructed from a blank page. The FAIR taxonomy for cyber risk second, which forces you to name the threat actor, the asset at risk and the loss effect rather than writing “cyberattack risk”. One scenario reads in both grammars, with no double entry.