Cyber risk management
The Cyber risk management section in Asset Manager provides an end-to-end workflow for identifying, assessing, and mitigating cyber risks across your IT asset portfolio. It brings together your asset data, threat library, vulnerability information, and controls into a structured risk assessment process.
Cyber risk management is available with the Cyber risk management tier.
Note
The Overview page is available after the initial release.
Key capabilities
- Overview Monitor your overall cyber risk posture with KPI summaries and a list of your most exposed assets.
- Cyber risk assessments Run structured assessments using a four-step workflow (Details, Scope, Scoring, Results) with AI-assisted scoring to evaluate risk across selected assets.
- Cyber risks View and manage cyber risks in Object library.
- Controls View and manage controls in Object library.
- Threats Browse and manage your threat library.
- Vulnerabilities Access all vulnerability data including vulnerability categories, discrete assets, findings, and CVEs imported from security scanners.
- Mitigation plans Track mitigation actions for cyber risks in Object library.
How it works
The core workflow in Cyber risk management is the cyber risk assessment. An assessment scopes a set of assets and uses their linked cyber risks, threats, vulnerabilities, and controls to score each cyber risk scenario. The AI scoring agent can automatically score threat severity and vulnerability severity for all scenarios using asset details and linked items, which you can review and override as needed. Approved assessments feed into the overview metrics, and you can create mitigation plans for each cyber risk within cyber risk assessments.
Cyber risks, controls, and mitigation plans are shared GRC objects in Object library and are reflected here in a cyber-risk-specific view. Vulnerability data is imported from external scanners such as Tenable VM or through the Schema mapping import layer.