Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

CAPABILITY · BUSINESS CENTRIC

Cyber risk, measured where the business makes money.

Model your value chains, from primary functions to the activities that carry them, and attach risk where it means something: to business activities with an owner and a criticality. Not to a list of servers.

Value chain · board view Illustrative data

7 functions 26 activities 21 risk links 8 incident links 6 supplier links 7 critical

Operations

Cold Chain Monitoring Critical

3 risks · 1 incident

Order Management High

2 risks

Outbound

Last Mile Delivery Critical

2 risks · 2 suppliers

Click & Collect High

1 risk · 1 supplier

Marketing & Sales

E-Commerce Platform Critical

4 risks · 1 supplier

Dynamic Pricing High

1 risk

Customer Service

Omnichannel Contact High

2 risks · 1 incident

AI Chatbot Medium

1 risk

VALUE ↓
Support functions Cloud Infrastructure Identity & Access Regulatory Compliance HR Information System

Each activity carries its criticality and its risk links: exposure reads in business activities, not in CVEs.

THE SITUATION

Your register speaks CVE. Your board speaks revenue.

Hover a finding: the chain shows the activity it threatens. That is the whole translation.

Translated by the chain Illustrative data

What the register says

Translated by the chain

What the board hears

  • E-Commerce Platform

    Marketing & Sales

    Critical

    2 risks · 1 supplier

  • Cold Chain Monitoring

    Operations

    Critical

    3 risks · 1 incident

  • Identity & Access

    Support function

    Critical

    4 risks · 6 activities depend on it

  • AI Chatbot

    Customer Service

    Medium

    1 risk

WHAT YOU DO WITH IT

Six things you actually do with the value chain.

Open one. The scene beside it shows what changes on the chain.

Sound familiar? Technical findings, business questions Assets without business context Impact numbers nobody stands behind Spend without a business story
01 Model the chain

Primary and support functions broken into activities, Porter style, each with an owner, a criticality level and an estimated financial impact.

  • Functions and activities in business language
  • An owner and a criticality on every activity
  • Support functions under the whole chain
02 Attach risk where it lands

Risks, incidents, suppliers and test engagements link to the activities they threaten, so exposure aggregates by what the business does, not by hostname.

  • Risks, incidents, suppliers and TLPT on the activity
  • Exposure rolls up from activity to function
  • A finding traces to the value it threatens
03 Run the impact analysis

BIA on the critical activities: loss horizons, recovery objectives, minimum resources, rolled up from the activity to the function.

  • Loss horizons and recovery objectives per activity
  • Minimum resources to restart
  • Consolidated at function level
04 Read the chain three ways

A board view by function, a dependency map, and a risk heatmap: the same model read as planning, architecture or exposure.

  • Board view: functions and their activities
  • Dependency map: what breaks what
  • Heatmap: where exposure concentrates
05 See suppliers in the chain

Third parties appear on the activities they operate or host, and concentration becomes visible exactly where it would hurt.

  • Each supplier on the activities it runs
  • Concentration flagged on the chain
  • Straight into third-party risk management
06 Report in business terms

Criticality per activity, exposure by function, and the security conversation anchored to the value the company defends.

  • Exposure by function, risks one click behind
  • Criticality the business owns
  • The board pack starts from value at stake
Inside the module Board view Dependency map Risk heatmap BIA Activity sheet

BUSINESS FIRST

From technical findings to business exposure.

The value chain is the translation layer: technical risk goes in, business exposure comes out. When a finding lands, you see the activity it threatens, the value that activity carries and what depends on it, and the discussion starts where it should: what does the business stand to lose?

  1. 01

    Map the chain

    Functions and activities, primary and support: the business as it creates value, described in business language.

  2. 02

    Attach the context

    Criticality, financial impact, BIA, suppliers, risks and incidents land on the activities they concern.

  3. 03

    Read and decide

    Exposure by activity and by function: prioritize, invest and report in the terms the board already uses.

FAQ

The value chain, in practice

Who maintains the value chain?

The business, in business language: functions and activities, not systems. Security enriches it with risk, incident and supplier links; activity owners keep criticality current.

Is this a CMDB?

No, deliberately. The chain models macro activities and the systems that serve them, not instances, hostnames or versions. It answers “what does the business lose?”, not “which server is this?”.

How does this change board reporting?

Exposure reads by activity and by function, with the risks behind each one a click away. The security conversation starts from the value at stake, which is the starting point boards accept.

VALUE, DEFENDED

Bring one business line. Watch its chain light up.

A live session: functions, activities, impacts and the risks that land on them.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.