Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

MODULE · RISK INTELLIGENCE

From project to governed risk, one lifecycle.

Risk Intelligence covers the whole lifecycle: security requirements attached to a project the day it starts, the feared events and business impact that frame the analysis, scoring in inherent, residual and target, and the appetite your board approves, with incidents and policies to answer for it. Ernest proposes; your team decides.

Risk record · triple scoring Illustrative data
R-0847 Ransomware freezes the order-to-cash ERP Treatment pending
Inherent 20 L4 × I5 Critical Worst-case before any control.
Residual 12 L3 × I4 High Current exposure after controls.
Target 6 L2 × I3 Moderate Tolerance ceiling the team commits to.
Before / after treatment
Inherent Residual
Improved ↘
Treatment Mitigate Next review: in 8 weeks · Quarterly

Every risk carries all three score sets: the distance from residual to target is the treatment commitment, on the matrix you govern.

WHAT YOU DO WITH IT

Eight surfaces, one lifecycle.

Open one. The scene beside it shows what changes in the module.

Sound familiar? Security arrives after everything is decided The register was true the day of the workshop Nobody knows the day appetite is breached The incident gets qualified under pressure
01 Attach security to the project, not to its delivery

Every initiative, a project, a tender, a new application, declares itself once in business words. Criticality and exposure decide the path: an AI-assisted fast track for the standard ones, an analyst-led review for the critical ones. A human validates on both.

  • An initiative declared once, in business words
  • A path proportionate to risk: assisted fast track or analyst review
  • Exceptions that carry an expiry date
02 Name what you fear, once and for all

The catalogue of your organization’s feared events: what must not happen, written from the business side, reusable in every analysis instead of being reinvented in each workshop.

  • A catalogue of feared events specific to your organization
  • Risk sources and consequences tied to every event
  • Reusable from one analysis to the next, instead of rewritten
03 Give the analysis its impact scale

The BIA says what an interruption does to the business: loss horizons, recovery objectives and minimum resources per critical activity, rolled up from the activity to the function. Analyses read that scale instead of estimating it each time.

  • Loss horizons and recovery objectives per critical activity
  • The minimum resources that keep the activity running
  • An impact scale your analyses read directly
04 Run the workshops with the method you practice

EBIOS Risk Manager in five guided workshops (framing and feared events, risk sources, strategic scenarios, operational scenarios, risk treatment), ISO/IEC 27005, or the NIST baseline. Scales and matrices are configurable per organization, with inheritance.

  • EBIOS RM in five guided workshops, end to end
  • Strategic and operational scenarios, as a bowtie (ISO 31010)
  • MITRE ATT&CK attribution, weighted by analyst confidence
05 Score three ways, and keep the register alive

Inherent, residual and target each carry a full score set, and the gap from residual to target is the treatment commitment. Every risk carries an owner, a review cadence and a next-review date; overdue reviews surface on their own.

  • Inherent, residual and target on one record
  • An owner and a review cadence on every risk
  • Links to suppliers, controls, incidents and the value chain
06 Govern appetite, and know the day it is breached

Appetite statements carry an approval, an expiry and breach alerts. Key risk indicators read against those thresholds, and a breach opens the acceptance request, escalated to the authority the residual band requires.

  • An appetite approved, dated, with breach alerts
  • KRIs with green, amber and red thresholds, read against appetite
  • An authority ladder by residual band, time-bound
07 Qualify the incident against the criteria, not under pressure

An incident is recorded and qualified once, against the criteria of each applicable regime. The cascade assesses, prepares the notification file and logs it; your entity remains the one that files it. GRC scope: the governance of the incident, not the technical response.

  • One qualification, read by every applicable regime
  • The notification file prepared, your entity still files it
  • The incident tied to the risk, supplier and control it touches
08 Keep the policies that frame the posture alive

Draft, approve and publish policies, then have them attested by the people they bind. Every version is dated, and the attestation says who read what, and when.

  • Drafting, approval and publication, versioned
  • An attestation by the people the policy binds
  • The cyber-risk policy the management body adopts
Inside the module Risk Register Risk Posture Feared Events Business Impact Analysis Risk Analysis Cyber Incidents Policies Security by Design

PROPOSED, NOT IMPOSED

Ernest proposes. Your team decides. The register remembers.

Ernest drafts likelihoods with weighted factors, full scenarios with their attack chain, treatment strategies with estimated residual, and even the acceptance rationale. Every suggestion carries a confidence score and an explicit accept-or-reject that is recorded: each risk keeps its provenance, human, AI-suggested or hybrid.

  1. 01

    Design

    The initiative declares itself, its criticality decides the path, and security requirements ship with the project instead of chasing it.

  2. 02

    Analyze and score

    Feared events, business impact, EBIOS RM workshops: the scenario becomes a risk scored inherent, residual and target, with its treatment plan. Ernest proposes; analysts accept or reject.

  3. 03

    Govern

    Appetite, KRIs and acceptances hold the posture; incidents and policies document it when someone asks for an account. Board packs export straight from the live register.

FAQ

Risk Intelligence, in practice

Which methodologies does it support?

Three ship ready to use: NIST 5×5 as a baseline, ISO/IEC 27005, and EBIOS Risk Manager as five guided workshops (framing and feared events, risk sources, strategic scenarios, operational scenarios, treatment). Scales and matrices are configurable per organization, with inheritance.

What do inherent, residual and target mean?

Inherent is the worst case before any control; residual is your current exposure after controls; target is the tolerance ceiling the team commits to. Each carries its own full score set, and the treatment strategy (avoid, mitigate, transfer or accept) is what moves residual toward target.

Are cyber incidents a SOC feature?

No. The scope is GRC, not SecOps: Mindlapse does not detect the attack and does not drive the technical remediation. It records the incident, qualifies it once against the criteria of each applicable regime, prepares the notification file, and ties it to the risk, the supplier and the control it touches. Your entity remains the one that files.

What exactly does Security by Design do?

Every initiative declares itself once in business words; its criticality and exposure decide the path, an AI-assisted fast track or an analyst-led review, with a human validating on both. Security requirements are attached to the project, and exceptions carry an expiry date. The product has no CI/CD integration and no code scanning: nothing runs in your pipeline.

RISK, GOVERNED

Bring a project that is starting. Leave with its risk scored.

Thirty minutes on a case of yours: the Security by Design path, the analysis, the scoring and the appetite beside it.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.