USE CASE · GROUP RISK
Steer group cyber risk like a P&L.
Entities, business units, countries: one consolidated risk picture along the structures you actually govern, with the autonomy each subsidiary needs and the visibility the group cannot do without.
| Organization | Score | Risk Analysis | Third parties | Exceptions | Business Impact | Remediation |
|---|---|---|---|---|---|---|
| France | 86 | 4.6 | 4.4 | 4.1 | 4.5 | 4.2 |
| Germany | 78 | 4.3 | 3.6 | 3.4 | 4.1 | 4.0 |
| Retail BU | 71 | 3.8 | 3.9 | 3.1 | 3.6 | 3.5 |
| Industrial BU | 64 | 3.4 | 3.2 | 2.6 | 3.3 | 2.8 |
| North America | 47 | 2.9 | 1.6 | 2.2 | 2.7 | 2.4 |
| Group average | · | 3.8 | 3.3 | 3.1 | 3.6 | 3.4 |
Third-party maturity flagged on a recent acquisition: exactly what a group view is for.
THE SITUATION
Twelve local registers do not make a group view.
-
Every entity keeps its own register
Different scales, different methods, different tools. Consolidation means a quarterly spreadsheet merge that nobody fully trusts.
-
The board asks for one number
You have twelve methodologies. The answer changes with whoever compiled it, and the meeting debates the figure instead of the risk.
-
Acceptance without a chain
Local risks get accepted locally, silently. Nobody can show who had the authority to accept what, or when that acceptance expires.
-
Autonomy versus visibility
Subsidiaries want to run their own program. The group needs to see across all of them. Most tooling forces you to pick one.
CAPABILITIES
One method. Every entity. Roll-up and drill-down.
-
Model the group as it is
Entities, business units and geographies are first-class objects in a hierarchy, with access scoped by role: an entity works its perimeter, the group sees across.
-
A consolidated risk picture
The group view rolls cyber posture up across entities and drills down to the risks behind it, with equal or weighted aggregation, stated on the dashboard.
-
Scores that compare
EBIOS RM, ISO/IEC 27005 and NIST in the same register: scenarios, scores and treatment plans expressed the same way in every entity.
-
Appetite and KRIs where risk lives
Risk appetite statements and KRIs are set per entity, and threshold breaches surface as they happen, at entity and group level.
-
Acceptance with an authority ladder
Risk acceptance follows an explicit approval ladder: the higher the residual risk, the higher it escalates in the organization. Owned, justified, time-bound.
-
Board-ready in one export
Board packs in PDF or PowerPoint, generated from the live register: the figures on the slide are the figures in the platform.
ROLL-UP, VERIFIED
A group view you can drill into is a group view you can trust.
Consolidation that ends in a static slide dies in the meeting. Every consolidated figure in Mindlapse opens onto the entities, risks and evidence behind it, so the discussion moves from “where does this number come from?” to “what do we decide?”.
- 01
Model the group
Load your organization: entities, business units, countries, roles and scopes. The structure you govern becomes the structure of the platform.
- 02
Align the method
One register, shared scales, appetite and KRIs per entity. Each subsidiary keeps its program; the group gains comparability.
- 03
Steer and decide
Consolidated posture, breach alerts, acceptance ladders and board packs: risk decisions with a paper trail.
UNDER THE HOOD
The modules doing the work.
Risk Intelligence
The shared register, scenarios, appetite and KRIs every entity works in.
Learn more
Board-Ready Reporting
The consolidated command view: posture, organization map, value chain.
Learn more
Ernest - AI engine
Drafts analyses, summaries and checks along the way, with humans on the final word.
Learn more
FAQ
Group risk, in practice
Can subsidiaries keep their autonomy?
Yes. Access is scoped by organization: an entity manages its own risks, appetite and acceptances inside its perimeter, while group roles see across entities. Autonomy is a permission model, not a promise.
What if entities use different methods today?
The register carries EBIOS RM, ISO/IEC 27005 and NIST analyses side by side. Entities converge on shared scales without abandoning how they work: comparability comes from the model, not from imposing one method overnight.
How does consolidated reporting work?
The group view aggregates residual exposure across entities, with equal or weighted aggregation, and every figure drills down to the underlying risks. Board packs export the same data to PDF or PowerPoint.
Who can accept a risk?
An acceptance ladder you configure: by residual level, approval escalates through the hierarchy, up to group level when the exposure warrants it. Every acceptance is owned, justified and expires.
GLOSSARY
Terms to know
GROUP VIEW, VERIFIED
Bring your org chart. Leave with a consolidation model.
A live session on your structure: entities, scopes, roll-up and the board view.