Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

BY ROLE · RISK MANAGER

A cyber line the rest of the risk map can trust.

Your committee arbitrates between risks it can compare, and cyber arrives as a colour on a slide, scored by a method nobody outside security can explain. Mindlapse gives the cyber line the same discipline as the others: explicit scoring, appetite, owners, reviews.

Inherent · Residual · Target · One appetite, one escalation path

Risk Register · one record, three scores Illustrative data
R-0231 Loss of the payments platform for 48 hours Treatment in progress
Inherent 20 L4 × I5 Critical Worst case, before any control.
Residual 12 L3 × I4 High Exposure today, after controls.
Target 6 L2 × I3 Moderate The ceiling the owner commits to.
The treatment path on the matrix
Inherent Residual
Improved ↘
Treatment Mitigate Quarterly · next review in 11 weeks

The residual-to-target gap is the commitment the committee arbitrates.

THE SITUATION

Cyber is the line on the map nobody can challenge.

  1. A score without a method

    “High” means whatever the last analyst meant; the committee cannot set it beside the fraud line.

  2. Appetite approved, never measured

    The board signed a tolerance statement; nothing tells you the day it is breached.

  3. Scenarios that live in workshops

    The EBIOS session produced a deck, not a register that changes when a control fails.

  4. Concentration nobody owns

    One provider under four business lines, visible only on the day it goes down.

YOUR WEEK, YOUR QUARTER

The week keeps the line true; the quarter puts it in front of the committee.

A risk line earns trust by being re-scored, re-reviewed and re-accepted on a schedule the committee can see.

A risk manager’s week, then the quarter Illustrative data

Your week

  1. MON 09:00

    Three reviews fell due while you were away.

    They surfaced on their own, each with its owner and its last score.

    Surface: Risk Register

  2. TUE 11:20

    Ernest proposed a likelihood you did not agree with.

    The analyst rejected it with the weighted factors on screen and re-scored; the record kept the provenance, human, AI-suggested or hybrid.

    Surface: Risk Analysis

  3. WED 15:00

    A supplier’s answer contradicted a control it had declared.

    A finding was raised into the queue, linked to the risk that depends on that supplier.

    Surface: Action queue

  4. alert: THU 08:30

    The payments line crossed its appetite.

    The alert reached the owner and an acceptance request opened on its own, escalated to the authority its residual band requires.

    Surface: Risk Posture

  5. verified: FRI 16:00

    The committee wants the trend, not a point.

    The KRI trend was read from the daily snapshots, no series rebuilt by hand.

    Surface: Risk Posture

Your quarter

  1. WEEK 4

    A new activity enters the scope.

    Five guided EBIOS RM workshops, the scenarios straight into the register.

    Surface: Risk Analysis

  2. WEEK 9

    The acceptance requests.

    Escalated by residual band, the required authority frozen at submission, each one time-bound.

    Surface: Risk Posture

  3. WEEK 12

    The committee review.

    Every cyber line with its owner, its last review and its residual-to-target gap.

    Surface: Risk Register

Illustrative week: the moments are fictional, the surfaces are the product’s.

FROM THE FIELD

Built with the people who defend the line.

CYBER COLLECTIVE LAB · Edition 2

Third-party risk assessment (TPRM) in the strategic chemicals sector

Concentration as a risk-committee topic: the edition on third-party risk in the strategic chemicals sector, where one provider under several business lines stopped being a procurement detail.

2–3×
risk visibility across the organization
−50–70%
time-to-risk-decision
15–30%
cyber-budget optimization

Measured with our design-partner CISOs, figures under continuous validation.

FAQ

The risk manager asks

Do you quantify in euros (FAIR, Monte-Carlo)?

No. Mindlapse works in scores, bands and commitments: likelihood times impact on the scales you govern, inherent, residual and target on every risk. The value chain carries a criticality and an estimated-impact field on each activity, never a euro figure, and no FAIR or Monte-Carlo model runs behind the score.

Can the cyber register feed our ERM tool?

Not through a connector today: there is no ERM integration in the catalog. What you get is a line built to be comparable: the scoring model is explicit, the scales are yours, and board packs export in PDF or PowerPoint for the committee file.

Which methods are supported?

NIST 5×5 as the baseline, ISO/IEC 27005, and EBIOS Risk Manager run as five guided workshops, from framing to treatment. Scales and matrices are configured per organization, with inheritance, so an entity can keep its scale and the group still compares.

How does a supplier rating change a risk?

It never rewrites the score by itself. A deteriorating rating fires the re-assessment trigger; a contradiction in the supplier’s answers raises a finding on the risk linked to that supplier; the score changes when you re-score, and the record shows why.

Does the AI decide anything?

No. Ernest proposes a likelihood, a scenario or a treatment with its confidence level; accepting or rejecting is an explicit act, recorded with its author, and every risk keeps its provenance: human, AI-suggested or hybrid.

ONE REGISTER, VERIFIED

Bring your top three cyber risks. Leave with them scored, owned and inside an appetite.

A live session on your method: scales, matrix, appetite, escalation.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.