No simulation has been run yet.
The dashboard shows risk posture, decision confidence,
and top priorities after the first run.
Why can the security views rank areas differently?
50% = calibrated analog (incident data from comparable organisations) · 25% = expert estimate · 0% = default assumptions · Click a scenario to see what evidence is present and what is missing.
| Scenario | Mean loss | P95 loss | Mode |
|---|
Edit calibration evidence, frequency, and cost assumptions directly in the catalog. Changes are saved to the YAML file on disk.
Loading scenarios…
Record the formal decision, its approved basis, and whether it remains defensible.
Select candidate or planned controls. Costs and eligibility are revalidated server-side.
No decisions recorded for this session.
Assessments
Import external evidence, compare it with current authoritative posture, and review the controls with greatest decision impact first.
Risk Workshop
Start from an unprotected baseline. Toggle controls to In Place, enter your actual annual cost, then run the simulation to see how your posture reduces financial exposure.
Enter at least annual revenue and number of employees to see estimates.
How to read the three security views
—
—
—
| Scenario | Inherent | Residual | Reduction |
|---|
| ID | Type | Age (d) | Score | Tier |
|---|
MITRE ATT&CK Coverage
How well the active scenario model covers the ATT&CK Enterprise tactic framework, and which techniques are mitigated by in-place controls.