We give every risk a number you can defend.
Cyber Electra assesses what your organization needs to protect, models the threats against it, and scores your exposure before and after the controls you already have. You finish with a ranked view of where to act first.
Aligned to NIST SP 800-30 Rev. 1, ISO/IEC 27005:2022, STRIDE and MITRE ATT&CK.
Scored before and after the controls in place. Every number traces back to how it was reached.
The risk before controls
What your organization would face if nothing were in place to stop it.
The risk that remains
What is left once the controls you have, and the ones we recommend, are accounted for.
Where the next dollar goes
The distance between the two shows what your current investment buys and what to fund next.
A risk assessment measures how much risk you carry, and how much of it a control actually removes.
Most reviews stop at listing what is broken. We go further and quantify what that exposure means, so the people paying for security can see where their money changes the outcome.
Six stages, run the same way on every assessment.
Consistency is what makes one year comparable to the next, and one system comparable to another.
One report your board and your engineers both work from.
Executive summary
The risk picture and the decisions it points to, in plain language.
Ranked risk register
Every finding ordered by inherent and residual score, with owners.
Threat model
Threats mapped with STRIDE and MITRE ATT&CK across each system.
Control recommendations
Specific mitigations matched to what you already run.
Remediation roadmap
A sequenced plan to close the gaps, with effort and timeline.
Risk register, ranked
CE-TM-SAT-001 · v1.0 · 8 June 2026
Threat Model for Satellite Systems Security
A public reference model across the space, link, ground and user segments, built on STRIDE, MITRE ATT&CK and the Aerospace SPARTA matrix, with a kill chain modelled on the 2022 Viasat KA-SAT incident. We publish our method so it can be examined rather than taken on trust.
Read the threat modelThe finding that stayed High.
Inherent
Critical
Residual
High
One risk of twelve, after every control we could recommend.
Anonymized at the client's request.
A Canadian funeral services provider asked us to assess an application their staff had started using on personal phones before it had been vetted. We modelled the threats, scored twelve risks, and mapped controls against the security tools the organization already owned.
One risk would not come down. Staff can type personal information into the application by hand, and no technical control stops a person from typing. It entered the register as Critical and it left as High, with a recommendation built on process and training rather than a tool that does not exist.
We report the number we can defend, including when it is a number the client would rather not see. An assessment that only tells you what you hoped to hear is not worth commissioning.
Start with the decision in front of you.
Tell us what you are weighing up and the timeline you are working to. We reply within one business day with a scope and an approach.