We give every risk a number you can defend.

Cyber Electra assesses what your organization needs to protect, models the threats against it, and scores your exposure before and after the controls you already have. You finish with a ranked view of where to act first.

Aligned to NIST SP 800-30 Rev. 1, ISO/IEC 27005:2022, STRIDE and MITRE ATT&CK.

Inherent

The risk before controls

What your organization would face if nothing were in place to stop it.

Residual

The risk that remains

What is left once the controls you have, and the ones we recommend, are accounted for.

The gap

Where the next dollar goes

The distance between the two shows what your current investment buys and what to fund next.

A risk assessment measures how much risk you carry, and how much of it a control actually removes.

Most reviews stop at listing what is broken. We go further and quantify what that exposure means, so the people paying for security can see where their money changes the outcome.

Six stages, run the same way on every assessment.

Consistency is what makes one year comparable to the next, and one system comparable to another.

StageWhat it produces
01Asset identificationScoped asset register tied to business value
02Threat modellingSTRIDE and MITRE ATT&CK threat catalogue
03Vulnerability analysisWeaknesses linked to each modelled threat
04Inherent risk scoringPre-control scores on a 1 to 5 scale
05Control mappingControls matched to the tools you run
06Residual risk and roadmapResidual scores and a prioritised plan

One report your board and your engineers both work from.

01

Executive summary

The risk picture and the decisions it points to, in plain language.

02

Ranked risk register

Every finding ordered by inherent and residual score, with owners.

03

Threat model

Threats mapped with STRIDE and MITRE ATT&CK across each system.

04

Control recommendations

Specific mitigations matched to what you already run.

05

Remediation roadmap

A sequenced plan to close the gaps, with effort and timeline.

Sample extract

Risk register, ranked

R-01Credential compromiseHigh
R-02Data exposure in transitElevated
R-03Third-party dependencyModerate
R-04Backup recovery gapModerate
AggregateInherent 20 → Residual 8

CE-TM-SAT-001  ·  v1.0  ·  8 June 2026

Threat Model for Satellite Systems Security

A public reference model across the space, link, ground and user segments, built on STRIDE, MITRE ATT&CK and the Aerospace SPARTA matrix, with a kill chain modelled on the 2022 Viasat KA-SAT incident. We publish our method so it can be examined rather than taken on trust.

Read the threat model

The finding that stayed High.

Inherent

Critical

Residual

High

One risk of twelve, after every control we could recommend.

Anonymized at the client's request.

A Canadian funeral services provider asked us to assess an application their staff had started using on personal phones before it had been vetted. We modelled the threats, scored twelve risks, and mapped controls against the security tools the organization already owned.

One risk would not come down. Staff can type personal information into the application by hand, and no technical control stops a person from typing. It entered the register as Critical and it left as High, with a recommendation built on process and training rather than a tool that does not exist.

We report the number we can defend, including when it is a number the client would rather not see. An assessment that only tells you what you hoped to hear is not worth commissioning.

Start with the decision in front of you.

Tell us what you are weighing up and the timeline you are working to. We reply within one business day with a scope and an approach.

Request an assessment