Built on standards, not a private scale.
We build on published frameworks rather than a proprietary one, so an assessment speaks the same language as your auditors, your regulators and your partners. Each framework contributes something distinct, and each one stops somewhere.
What each one governs.
The six stages of an assessment, and which framework carries each. The highlighted stages show where a framework does its work.
The backbone of how we score, defining the risk model of likelihood and impact.
Structures how risk is governed over time rather than assessed once.
The control catalogue we map recommendations against.
Organises findings into functions leadership reads without translation.
Aligns the work to the ISO 27001 world for organizations that live in it.
Categorises how each component of a system can be attacked.
Grounds the threat model in how adversaries actually operate.
Why not one framework, done thoroughly?
Because no single one covers the whole path. NIST SP 800-30 tells you how to score but not how to enumerate threats against a component. STRIDE does that but says nothing about likelihood. ATT&CK grounds the threats in real behaviour but is not a scoring system. ISO/IEC 27005 aligns the work to a certification world but defers the threat detail.
Used together they close each other's gaps. The skill is in the seams, applying each where it is strong and not stretching it past where it stops.
See how the score itself works.
The frameworks set the structure. The scoring model shows how a number is actually reached.