CYBER · PRIVACY · DIGITAL TRUSTPowered by Falconry360 Book a working session

Home/Platform/Risk coverage

Proposition

Risk coverage

A cyber platform that only carries cyber risk leaves the board with an incomplete picture. These are the categories FalconryTrust holds, all quantifiable through the same FAIR method.

FALCONRY360 IN PRACTICE

See the operating layer behind the service.

The platform gives the client a current view of the work, not only an end-of-month report. Scope, owners, evidence and actions remain visible between service reviews.

Illustrative Falconry360 risk quantification workspace showing exposure drivers and treatment priorities.Illustrative platform view
The risk taxonomy becomes useful when every category can be linked to an owner, scenario, control and treatment decision.
One register quantified in USD Asset Third party Concentration Technology Cloud Privacy Human OT AI and model Resilience Regulatory Geopolitical

One registerquantified in USD

  • Asset
  • Third party
  • Concentration
  • Technology
  • Cloud
  • Privacy
  • Human
  • OT
  • AI and model
  • Resilience
  • Regulatory
  • Geopolitical
A cyber platform that carries only cyber risk leaves the board with an incomplete picture. These are the categories that actually generate loss.

The taxonomy

Every category feeds the same register, uses the same asset and supplier masters, and can be quantified in USD rather than scored on a five-point scale.

Asset-based risk
Risk assessed against the asset itself: applications, infrastructure, databases, endpoints, cloud services, OT assets and the business services they support. Each carries confidentiality, integrity and availability ratings, an owner, a classification and a crown-jewel flag. Exposure aggregates upward to the service and downward to the control.
Third-party and supply chain risk
Supplier master with criticality tiering, data exposure, assessment cycles by tier, contract clause tracking, right-to-audit position, exit and substitutability assessment, and fourth-party visibility where the supplier discloses it. Continuous external monitoring is ingested where the client subscribes to it.
Concentration risk
Calculated across the portfolio rather than judged supplier by supplier: how much of the estate depends on one cloud region, one payment processor, one core banking provider, one identity platform. The question a regulator now asks directly.
Technology and IT general controls
Change management, logical access, privileged access, segregation of duties, backup and recovery, and the ITGC set that external audit tests annually. Held as controls with evidence, not as an audit deliverable rebuilt each year.
Cloud risk
Shared responsibility split made explicit per service, configuration posture, tenancy and residency position, provider assurance artefacts, and the national cloud control sets that apply in each market.
Data and privacy risk
Processing activities, lawful basis, retention, cross-border transfer, data subject rights exposure and breach likelihood, assessed per jurisdiction against the regime that governs that processing.
Human risk
Susceptibility measured through simulation, reporting behaviour, policy acknowledgement, access hygiene and role-based exposure, expressed as a risk contribution rather than a training completion rate.
Operational technology and industrial risk
OT asset inventory, zone and conduit position, remote access exposure, and control compliance mapped to national OT control sets and IEC 62443. Compliance and control assurance; not offensive testing.
Artificial intelligence and model risk
AI system inventory, use-case impact assessment, data lineage, model change control and human oversight, governed under an ISO 42001 management system.
Resilience and continuity risk
Risk expressed against impact tolerances for important business services, with dependency-driven single points of failure surfaced from the same asset and supplier masters.
Regulatory and compliance risk
Exposure arising from obligations not met, evidence not held, or change not absorbed — tracked per jurisdiction and per instrument.
Geopolitical and cross-border risk
Regional exposure, data localisation constraints, sanctions and sovereignty considerations affecting where systems run and where data sits.

Artificial intelligence and model risk

Adoption is running ahead of governance in most organisations we work with. The gap is usually inventory: nobody can list the AI systems already in use.

AI system inventory
What is deployed, by whom, on what data, with what human oversight — including embedded vendor features that arrived without a procurement decision.
Impact assessment
Use-case assessment covering purpose, affected parties, data, model provenance, failure modes and oversight, routed for approval before deployment.
ISO/IEC 42001 management system
Policy, roles, objectives, controls and internal audit for an AI management system, structured the same way as the ISMS so the two share evidence.
Model and change governance
Version control, evaluation records, change approval, and monitoring for drift or degradation in the outcomes that matter.
Data lineage and rights
Training and inference data traced to source, with lawful basis and transfer position recorded alongside the privacy register.
Third-party AI
Vendor AI capability assessed as part of supplier due diligence rather than as a separate exercise.

Operational technology and industrial risk

Industrial estates in this region are being brought into national cyber control regimes with real deadlines. Our scope is compliance and control assurance.

OT asset inventory
Assets, zones and conduits recorded in the same asset master as the IT estate, with criticality and safety relevance.
National OT control compliance
Mapping and evidence against the operational technology control sets applicable in the market, maintained as they are updated.
IEC 62443 alignment
Security levels, zone and conduit requirements and supplier obligations mapped to the same control library.
Remote access and third-party exposure
Vendor access to OT tracked as a controlled, evidenced pathway rather than a standing arrangement.
IT and OT convergence risk
Interface points between corporate IT and industrial control assessed as risk objects with their own treatment.
OT resilience
OT-supported business services carried into the Withstand pillar with their own impact tolerances and scenarios.

Scope note. FalconryTrust covers OT compliance, control assurance and governance. It does not provide offensive security, penetration testing or red-team services in any environment, industrial or otherwise.

Why one taxonomy matters

Aggregation is impossible when every category is scored differently.

Organisations commonly run a cyber risk register, a technology risk register, a third-party register and a privacy risk log, each with its own scoring scale. Nothing can be added up, so nothing can be prioritised across them, so investment decisions are made inside categories rather than across the estate.

A single taxonomy with a single quantification method makes the comparison possible: a third-party concentration exposure and a legacy application exposure become two numbers in the same currency, and the more expensive one gets the budget.

How quantification works

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.