FALCONRY360 IN PRACTICE
See the operating layer behind the service.
The platform gives the client a current view of the work, not only an end-of-month report. Scope, owners, evidence and actions remain visible between service reviews.
One registerquantified in USD
- Asset
- Third party
- Concentration
- Technology
- Cloud
- Privacy
- Human
- OT
- AI and model
- Resilience
- Regulatory
- Geopolitical
The taxonomy
Every category feeds the same register, uses the same asset and supplier masters, and can be quantified in USD rather than scored on a five-point scale.
- Asset-based risk
- Risk assessed against the asset itself: applications, infrastructure, databases, endpoints, cloud services, OT assets and the business services they support. Each carries confidentiality, integrity and availability ratings, an owner, a classification and a crown-jewel flag. Exposure aggregates upward to the service and downward to the control.
- Third-party and supply chain risk
- Supplier master with criticality tiering, data exposure, assessment cycles by tier, contract clause tracking, right-to-audit position, exit and substitutability assessment, and fourth-party visibility where the supplier discloses it. Continuous external monitoring is ingested where the client subscribes to it.
- Concentration risk
- Calculated across the portfolio rather than judged supplier by supplier: how much of the estate depends on one cloud region, one payment processor, one core banking provider, one identity platform. The question a regulator now asks directly.
- Technology and IT general controls
- Change management, logical access, privileged access, segregation of duties, backup and recovery, and the ITGC set that external audit tests annually. Held as controls with evidence, not as an audit deliverable rebuilt each year.
- Cloud risk
- Shared responsibility split made explicit per service, configuration posture, tenancy and residency position, provider assurance artefacts, and the national cloud control sets that apply in each market.
- Data and privacy risk
- Processing activities, lawful basis, retention, cross-border transfer, data subject rights exposure and breach likelihood, assessed per jurisdiction against the regime that governs that processing.
- Human risk
- Susceptibility measured through simulation, reporting behaviour, policy acknowledgement, access hygiene and role-based exposure, expressed as a risk contribution rather than a training completion rate.
- Operational technology and industrial risk
- OT asset inventory, zone and conduit position, remote access exposure, and control compliance mapped to national OT control sets and IEC 62443. Compliance and control assurance; not offensive testing.
- Artificial intelligence and model risk
- AI system inventory, use-case impact assessment, data lineage, model change control and human oversight, governed under an ISO 42001 management system.
- Resilience and continuity risk
- Risk expressed against impact tolerances for important business services, with dependency-driven single points of failure surfaced from the same asset and supplier masters.
- Regulatory and compliance risk
- Exposure arising from obligations not met, evidence not held, or change not absorbed — tracked per jurisdiction and per instrument.
- Geopolitical and cross-border risk
- Regional exposure, data localisation constraints, sanctions and sovereignty considerations affecting where systems run and where data sits.
Artificial intelligence and model risk
Adoption is running ahead of governance in most organisations we work with. The gap is usually inventory: nobody can list the AI systems already in use.
- AI system inventory
- What is deployed, by whom, on what data, with what human oversight — including embedded vendor features that arrived without a procurement decision.
- Impact assessment
- Use-case assessment covering purpose, affected parties, data, model provenance, failure modes and oversight, routed for approval before deployment.
- ISO/IEC 42001 management system
- Policy, roles, objectives, controls and internal audit for an AI management system, structured the same way as the ISMS so the two share evidence.
- Model and change governance
- Version control, evaluation records, change approval, and monitoring for drift or degradation in the outcomes that matter.
- Data lineage and rights
- Training and inference data traced to source, with lawful basis and transfer position recorded alongside the privacy register.
- Third-party AI
- Vendor AI capability assessed as part of supplier due diligence rather than as a separate exercise.
Operational technology and industrial risk
Industrial estates in this region are being brought into national cyber control regimes with real deadlines. Our scope is compliance and control assurance.
- OT asset inventory
- Assets, zones and conduits recorded in the same asset master as the IT estate, with criticality and safety relevance.
- National OT control compliance
- Mapping and evidence against the operational technology control sets applicable in the market, maintained as they are updated.
- IEC 62443 alignment
- Security levels, zone and conduit requirements and supplier obligations mapped to the same control library.
- Remote access and third-party exposure
- Vendor access to OT tracked as a controlled, evidenced pathway rather than a standing arrangement.
- IT and OT convergence risk
- Interface points between corporate IT and industrial control assessed as risk objects with their own treatment.
- OT resilience
- OT-supported business services carried into the Withstand pillar with their own impact tolerances and scenarios.
Scope note. FalconryTrust covers OT compliance, control assurance and governance. It does not provide offensive security, penetration testing or red-team services in any environment, industrial or otherwise.
Why one taxonomy matters
Aggregation is impossible when every category is scored differently.
Organisations commonly run a cyber risk register, a technology risk register, a third-party register and a privacy risk log, each with its own scoring scale. Nothing can be added up, so nothing can be prioritised across them, so investment decisions are made inside categories rather than across the estate.
A single taxonomy with a single quantification method makes the comparison possible: a third-party concentration exposure and a legacy application exposure become two numbers in the same currency, and the more expensive one gets the budget.