Exposure and decisions
What changed, what is outside appetite and what should the board decide?
Executive postureServices
A platform nobody outside the security team opens is a reporting tool. This is how the work reaches the people who actually control the risk — a view per role, and a champion network that gives every department a named owner.
ROLE-BASED OPERATIONS
Falconry360 is designed to move a programme beyond the security team. Each role sees the records, decisions and work queue they can influence—without losing the common context underneath.
What changed, what is outside appetite and what should the board decide?
Executive postureWhich processing, transfer, rights or incident action is due next?
Privacy operationsWhich technology owner or supplier needs to act to keep the service within tolerance?
Service resilienceShown the whole register, a department head sees nothing. Shown their nine open findings, they act.
Most implementations fail the same way: everything is built for the security function, so everyone else receives a report they did not ask for about controls they do not recognise. Nothing changes in the business, and within two quarters the platform is a compliance artefact.
Each role gets a view scoped to what they own and what they can change. The underlying data is the same record; the framing, the scope and the call to action are not.
| Role | What they see | What they do with it |
|---|---|---|
| Board and risk committee | Quantified exposure in USD with trend, control health, resilience position against impact tolerances, regulatory status by jurisdiction, and the small number of decisions actually being asked for. | Approve appetite, accept or reject residual risk, release investment. |
| CISO or CRO | Full exposure register, control effectiveness, assurance coverage, third-party portfolio, incident and human risk position, and the regulatory change queue. | Direct the programme, prioritise remediation, prepare the board and the regulator. |
| DPO or privacy lead | Processing records, rights requests against statutory clocks, DPIA queue, transfer register, breach position and training compliance — separated by governing regime. | Advise, escalate, respond to regulators, evidence accountability. |
| CIO or CTO | ITGC health, change and access evidence, cloud posture, concentration position, technology risk register and AI inventory. | Fix control failures at source, plan around dependency and concentration. |
| Head of department or business unit | The unit's own controls, open findings and their ageing, its suppliers, its people's human risk score and its share of the risk register — and only that. | Own the unit's position, close findings, justify exceptions. |
| Cyber champion | The champion's department view: awareness and simulation results, policy attestation, access hygiene, open actions, and a comparison against the organisation. | Drive local behaviour, chase attestations, escalate what the unit cannot fix. |
| Control owner | The controls they own, when each is next tested, what evidence is due, what is overdue — and nothing else. | Operate the control, supply evidence, flag design problems. |
| Supplier or contract manager | Their suppliers by tier, assessment status, expiring clauses, outstanding evidence and criticality. | Run reassessment, chase evidence, escalate concentration. |
| Internal audit and assurance | Combined assurance coverage, control test history, findings across all sources, and the evidence vault. | Plan risk-based audits, avoid duplicating work already done. |
The mechanism that puts a named person in every department and gives them something specific to do.
Adoption is the implementation risk. Treat it as one.