Platform
Who it serves
Six people carry the accountability between them, from the control owner's desk to the board table, and they do not want the same thing from the same platform. What each sees, and what changes for them.
- OPERATING
- The CISO, the DPO and the CIO
- OVERSIGHT
- The CRO, the Chief Executive and the Board
- ONE RECORD
- Six readings of the same asset, supplier, control and evidence base
- AND THE FORUM
- The cyber security steering committee, where they decide together
One record, six readings
The data is the same. The framing, the scope and the call to action are not.
Most platforms are built for one of these people and hand the others a report they did not ask for about controls they do not recognise. The result is a tool the security function opens and nobody else does, which is why so many implementations become compliance artefacts inside two quarters.
Each role works from a view scoped to what they own and can change, drawn from the same asset master, supplier master, control library and regulatory intelligence.
The CISO
Accountable for the posture, and for the story the board hears about it.
- The board asks what the risk is worth. FAIR quantification gives a USD exposure with the method open to challenge, rather than a rating that invites an argument about the scale.
- Four regulators, one team. One control set mapped across every regime you answer to, tested once, evidenced once.
- Examination season consumes the function. Evidence collected as work happens, assembled into examination packs on request rather than as a project.
- Third-party risk never finishes. Tiered assessment cycles, contract tracking, fourth-party visibility and portfolio concentration in one place.
- Awareness reporting says nothing. Human risk scored on behaviour and fed into the same register as every other exposure.
- The board pack takes a fortnight. Generated from live data, every figure traceable.
First ninety days: control library normalised, primary regulatory pack mapped, asset and supplier masters populated, and a first quantified view of the top exposures.
The DPO
Accountable for demonstrable compliance across regimes that do not agree with each other.
- Several regimes govern one group. Each processing activity is bound to the regime that governs it, and the workflow applies that regime's clock and conditions.
- The ROPA is out of date the day it is finished. Records linked to systems and suppliers in the platform's masters, updated as the estate changes.
- Rights requests arrive without warning. Intake, verification, system search, redaction and response with the statutory clock running on the record.
- Transfers are the exposure nobody has mapped. A transfer register with mechanism, destination and per-regime conditions.
- Breach timescales differ by jurisdiction. Threshold assessment and notification workflow per regime, with the clocks built in.
- Privacy sits outside the risk conversation. Privacy exposure quantified in the same taxonomy and the same currency as everything else.
Regimes covered: UAE federal PDPL, ADGM DPR 2021, DIFC DP Law 5 of 2020, Saudi PDPL and its regulations, Qatar PDPPL and QFC regulations, Oman PDPL, Bahrain PDPL, CITRA DPPR in Kuwait, and UK GDPR.
The CIO
Accountable for the estate everyone else assesses.
- ITGC is rebuilt for every audit. Change, access, privileged access, segregation of duties and backup held as controls with continuous evidence.
- Cloud governance is a set of assumptions. Shared responsibility made explicit per service, configuration posture tracked, residency recorded per tenant.
- Nobody can state the concentration position. Dependency on a single provider, region or platform calculated across the portfolio.
- Resilience is a document. Impact tolerances, dependency maps and tested recovery against the services the business actually depends on.
- AI is arriving through the side door. Inventory, impact assessment and oversight under an ISO 42001 management system.
- Security asks for the same data four times a year. One asset master, one supplier master, used by every function.
The platform governs the estate; it does not attempt to replace your operational stack. Findings, configuration and identity data are ingested from the tooling already in place.
The CRO
Accountable for aggregating risks that are measured on incompatible scales.
- Cyber arrives as a colour. Quantified in USD using the same loss-distribution method as the rest of the risk estate, so it can sit in the same report.
- Four registers, no aggregation. Cyber, technology, third-party and privacy risk in one taxonomy, so exposure can actually be summed and ranked.
- Appetite is stated but not measured. Appetite decomposed into tolerances by service, asset class and risk type, with breaches escalating on the agreed path.
- Investment cases are unarguable in either direction. Control spend argued against the exposure it removes, with assumptions visible and open to challenge.
- Assurance duplicates itself. Combined assurance mapping across first line, second line, internal audit and external assurance.
- Board reporting is assembled by hand. Produced from the live record, every figure traceable to its source.
Where a group also runs corporate governance and enterprise risk, Falconry360 shares this architecture, these libraries and this engine — so the consolidated view is one system, not an integration project.
The Chief Executive
Accountable for whether any of this threatens the strategy.
- Does this stop us doing what we said we would do? Exposure mapped to the services and markets the strategy depends on, not to a control list.
- Can we answer a customer's security questionnaire without a fire drill? Structured responses produced from the live control and evidence base, so enterprise deals stop stalling in procurement.
- Are we able to enter this market? Regulatory position per jurisdiction, so a licence application or a new-market decision is made with the compliance cost known in advance.
- What are we spending, and what does it buy? Investment argued against quantified exposure removed, in dollars, over a stated period.
- If it happens, are we ready? Crisis structures, decision logs and rehearsed communications — including the parts that involve you personally.
- Would our decisions survive scrutiny afterwards? A decision record showing what was known, who decided, and on what basis.
Most chief executives meet cyber risk twice: in a budget request they cannot evaluate, and in an incident they cannot control. The purpose of quantification and a decision record is to make the first one arguable and the second one survivable.
The Board and Risk Committee
Accountable for oversight that has to hold up afterwards.
- Are we inside appetite? Appetite stated in the terms the board set and decomposed into measurable tolerances, with breaches escalating on the agreed path rather than the convenient one.
- Who owns this? Every control, risk, supplier and regulatory obligation carries a named accountable owner, visible without asking management.
- What did we approve, and on what basis? Risk acceptances, exceptions and material decisions held as a dated record with the evidence that supported them.
- Is the assurance independent? Combined assurance coverage across first line, second line, internal audit and external assurance — showing gaps as well as coverage.
- Are we being told the whole picture? Reporting generated from the live record rather than assembled by the function being reported on, with every figure traceable to source.
- Would this withstand a post-incident inquiry? The question worth asking before the incident, and the one a decision record is built to answer.
Board packs are produced from platform data on a fixed cadence — exposure in USD with trend, control health, resilience position against impact tolerances, assurance coverage and regulatory status by jurisdiction. The small number of decisions actually being asked for is stated first.
THE FORUM WHERE THEY MEET
The cyber security steering committee
Not a seventh role — the place the six above make decisions together. In most of the markets we serve it is also a regulatory requirement, and the thing examiners ask to see minutes of.
What it decides
- Risk acceptance within delegated limits. Quantified in USD, with the residual position and the probability attached, so the committee knows the size of what it is accepting.
- Prioritisation of the roadmap. Competing investments compared on exposure removed rather than on who presented better.
- Exceptions and their expiry. Approved with an owner and an end date, then tracked. Exceptions that quietly become permanent are the most common governance failure we see.
- Escalation to the board. What crosses the threshold, stated in the terms the board set rather than translated afterwards.
What it must be able to evidence
- Terms of reference, membership and quorum — current, approved, and version-controlled rather than attached to an email from two years ago.
- A decision log showing what was decided, by whom, on what basis, and what evidence supported it.
- Action tracking to closure, with ageing visible, so the committee can see what it asked for and never received.
What the platform puts in front of it
- A standing pack generated from live data on the committee's cadence — exposure and trend, control health, incident and resilience posture, regulatory status by jurisdiction.
- The decisions actually requiring its authority, listed first. A committee handed a status deck and no decisions will stop meeting properly within a year.
- Open exceptions with ageing, and breaches of tolerance with the escalation path already applied.
- Roadmap position against regulatory deadlines, so slippage is visible while it is still recoverable.
- The minute and decision record written back against the controls, risks and exceptions it touched — so a decision taken here is findable from the control it affected.
Where the requirement comes from. Committee structures with defined mandate and reporting lines are expected under the SAMA Cyber Security Framework, the NCA governance controls, central bank rulebooks across the Gulf, ISO/IEC 27001 Clause 5, and the UK NCSC Cyber Assessment Framework. The specific composition and cadence that satisfies each is confirmed during scoping.