Confidential W10 / 2026

Risk Intelligence Dashboard

MusterSec GmbH · Cyber Risk Measurement · March 2026

Risk-based approach · 12 risk scenarios · 10 control families · 8 KRI/KPI pairs

Risk Intelligence Risk Organization Board Report Risk P&L Methodology
A$84.2M
Inherent Risk
A$38.6M
Residual Risk
54%
Control Effectiveness
4
Beyond Appetite
14.3x
Investment ROI
5×5 Risk Matrix Controls → Residual Risk

12 scenarios · FAIR methodology · Risk in EUR

Panel 1
Risk matrix — 12 scenarios plotted by likelihood and business impact

Each risk is plotted on a 5×5 grid. Hover over a risk dot to see details. Colour indicates impact severity.

> A$15M
01
A$5–15M
12
02
05
10
A$2–5M
07
03
04
09
A$0.5–2M
11
08
06
< A$0.5M
Rare
Unlikely
Possible
Likely
Almost Certain
Likelihood →
Panel 2
Four risks exceed board-approved appetite — €8.5M total exceedance

“MusterSec accepts moderate cyber risk where controls reduce residual exposure below A$5M per risk. Risks exceeding appetite require board-level acceptance or immediate remediation.”

Approved: Board of Directors · 2025-12-15 · Next review: 2026-06-15
Within appetite
5
< A$3M residual
Click to expand ▾
At appetite limit
3
A$3–5M residual
Click to expand ▾
Beyond appetite
4
> A$5M residual
Click to expand ▾
Appetite Exceedances
R-001
Ransomware
Accelerate EDR + backup isolation
Agents: soc, ir
A$9.1M
vs A$5M limit
+A$4.1M
R-002
Supply chain compromise
Vendor continuous monitoring
A$7.2M
vs A$5M limit
+A$2.2M
R-005
SOCI Act non-compliance
Close 3 open gaps by Q2
Agents: compliance, grc
A$6.8M
vs A$5M limit
+A$1.8M
R-010
Unpatched CVE exploitation
Reduce patch SLA to 14 days
Agents: vuln, secarch
A$5.4M
vs A$5M limit
+A$0.4M
Panel 3
Inherent risk totals €84.2M before controls — threat-based risks dominate
A$84.2M
Total inherent risk

Value-at-Risk (VaR) methodology per McKinsey cyber risk framework. Inherent risk = exposure before any controls. Based on threat frequency, asset value, and vulnerability prevalence.

Threat-based ▾
A$27.0M
Vulnerability-based ▾
A$14.9M
Third-party ▾
A$14.3M
Compliance / Regulatory ▾
A$18.4M
Emerging / AI ▾
A$2.8M
Operational ▾
A$4.7M
Business Impact Analysis
AssetValueInherent Exposure
Customer payment platformA$28.4MA$22.1M
Customer PII databaseA$18.2MA$13.2M
ERP / financial systemsA$15.6MA$12.8M
Intellectual propertyA$22.0MA$7.6M
Public web infrastructureA$8.4MA$5.2M
Panel 4
10 control families reduce exposure by €45.6M — residual risk is €38.6M
A$84.2M
Inherent
A$45.6M
Controls reduce
A$38.6M
Residual
Control Effectiveness
EDR / XDR (CrowdStrike Falcon) ▾
Mitigates: R-001, R-006 · Agents: soc, ir, iam
72%
A$8.4M
Network segmentation (Zscaler + PA NGFW) ▾
Mitigates: R-001, R-004 · Agents: soc, ir, secarch, vuln
58%
A$5.2M
Identity & MFA (Okta + Entra ID) ▾
Mitigates: R-003, R-006, R-009 · Agents: iam, privacy, soc, awareness
88%
A$6.1M
Vulnerability management (Tenable + Wiz) ▾
Mitigates: R-004, R-010 · Agents: secarch, vuln
62%
A$5.8M
Vendor risk program (SecurityScorecard + OneTrust) ▾
Mitigates: R-002, R-008 · Agents: vendorrisk, appsec
45%
A$3.9M
Compliance automation (Vanta + ServiceNow GRC) ▾
Mitigates: R-005, R-012 · Agents: compliance, grc, privacy
64%
A$7.2M
Security awareness (KnowBe4) ▾
Mitigates: R-009 · Agents: awareness, soc
52%
A$2.9M
AI governance framework (OneTrust AI) ▾
Mitigates: R-007 · Agents: aigov, appsec
38%
A$1.1M
Incident response playbooks (XSOAR) ▾
Mitigates: R-001, R-002 · Agents: soc, ir, vendorrisk, appsec
67%
A$4.2M
DDoS protection (Cloudflare + Palo Alto) ▾
Mitigates: R-011 · Agents: secarch, soc
91%
A$0.8M
Inherent vs Residual Risk
Inherent
Residual
R-001 Ransomware
-50%
R-002 Supply chain
-42%
R-003 Insider exfiltration
-63%
R-004 Cloud misconfig
-48%
R-005 SOCI Act non-compliance
-32%
R-006 Credential stuffing
-74%
R-007 AI model poisoning
-39%
R-008 SaaS outage
-47%
R-009 Phishing / BEC
-39%
R-010 Unpatched CVE
-38%
R-011 DDoS
-90%
R-012 Privacy Act breach
-52%
Panel 5
Control compliance measured from 5 data sources — AI Safety Standards lags at 64%
Data Sources
Operational data
Real-time telemetry from CrowdStrike, Wiz, Tenable, Okta, Sentinel
78%
Real-time
high
Central policy
ServiceNow GRC policy library with 347 controls mapped to ISO 27001, SOCI Act, CPS 234
92%
Weekly sync
high
Self-assessments
Quarterly control owner attestations via Vanta + manual questionnaires
64%
Quarterly
medium
External audits
Annual ISO 27001, SOC 2, PCI DSS external certifications
100%
Annual
high
Threat intelligence
Recorded Future + CrowdStrike TI feeds mapping threats to control gaps
71%
Daily
medium
Compliance by Framework
ISO 27001:2022
84%
78/93 controls
SOCI Act (ACSC Act)
76%
32/42 controls
CPS 234
79%
30/38 controls
Privacy Act
86%
24/28 controls
PCI DSS 4.0
81%
52/64 controls
AI Safety Standards
64%
14/22 controls
Critical Control Gaps
non compliant
Privileged access MFA
SOCI Act s30BC · Personal board liability
2026-03-15
IAM team →
non compliant
Incident early warning (24h)
SOCI Act Art. 20 · A$500K fine risk
2026-04-01
SOC team →
non compliant
AI risk classification
AI Safety Standards Art. 6 · A$3.2M fine risk
2026-08-01
AI Gov team →
partial
Vendor exit strategy
CPS 234 Art. 28 · Concentration risk
2026-06-30
Vendor Risk →
partial
Cryptographic key rotation
PCI DSS 3.6 · Audit finding
2026-05-15
SecArch →
Panel 6
Risk-based investment saves €9M vs maturity-based — 14.3x overall ROI

Risk-based prioritization per McKinsey framework: investments ranked by residual risk reduction per euro spent, not by maturity level.

Maturity-based vs Risk-based Investment
Maturity-based approach
A$14M
Residual risk: A$42M
A$3.0 risk reduced per A$1 spent
Risk-based approach
A$5M
Residual risk: A$38.6M
A$9.1 risk reduced per A$1 spent
A$9M savedwith risk-based approach
Investment Priorities (ranked by risk reduction per € spent)
1
Cloud-native IR playbooks (XSOAR)
Risks: R-001, R-004 · 60 days · soc, ir, secarch, vuln
17.8x ROI
A$180K → A$3.2M
2
Continuous compliance automation
Risks: R-005, R-012 · 90 days · compliance, grc, privacy
11.7x ROI
A$240K → A$2.8M
3
Vendor continuous monitoring upgrade
Risks: R-002, R-008 · 45 days · vendorrisk, appsec
15.8x ROI
A$120K → A$1.9M
4
Patch SLA acceleration (14d critical)
Risks: R-010 · 30 days · vuln, secarch
17.8x ROI
A$90K → A$1.6M
5
Security awareness refresh + phishing sim
Risks: R-009 · 30 days · awareness, soc
18.3x ROI
A$60K → A$1.1M
6
AI governance conformity assessment
Risks: R-007 · 120 days · aigov, appsec
9.3x ROI
A$150K → A$1.4M
A$840K
Total investment
A$12.0M
Risk reduction
14.3x
Overall ROI
Framework
8-step risk-based cybersecurity approach — implementation progress

Sequential actions to move from maturity-based to risk-based cybersecurity. Each step builds on the previous.

1
Embed in enterprise risk management ▾
Complete
Cyber risk integrated into ERM via ServiceNow GRC. Board receives quarterly risk reports.
95% complete
2
Define sources of business value ▾
Complete
5 crown jewels identified and valued. Business impact analysis maps threats to revenue impact.
90% complete
3
Understand the vulnerability landscape ▾
In Progress
Tenable + Wiz scan 93% of assets. Gap: 7% shadow IT unscanned. 347 vulns catalogued.
78% complete
4
Understand the threat landscape ▾
In Progress
Recorded Future + CrowdStrike TI feeds active. Threat profiles for 8 actor groups. Gap: no OT threat model.
72% complete
5
Link controls to vulnerabilities ▾
In Progress
10 control families mapped to 12 risk scenarios. Gap: 3 controls lack automated evidence.
65% complete
6
Map the risk ecosystem ▾
Partial
Risk register with 12 scenarios. Partial: cross-risk dependencies not yet modeled (e.g., supply chain + ransomware).
55% complete
7
Plot risk vs appetite ▾
Partial
Risk appetite statement approved. 4 risks exceed appetite. Gap: no automated breach alerting.
60% complete
8
Monitor with KRI/KPI pairs ▾
In Progress
8 KRI/KPI pairs defined. Real-time for 5, quarterly for 3. Target: all real-time by Q3.
68% complete
Risk Monitoring
8 linked KRI/KPI pairs — risk altitude meets risk trajectory

KRI measures where risk stands today (altitude). KPI measures whether it is moving toward or away from the appetite (trajectory). Together they answer: “Are we getting safer?”

Endpoint Security →
KRI · Risk Altitude
Unprotected endpoints
4.2%at limit
Target: < 2%
KPI · Risk Trajectory
EDR deployment velocity
12 endpoints/day▲
Target: 20/day
Vulnerability Mgmt →
KRI · Risk Altitude
Critical CVEs unpatched > 30d
12beyond
Target: < 5
KPI · Risk Trajectory
Patch SLA compliance
68%▲
Target: > 90%
Identity & Access →
KRI · Risk Altitude
Privileged accounts w/o MFA
5beyond
Target: 0
KPI · Risk Trajectory
MFA rollout completion
96%▲
Target: 100%
Incident Response →
KRI · Risk Altitude
MTTR (mean time to respond)
2.4hat limit
Target: < 1h
KPI · Risk Trajectory
Playbook coverage
12 of 15 scenarios▲
Target: 15/15
Third-Party Risk →
KRI · Risk Altitude
High-risk vendors
3 of 67beyond
Target: < 2
KPI · Risk Trajectory
Vendor assessment cadence
Quarterly▼
Target: Continuous
Compliance →
KRI · Risk Altitude
Non-compliant controls
17 of 287at limit
Target: < 5
KPI · Risk Trajectory
Evidence automation rate
64%▲
Target: > 90%
Data Protection →
KRI · Risk Altitude
PII in non-prod envs
3 instancesbeyond
Target: 0
KPI · Risk Trajectory
Data masking coverage
72%▲
Target: 100%
AI Governance →
KRI · Risk Altitude
Unregistered AI tools
7beyond
Target: 0
KPI · Risk Trajectory
AI inventory completion
80%▲
Target: 100%
Threat Landscape
Six threat actor groups ranked by capability and attack frequency
Control Architecture
Risk-based control tiers — higher-impact risks require more control layers

Risk-based control allocation: higher-impact risks require more control tiers. Baseline controls are "no regrets" moves applied universally.

Baseline ▾
All assets
AntivirusBasic access controlNetwork monitoringPatch management
A$0.5M
Tier 1 ▾
Medium-impact risks and above
EDR/XDREmail securityDLPVulnerability scanning
A$1.5M
Tier 2 ▾
High-impact and very-high-impact risks
SIEM correlationPAMNetwork segmentationIR playbooks
A$2.0M
Tier 3 ▾
Very-high-impact risks only
Advanced threat huntingRed team exercisesDeception technologyZero trust architecture
A$1.0M
Risk-to-Tier Mapping
R-001
Ransomware
Very high
Baseline Tier 1 Tier 2 Tier 3
R-002
Supply chain
High
Baseline Tier 1 Tier 2
R-005
SOCI Act non-compliance
High
Baseline Tier 1 Tier 2
R-010
Unpatched CVE
High
Baseline Tier 1 Tier 2
R-009
Phishing / BEC
Medium
Baseline Tier 1
R-004
Cloud misconfig
Medium
Baseline Tier 1
R-006
Credential stuffing
Low
Baseline
R-011
DDoS
Low
Baseline
Holistic Model
Six-layer cyber risk management model — from governance down to third parties

The holistic approach proceeds from top-management oversight through organizational structures, processes, and controls to the assets and third parties that create the attack surface.

Governance ▾
established88%
Organization ▾
established82%
Processes ▾
maturing75%
Controls ▾
maturing68%
Assets ▾
maturing72%
Third parties ▾
developing55%
Mitigation Path
Four-phase root-cause mitigation — identify, analyze, treat, monitor

The holistic approach lays out a path to root-cause mitigation of top risks in four phases. Each phase feeds the next in a continuous cycle.

1
Identify
▾
Identify top risks, risk appetite, and assess controls and vulnerabilities
Complete
2
Analyze
▾
Analyze and evaluate identified risks and their relevance to the organization
Complete
3
Treat
▾
Treat risks that exceed the organization's risk appetite
In Progress
4
Monitor
▾
Monitor risks and their relevance to the organization
In Progress
Maturity Journey
MusterSec is in the Advanced stage — transitioning from maturity-based to risk-based

The risk-based approach is the next stage in the cybersecurity journey. MusterSec has moved past foundational capabilities and is now implementing risk quantification and linked KRI/KPI monitoring.

Security not considered ▾
100%
Lack of capability and awareness throughout organization
Foundational ▾
100%
Build capabilities: SOC, IR playbooks, IAM, MFA, VPN
Build SOCIR playbooksIAM functionMFA on appsVPN
Advanced (current) ▾
72%
Risk-based: quantify risk, measure reduction, linked KRI/KPI pairs
Risk quantificationKRI/KPI monitoringRisk-based prioritizationControl-to-risk mapping
Proactive ▾
25%
Holistic resilience: next-gen detection, security by design, full ecosystem coverage
ML-powered detectionSecurity by designFull 3rd-party integrationAutomated response
Golden Thread
From the boardroom to the front line — every level connected to risk reduction
Data Architecture
Integrated data lake with 5 golden sources feeding real-time risk intelligence

Consistent cyber risk reporting requires an integrated data architecture. A consolidated data lake is filled directly from the organization’s golden sources, avoiding conflicting and inconsistent information.

Dashboard
8 data feeds
Real-time to quarterly
Data Lake
12.4M events/day
13 months retention
5 Golden Sources
Assets, Identity, People, Config, Vendors
Golden Sources
Applied Methodologies
Qualitative
Automated assessments
Vanta, ServiceNow GRC, KnowBe4 self-assessments
Quantitative
Value at risk (VaR)
FAIR methodology, Monte Carlo simulation, agent-generated risk scores
Risk Organization
3-element operating model: domain pods, nerve center, analytics CoE
Board Report
11-exhibit security brief with risk appetite and board actions
Agent Dashboard
Alex, Peter, Sarah, James, Maria — your team

Build this dashboard with your own risk data

We connect to your existing tools and build a risk-based view in weeks, not months. Read-only access. EU-hosted.

Get Your Free Assessment →