Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Risk Composition Widget

Prev Next

The Risk Composition widget breaks down the financial structure of your cyber risk, giving you visibility into how much risk exists at each stage of your security posture. It shows the maximum possible impact of a breach, followed by the inherent risk (before any controls), post-mitigation risk (after applying current controls), and residual risk (after accounting for all known mitigations and compensating factors). This helps you understand not just your current exposure, but how much risk your controls are actively reducing.

  • Breach Impact is the estimated financial loss your organization would face if a significant security incident were to occur, assuming no controls are in place. It represents the worst-case scenario in terms of business disruption, data loss, regulatory penalties, and recovery costs. This value sets the upper boundary of your potential risk.

  • Inherent Risk is the level of risk present before any security controls or mitigations are applied. It reflects the raw exposure based on factors such as asset value, existing vulnerabilities, and threat landscape. This number helps you understand how risky your environment is in its unprotected state.

  • Post Mitigation Risk shows the amount of risk remaining after accounting for your current set of security controls. It includes the risk that persists even with preventive measures like patching, network segmentation, or endpoint protections in place. This value lets you see how much your controls are reducing your exposure.

  • Residual Risk represents the final level of risk after considering all known mitigations, compensating controls, and risk transfer strategies. This is the risk your organization still carries and must either accept or further reduce through additional measures. In many cases, post mitigation and residual risk will be equal, unless there are unmodeled factors or risk acceptance decisions in place.

You can use this widget to evaluate the effectiveness of your mitigation strategies. The gap between inherent risk and post-mitigation risk shows the risk reduction achieved through deployed controls. A large gap suggests your existing defenses are reducing risk significantly, while a small gap might indicate that additional controls are needed or that current ones aren’t effective. The residual risk value represents the risk that remains even after all mitigations—this is the risk you must accept, transfer, or treat further.

This breakdown also supports conversations with leadership and auditors by providing a clear, quantifiable picture of your organization's security posture. You can use it to justify investments in new controls, demonstrate the value of existing measures, or highlight areas where further action is needed. It enables more strategic decision-making by tying control effectiveness directly to measurable reductions in financial risk.

See Also:

Create Widgets