Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Risk Settings

Prev Next

You can find these options in the Risk Settings menu.

What You Can Do Here

  • Review the organization’s CRQ readiness using the CRQ Readiness Check.

  • Launch and complete the Readiness Self-Assessment covering Inventory Coverage, Entity Categorization and Tagging, and Exposure Assessment Fidelity.

  • Edit enterprise-level risk valuation using the Edit Enterprise Impact section.

  • Configure risk impact categories including Incident & Response Costs, Data Recovery & Restoration Costs, Business Interruption Costs, Fines, Legal & Defence Costs, Financial Fraud, Physical Damage Costs, and Indirect Losses.

  • View and validate predefined assumptions in the Cost Assumptions List.

  • Review consolidated financial impact estimations in the Impact Details section.

  • Set organizational impact values using the Set Impact control.

  • Perform a detailed control maturity evaluation using the Maturity Assessment tool.

  • Select specific controls such as Entity Management and User Management for evaluation and configuration.

You can also see the walkthrough in this link

Risk Settings

In Risk Settings, you can configure the parameters that will determine the way CRQ calculates impact.

These are the modules you can configure:

  • CRQ Readiness Check

  • Impact Settings

  • Assessment

  • Other Settings

CRQ Readiness Check

CRQ Readiness Check is a non-binding questionnaire to assess readiness for CRQ. You are required to check if the following has been implemented:

Inventory Coverage: Indicate if enterprise asset, application, and user inventory is sufficiently comprehensive and accurate to enable appropriate coverage for key risk scenarios.

Entity Categorization and Tagging: Indicate if enterprise asset, application, and user inventory has been accurately categorized and assigned sufficient context (tags and roles) to specify key risk scenarios.

Exposure Assessment Fidelity: Indicate if exposure assessment across vulnerabilities, categorizations, and other findings is sufficiently comprehensive, accurate, prioritized, and timely to provide an effective view of the enterprise security posture.

Edit Enterprise Impact

In this section, you can configure the following variables:

Groups

  • Currency

  • Industry type

  • Number of customers

  • Number of annual working days

  • Headquarters country

  • Annual revenue

  • Number of employees

Enter Firmographics

  • Incident and Response Costs

    • Notificant Costs

    • Credit Monitoring Costs

    • Card Replacement Costs

    • Forensic Investigation Costs

    • Public Relations Cost

    • Average Employee Training Costs

    • External Cyber Experts Cost

  • Data Recovery & Restoration Costs

    • Ransom Payment Costs

    • Data Restoration Costs

  • Business Interruption Costs

    • Business Downtime Costs

  • Direct Loss of Funds Costs

    • Monetary Theft

  • Fines

    • PCI Non-Compliance Fine

    • PHI Non-Compliance Fine

    • PII Non-Compliance Fine

    • GDPR Fine

    • Other Regulatory Fine

  • Legal & Defence Costs

    • Legal Guidance & Defence Costs

    • PCI Consumer Settlement Costs

    • PHI Consumer Settlement Costs

    • PII Consumer Settlement Costs

  • Financial Fraud

    • Fraud Reimbursement Costs (Customer)

  • Physical Damage Costs

    • Endpoint Replacement Costs

    • Server Replacement Costs

  • Indirect Costs

    • Cyber Security Investment Costs

    • Customer Churn Costs

Cost Categories

  • Notification cost per customer

  • Credit monitoring cost per customer

  • Card replacement cost per customer

  • Average daily forensic team cost

  • Average daily external PR team cost

  • Average security awareness cost

  • Average daily external cyber team cost

  • Average daily data restoration team cost

  • Average daily external legal team cost

  • Number of days forensics team is required for

  • Number of days external cyber team is required for

  • Number of days data restoration team is required for

  • Number of days legal team is required for

  • Number of days PR team is required for

  • Cost per PII record

  • Average endpoint repair cost

  • Average server repair cost

  • Percentage of endpoints affected

  • Percentage of servers affected

  • Percentage of customers affected in scenario

  • Number of days downtime

  • Percentage of fine

  • Percentage of customers churn

Perform Control Maturity Assessment

You can set the maturity level for the following controls:

  • Entity Management

  • Business Continuity and recovering planning

  • Data Protection

  • Exposure Management

  • Deception Technologies

  • Endpoint Security

  • Secure Configuration Management

  • Compliance

  • Continuous Monitoring

  • Identity and Access Management

  • Incident Response and Prevention

  • Log Management

  • Capacity and Performance planning

  • Human Resource Security

  • Cyber Insurance

  • Third Party Management

  • Project and resource management

  • Risk Management

  • Secure Engineering Architecture

  • Network Security

  • DDoS protection

  • Change Management

  • Email gateway security

  • Privileged Account Management

  • AI Risk Management

The possible Maturity Levels are:

  • Not implemented

  • Initial (Ad hoc)

  • Repeatable (Managed)

  • Defined (Standardized)

  • Managed (Monitored & Measurable)

  • Optimized (Continuous Improvement)

Set Risk Appetite

Coming soon