R · Risk
Know what could hurt you, and what it would cost.
A complete risk management platform: live register, structured assessments, AI-powered SWOT, configurable heatmaps, treatment plans, and continuous supplier monitoring via Black Kite.
Everything in the Risk bundle.
Cyber risk management is not one thing. The platform covers the full lifecycle: identify, assess, treat, monitor.
Risk register
A live canonical register of every identified risk: likelihood, impact, owner, treatment plan and lifecycle status. Risks are ranked by potential incident cost so you focus on what matters. Exportable to Excel, Word and PDF.
Risk assessments
Structured questionnaire-based assessments with document upload and AI-powered analysis. Responses feed directly into the risk register. Assessment history is retained for audit purposes.
SWOT analysis
AI-generated SWOT analysis specific to your business and security context. Weaknesses and threats automatically generate suggested risk register entries, so your strategic and cyber risk views are connected.
Risk heatmap
A 5×5 configurable heatmap that visualises your risk register by likelihood and impact. Likelihood and impact scale labels are customisable per tenant. Cell thresholds (Low/Moderate/High/Extreme) can also be adjusted.
Treatment plans and Action Hub
Every risk can have a structured treatment plan with individual actions, owners and due dates. The Action Hub surfaces all open actions across the register in one place, with overdue alerts and progress tracking.
Supplier risk (Black Kite)
Continuous outside-in monitoring of your supplier ecosystem. Black Kite generates risk scores, ransomware susceptibility ratings and financial impact estimates for every supplier, updated as threat intelligence changes, with no questionnaires to chase.
Risk register
Every risk. Owner assigned. Treatment tracked.
The register shows every identified risk in priority order. Click a risk to see its full detail: likelihood and impact scores, treatment plan with individual actions, linked ISO 27001 and SMB1001 controls, and the full audit history.
- Ranked by financial impact, not just score
- Treatment plans with per-action owners and due dates
- ISO 27001 and SMB1001 control mapping
- Export to Excel, Word or PDF for board reporting
Risk heatmap
See your whole risk landscape at a glance.
The 5×5 heatmap plots every risk in your register by likelihood and impact. Cells are colour-coded Low through Extreme using a scoring model you can configure. Each dot in the grid is a real risk: click it to open the full detail.
- Likelihood and impact scale labels are configurable
- Cell colour thresholds adjustable per your risk appetite
- Risks plotted live from the canonical register
- SWOT threats generate suggested register entries with one click
SWOT Analysis
Strategic risk, connected to your cyber register.
Most risk registers are a list of technical vulnerabilities with no connection to business strategy. CyberGrape connects them. The AI-generated SWOT analysis is built from your company context, security posture and assessment results. Threats flow directly into the risk register as suggested entries.
The result: a risk register that reflects both technical exposure and strategic risk, without maintaining two separate documents.
Build the context profile
The platform builds a company and security context profile from your SMB1001 assessment, asset register and existing risk data.
AI generates the SWOT
Claude analyses your profile and generates a SWOT specific to your business: not a generic template, but a view built from your actual posture.
Threats become risks
Each weakness or threat in the SWOT can be converted to a suggested risk register entry with pre-populated likelihood, impact and control mapping.
Third-party risk
Your suppliers are part of your attack surface.
Most breaches don't start with you. They start with a supplier who has poor controls, and access to your systems. The Risk bundle includes continuous supplier monitoring via Black Kite, so you know when a supplier's exposure changes, before it becomes your incident.
Black Kite scores suppliers from the outside: public signals, dark web monitoring, technical fingerprinting. No questionnaires to send. No chasing for responses. Just a live dashboard of supplier risk, ranked by financial impact to you.
Supplier scores update as threat intelligence changes, not just at your annual review.
Know which suppliers are most likely to be hit with ransomware, and what the financial cost to your business would be.
Build the formal programme required for SMB1001 Diamond (control 4.9.0.1): supplier classification, risk thresholds and monitoring cadence.
Supplier risk findings flow directly into the canonical risk register as register items, with owner assignment and treatment plans.
Black Kite's outside-in methodology means your suppliers don't need to do anything. No forms, no emails, no waiting.
Required for SMB1001 Diamond: control 4.9.0.1.
A formal digital trust programme, including supplier risk classification, monitoring and evidence of ongoing oversight, is required for SMB1001 Diamond certification. The Risk bundle is designed to satisfy this control and provide the auditable evidence your certifier needs.
Learn about SMB1001 certificationWhat is inside Cyber Risk.
Everything included when you subscribe to the Risk bundle on the CyberGrape Platform.
Common questions.
The risk register is a canonical log of every cyber risk your business has identified. Each entry records the risk title, category, likelihood, impact, owner, current treatment status, linked controls, and action plan. The register is live in the platform, not a spreadsheet that goes stale.
The platform generates a SWOT analysis from your business and security context profile. Every weakness and threat in the SWOT can be turned into a suggested risk register entry with a single click. The AI pre-fills the likelihood, impact, category and control mapping, so you just review and confirm.
The heatmap is a 5×5 grid that plots your risks by likelihood (rows) and impact (columns). Each cell is colour-coded Low, Moderate, High or Extreme. Both the likelihood and impact scale labels and the cell threshold scoring can be configured per tenant to match your risk framework.
Black Kite is a third-party cyber risk intelligence platform that provides continuous outside-in risk ratings for any organisation. It scores your suppliers across hundreds of technical and financial indicators using publicly available data, dark web monitoring and technical fingerprinting. Your suppliers don't need to install anything or fill in a questionnaire.
A digital trust programme (which includes supplier risk monitoring) is required for SMB1001 Diamond certification (control 4.9.0.1). Supplier risk monitoring is increasingly expected at Platinum tier and above, and is a common enterprise procurement requirement regardless of tier.
The Action Hub aggregates every open action across all risks in the register into one view. It shows the action, the linked risk, the owner, the due date and the current status. Overdue actions are surfaced prominently so nothing is forgotten.
Explore the other GRAPE bundles.
Governance
Expert security leadership without the full-time hire.
A senior security officer embedded in your business for a set number of hours each month — owning your programme, attending your board and turning cyber risk into decisions your leadership team can act on.
Advisory
Security leadership without the salary.
A senior security leader in your corner for a set number of hours each month. Someone who owns the plan, sits in the meetings that matter, and turns the technical into decisions you can actually make.
Protection
Watched, defended and backed up.
The day to day defending. Someone is watching your systems around the clock, so a problem at two in the morning gets handled at two in the morning rather than discovered on Monday.
Education
Turn your team into the first line of defence.
Most incidents start with a person, not a firewall. This is the bundle that changes behaviour, in short pieces people will actually finish rather than an annual video nobody watches.
Know every risk. Own every action.
Get started and have your first risks assessed and plotted on the heatmap within your first week.

