Skip to content
Risk model

Risk model

The evaluation chain links controls to resources and findings to benchmarks. A control is a security check that evaluates a single resource for one specific condition, such as whether a device has default credentials or runs outdated firmware. The platform ships a library of controls covering common OT security concerns.

At each snapshot, the control evaluator runs every applicable control against every resource. When a control check matches a resource, the resource fails that check. The result is a finding. A finding ties together the control that triggered it, the resource it applies to, a rationale explaining why this is a problem, and a remediation describing how to fix it.

A finding showing control rationale and remediation

Findings can be muted. When you mute a finding, you provide a reason. The platform records who muted it and when. Muted findings remain visible in the resource and the findings queue, but the control they belong to counts as passed for scoring purposes, the same as if the resource had never failed it.

A benchmark maps a set of controls onto the requirements of a compliance framework. The platform ships several benchmarks. These include ISA/IEC 62443-3-3 and CIS Controls for Industrial Control Systems (v8.1). You can measure compliance against ENS (Esquema Nacional de Seguridad) at Low, Medium, and High levels. Additional benchmarks cover NIS2, NIS2 Slovakia, and MITRE ATT&CK for ICS. The platform also supports ISO/SAE 21434:2021, NIST Cybersecurity Framework 2.0, TISAX, and CCN-STIC 892.

A compliance score is computed from the findings of its controls. Every control the benchmark references counts once towards the total, regardless of how many requirements it satisfies, and passes unless it has an active finding. Some requirements ask for evidence instead: a document or a note showing how you meet them. These count towards the total too, and pass once you upload evidence for them. The score is the share of all of those, controls and evidence requirements together, that pass.

Controls are re-evaluated at each snapshot. Between snapshots, findings and scores do not change. See Snapshots and change detection for details on the refresh cadence.