Remediation measures
Remediation measures form the treatment plan for the identified risks. This tab lets you generate, consult and enrich the list of measures to be implemented on your project.
Generate the measures
Click the Generate button to launch generation by the AI. It relies on the risks identified in the previous step, as well as the measure catalogues assigned to the project (for example MITRE ATT&CK, ISO 27002, etc.).
As on all Generate buttons of the platform, the magic wand (targeted generation) and the generation history are available here. Learn more
Measures table
Measures are presented in a summary table:
| Column | Content |
|---|---|
| ID | Unique identifier of the measure |
| Description | Measure label |
| Category | Functional family of the measure |
| Cost | Low / Medium / High / Very high |
| Impact | Low / Medium / High / Very high |
| Stakeholders | Actors responsible for the measure |
| Implementation status | Implemented / Not implemented / In progress |
| Actions | Edit, Delete, Details |
Available stakeholders
Stakeholders represent the actors responsible for the implementation or monitoring of the measure. Some examples:
- Business Owner
- Development Team
- DevOps Team
- Executive Management
- External IT Provider
- Hosting / Cloud Provider
- Infrastructure Team
- Operations Support Team
- Regulatory Authority
- Security Team
This list is configurable in the organisation settings. You can therefore adapt the labels to the structure of your company.
Implementation statuses
The status reflects the progress of the measure on the project:
- Implemented — the measure is in place and operational
- In progress — the measure is planned or being deployed
- Not implemented — the measure is identified but not yet put in place
The status is taken into account in the calculation of the analysis current matrix: only implemented measures (or in progress, depending on the organisation's configuration) reduce the position of the risk.
View the details of a measure
The Details action opens a side panel organised in several sections.
Summary section
This section recalls the key information of the measure:
- Category
- Implementation status
- Expected impact
- Estimated cost
Associated risks section
The section lists the risks on which the measure acts. For each associated risk, you will find:
- Justification — why the measure is relevant for this risk
- Probability reduction rate — for example
−30 % - Impact reduction rate — for example
−20 %
These rates are editable directly from the panel, to refine the residual risk assessment based on your real context.
| Risk ID | Justification | Probability reduction | Impact reduction |
|---|---|---|---|
R-014 | Encryption at rest makes data unreadable in case of unauthorised access to the database | −30 % | −20 % |
R-022 | MFA blocks the majority of identity theft attempts | −50 % | −10 % |
Values are editable directly from the side panel.
Catalogue reference
When the measure comes from a catalogue assigned to the project, its reference is displayed in the details (for example MITRE ATT&CK ENT-M1030). This lets you easily find the original record to consult its full recommendations.
Associate a measure with an additional risk
The same measure can address several risks. From the Details panel, you can manually add an additional association with another risk, then enter the corresponding justification and reduction rates.
Adjust the reduction rates throughout the analysis. The values suggested by the AI are a starting point, but your field knowledge often allows them to be refined to obtain a more realistic view of the residual risk.
Move to the next step
Once the measures are validated, move to the Analysis summary tab to view the risk matrices and drive your treatment plan.