Skip to main content

My first risk analysis

This tutorial walks you through every step, from creating a project to exporting a report. By the end, you will have carried out a complete risk analysis: you will have created a project, qualified it, run the AI-assisted risk analysis, handled the risks and exported a deliverable.

The workflow unfolds in three main phases: Qualification → Risk analysis → Architecture review. The architecture review is not available yet, so this tutorial covers the first two phases, which are enough to produce a usable report.

info

No prior knowledge of the tool is required to follow this tutorial. There is only one prerequisite: being attached to an organisation. If that is not the case, start with the Login and first access page.

Step 1 — Create your project

From the project list (Projects in the left-hand menu), click Create a project. A window opens and asks you to fill in:

  • the project Name;
  • a Description (general context);
  • the Lifecycle (project status);
  • the Dependency type (Infrastructure or Service);
  • the project Language.

Once the form is validated, you are automatically redirected to the project detail page. This is your control hub for everything that follows.

note

Going further See the Create a project page for details on each field.

Step 2 — Assign a measure catalogue

From the project detail page, click Measure catalogues. Choose a catalogue (for example MITRE ATT&CK Enterprise), then click Assign.

This catalogue will serve as the basis for the remediation measures the AI proposes at the end of the journey: it defines the reference framework to draw measures from. You can assign several if more than one framework is relevant to your project.

note

Going further See the Measure catalogues page.

Step 3 — Start the qualification

From the project's Overview tab, in the Workflow widget, click Start on the Qualification block.

Qualification is used to frame the project before the analysis: the more precisely you describe your context, the more relevant the AI generations will be. It runs in three sub-steps.

3a — Fill in the scoping cards

Describe the project context in the free-text field: architecture, scope, business and technical stakes. Then import any useful documents (diagrams, specifications, procedures).

Finally, link the project's structuring elements:

  • the assets — manually from the organisation catalogue, or via AI generation;
  • the processes — manually or via AI generation.
tip

The richness of this information directly determines the quality of all subsequent AI generations. This is the step worth spending the most time on.

3b — Answer the questionnaire

Launch the automatic completion by AI, or answer the twenty or so questions manually. Either way, review and adjust the answers: they feed the assessment of risk factors.

3c — Generate the summary

Click Generate to obtain the overall risk level along with the DICT levels (Availability, Integrity, Confidentiality, Traceability), each with its justification.

This is the first time you encounter a Generate button in the journey. Two cross-cutting features accompany it everywhere on the platform:

  • the magic wand, to relaunch a targeted generation on a specific element;
  • the generation history, to find and compare previous versions.
info

As with every Generate button on the platform, you have access here to the magic wand (targeted generation) and the generation history. Learn more

note

Going further See the Pre-qualification section: Introduction, Scoping cards, Questionnaire and Qualification summary.

Step 4 — Start the risk analysis

At the bottom of the qualification summary (or from the Workflow widget), click the button to launch the risk analysis.

4a — Check the initialisation

Verify that the elements from the qualification are correctly carried over: DICT levels, linked assets and linked processes. If needed, adjust the analysis Settings by choosing the mode (Standard, Synthetic or Detailed).

4b — Generate the feared events

Click Generate to obtain the list of feared events — the undesirable impact scenarios. Then review the list: modify, delete or add events, and open the detail of each one (impacts, linked processes, comments).

4c — Generate the risks

Click Generate to produce the risks from the feared events. For each risk, check the criticality, review the detail (risk sources, likelihood, impact) and choose a treatment: Reduce, Avoid, Accept or Transfer.

4d — Generate the remediation measures

Click Generate to obtain the remediation measures, built from the risks and the catalogue assigned in Step 2. For each measure:

  • assign one or more stakeholders;
  • set an implementation status;
  • adjust the likelihood and impact reduction rates if needed.

4e — Review the analysis summary

Examine the risk matrices (gross, current, target) to visualise the effect of the measures on your exposure. Click a matrix cell to display the associated risks.

note

Going further See the Risk analysis section: Analysis settings, Initialisation, Feared events, Risks, Remediation measures and Analysis summary.

Step 5 — Export your report

From the project's Reports tab, export the deliverable in Word or Excel format. The report gathers, among other things, the risk register, the remediation plan and the summaries produced throughout the journey.

Recap

You have just carried out a complete risk analysis:

  1. Creation of the project and assignment of a measure catalogue;
  2. Qualification: scoping cards, questionnaire, summary;
  3. Risk analysis: feared events, risks, measures, summary;
  4. Report exported.
tip

A risk analysis lives alongside your project. Come back regularly to update the implementation status of your measures: the current matrix will evolve as work progresses, letting you concretely track the reduction of your risk exposure.