Same CVE, different risk
System A: $4.2M expected loss; System B: $0.05M. Same CVE.
A risk engine designed for paths, not points. Every validated chain scored by how attackers actually monetise it — not by raw vulnerability number.
CVSS scores a single vulnerability in isolation. EPSS scores exploit-in-the-wild probability. Neither answers: "If exploited in this environment, how much damage does it actually cause?"
Boards, insurers and regulators want business-impact-weighted risk. Most platforms cannot produce it.
KeenSafe scores every validated path on three axes: exploitability (proven, not theoretical), blast radius (what the path reaches) and business impact (financial, regulatory, operational, reputational).
Each axis is grounded in evidence — not opinion. The output is a single risk number that defends itself in front of an auditor or insurer.
Validated by autonomous + manual replay. Theoretical CVSS does not factor in.
How many systems, identities and datasets the path reaches if traversed.
Per-crown-jewel financial, regulatory, operational and reputational modelling.
Detection, response and recovery efficacy reduce score where validated by replay.
Asset criticality drives impact; criticality is owned by the business, not security.
Output template formats accepted by major insurers, regulators and audit firms.
Two paths might share an entry CVE. One reaches crown-jewel PII; the other reaches a test sandbox. Same CVE, very different risk. The engine scores them differently because the chain — not the link — drives risk.
System A: $4.2M expected loss; System B: $0.05M. Same CVE.
Validated control efficacy reduces residual risk by 78%
Risk-weighted prioritisation removes work that does not move the needle.
Every validated path carries its own exploitability × blast × impact score.
Native formats for major cyber insurers and reinsurers.
Score rationale traces to evidence; no opaque AI black-box.
Most CISOs spend disproportionate energy defending the risk number to the board, the auditor or the insurer. KeenSafe makes the score defensible by construction — every component is evidence-backed and reproducible.
The conversation moves from "trust the number" to "let me walk you through how we got it".
For each validated path, the engine assembles evidence-backed inputs across the three axes, applies environment-specific weights and produces a residual-risk number. AI is used for scoring synthesis, not for opaque prediction.
A guided session walks through one path scored across all three axes — exploitability, blast radius, impact.