Skip to main content
KeenSafe
Pillar · AI Risk Engine

Risk weighted by exploitability, blast radius and business impact

A risk engine designed for paths, not points. Every validated chain scored by how attackers actually monetise it — not by raw vulnerability number.

  • Defensible to auditor + insurer
  • Crown-jewel-weighted
  • Compensating-control-aware
  • Evidence-traceable
LiveRisk Engine · AI Scoring
9278648871419635AI ENGINEEXPLOITABILITY × BLAST RADIUS × BUSINESS IMPACT
The problem

Vulnerability scoring is not risk scoring

CVSS scores a single vulnerability in isolation. EPSS scores exploit-in-the-wild probability. Neither answers: "If exploited in this environment, how much damage does it actually cause?"

Boards, insurers and regulators want business-impact-weighted risk. Most platforms cannot produce it.

The KeenSafe approach

Risk that boards, insurers and regulators recognise

KeenSafe scores every validated path on three axes: exploitability (proven, not theoretical), blast radius (what the path reaches) and business impact (financial, regulatory, operational, reputational).

Each axis is grounded in evidence — not opinion. The output is a single risk number that defends itself in front of an auditor or insurer.

Capabilities

What ships in this engagement

Exploitability

Validated by autonomous + manual replay. Theoretical CVSS does not factor in.

Blast Radius

How many systems, identities and datasets the path reaches if traversed.

Business Impact

Per-crown-jewel financial, regulatory, operational and reputational modelling.

Compensating Controls

Detection, response and recovery efficacy reduce score where validated by replay.

Crown-Jewel Weighting

Asset criticality drives impact; criticality is owned by the business, not security.

Insurance + Audit Mode

Output template formats accepted by major insurers, regulators and audit firms.

Attack path

How attackers actually move

Two paths might share an entry CVE. One reaches crown-jewel PII; the other reaches a test sandbox. Same CVE, very different risk. The engine scores them differently because the chain — not the link — drives risk.

Validated chain

Same CVE, different risk

CVE2024XXXX exploited on system A (reaches PII) vs system B (reaches sandbox)
Business impact

System A: $4.2M expected loss; System B: $0.05M. Same CVE.

Validated chain

Compensating controls reduce score

Path B exploits same CVE as Path A but EDR detection blocks lateral move within 90s
Business impact

Validated control efficacy reduces residual risk by 78%

Outcomes

Measurable, evidence-backed

60%
Less noise

Risk-weighted prioritisation removes work that does not move the needle.

Per-path
Risk score

Every validated path carries its own exploitability × blast × impact score.

Insurer-ready
Output

Native formats for major cyber insurers and reinsurers.

Defensible
In audit

Score rationale traces to evidence; no opaque AI black-box.

For the board

A risk number that defends itself

Most CISOs spend disproportionate energy defending the risk number to the board, the auditor or the insurer. KeenSafe makes the score defensible by construction — every component is evidence-backed and reproducible.

The conversation moves from "trust the number" to "let me walk you through how we got it".

Technical validation

Inside the engine

For each validated path, the engine assembles evidence-backed inputs across the three axes, applies environment-specific weights and produces a residual-risk number. AI is used for scoring synthesis, not for opaque prediction.

  1. 01
    Exploitability: derived from autonomous + manual replay results
  2. 02
    Blast radius: derived from path graph (assets, identities, datasets reached)
  3. 03
    Business impact: derived from crown-jewel inventory + business-stated impact weights
  4. 04
    Compensating controls: derived from purple-team detection efficacy results
  5. 05
    Final score: residual-risk after controls; full rationale exposed for audit
Get Started

See risk scored end-to-end

A guided session walks through one path scored across all three axes — exploitability, blast radius, impact.