KCF–CRIF · Cyber Risk Intelligence Framework

Cyber Risk Intelligence for the Enterprise.

Transform fragmented cyber data into a continuously updated view of threats, vulnerabilities, business exposure and remediation priorities.

The intelligence equation

Threat intelligence

+ Enterprise context

+ Business impact

+ Regulatory context

= Cyber risk intelligence

Decision frame

Five questions every enterprise must answer.

  1. 01

    What cyber threats are relevant to this enterprise?

  2. 02

    Which assets, suppliers, identities, applications and business processes are exposed?

  3. 03

    What would happen to the business if those threats materialised?

  4. 04

    What should management prioritise and invest in?

  5. 05

    Is cyber risk improving or deteriorating over time?

The framework

Eight connected layers. One decision system.

01

Global cyber intelligence

What is changing across threats, vulnerabilities, campaigns and regulation?

02

Enterprise exposure

Which assets, identities, suppliers, applications and processes could be affected?

03

Threat-to-asset mapping

Which threats can realistically exploit the enterprise?

04

Business criticality

What happens when an exposed asset or process is compromised?

05

Control effectiveness

Can the organisation prevent, detect, respond and recover?

06

Financial & operational risk

What is the plausible enterprise impact?

07

Recommended action

What should management prioritise and invest in now?

08

Continuous cyber-risk digital twin

How is the organisation’s risk posture changing over time?

Intelligence modules

Technical signals, translated into enterprise action.

Threat & exposure intelligence

Correlate external intelligence, active exploitation and enterprise exposure.

Attack-path intelligence

Connect likely entry paths to identities, assets, processes and consequences.

Business impact

Translate technical findings into operational, financial and regulatory exposure.

Controls & resilience

Assess prevention, detection, response, recovery and evidence quality.

Third-party risk

See supplier concentration, dependencies, incidents and inherited exposure.

Regulatory intelligence

Map changing obligations to assets, controls, evidence and remediation.

Prioritised remediation

Rank action by threat probability, exploitability, criticality and control weakness.

Executive reporting

Turn intelligence into board, CISO, maturity and investment reports.

KCF–CRIS

0–1000

The proposed KCF Cyber Risk Intelligence Score is a weighted intelligence model—not a simple questionnaire score. Industry-specific weights remain configurable.

Cyber maturity

How developed and effective are the controls?

Cyber exposure

How exposed is the organisation to relevant threats?

Cyber resilience

Can critical operations continue and recover?

Role-based intelligence

One risk picture, shaped for each decision-maker.

Board & Audit Committee

Enterprise exposure, risk appetite, resilience, investment priorities and accountability.

CEO & Business Leadership

Critical services, disruption, revenue at risk, customers and transformation priorities.

CISO & Security Operations

Threats, vulnerabilities, attack surface, incidents, remediation and ATT&CK coverage.

CIO, CTO & CDO

Infrastructure, cloud, identity, applications, APIs, data and software supply chains.

CFO

Cyber-loss exposure, scenario ranges, insurance, control ROI and expected-loss reduction.

Risk & Compliance

Regulatory mappings, evidence, control gaps, audit findings and remediation progress.

Evidence & governance

Traceable intelligence. Human-approved action.

Every important assertion should show its source, freshness and confidence. The framework separates facts, observations, inferences and AI recommendations. AI recommends; a human approves; authorised security tools execute.

NIST CSF 2.0MITRE ATT&CKCISA KEVCVSS 4.0ISO/IEC 27001:2022

Adoption path

  1. Questionnaire onlyLevel 1
  2. Questionnaire + evidenceLevel 2
  3. Asset uploadLevel 3
  4. API integrationsLevel 4
  5. Continuous intelligenceLevel 5

Start with context

Know what can attack you. Know what matters. Know what to fix first.

Home