Explainable cyber risk scoring · for regulated industries

Cisco sorted the to-do list.
RiskPrism scores the actual risk.

One explainable score per asset. Graded A to F, priced in dollars, defensible to any board or auditor.

Your board does not want a longer list. It wants to know which handful of things actually put the business at risk, and what the exposure is worth in dollars. RiskPrism answers both with FARS, our Final Adjusted Risk Score, and shows its working.

  • WhatA scoring layer on top of the scanners you already run, not another scanner.
  • WhoBanks, healthcare, government, and regulated enterprises.
  • SolvesTurns thousands of scanner findings into one defensible, dollar based priority.

Keep the scanners you already run. No rip and replace. SaaS, on-prem, or fully air-gapped.

0 vulnerabilities
F
0
E
0
D
0
C
0
B
0
A
0
One methodology. A full spectrum of actionable risk.
FEDCBA

47,000 findings in. One clear order of what to fix, graded F to A.

47,000 to 12
findings reduced to a first fix list, in the live demo dataset below
$ per asset
every exposure priced in dollars, so the board decides on cost, not counts
9 packs
industry weightings and regulatory floors, from banking to OT
0 black boxes
every score decomposes to the finding that drove it
Why RiskPrism

The outcomes security leaders actually buy.

RiskPrism is not a scanner, a dashboard, or a CMDB. It is the scoring layer that sits on top of the tools you already run, so the thousands of findings underneath become a short, defensible list of what matters.

Risk in dollars, not counts

Every exposure carries an ALE figure. Leadership sees the financial consequence of leaving something unfixed instead of a spreadsheet with 47,000 rows.

A score you can read

FARS scoring gives you end-to-end transparency. Every FARS grade decomposes across organization, tier, asset, and CVE, so a CISO can show an auditor exactly why an asset scored what it did. No black box.

A hospital is not a bank

An infusion pump and a payment gateway fail in very different ways. Each industry pack weights confidentiality, integrity, and availability to match, and gives credit for the controls you have already deployed.

Scanner neutral by design

We sell no scanner. RiskPrism scores whatever you already run, so the ranking reflects your risk, not a vendor's catalog. Swap tools underneath and the score still holds.

The compliance view

Hand the auditor evidence, not screenshots

Every score carries the trail behind it, mapped to the framework you report against, and it ties back to the same dollar figure leadership saw. When the auditor asks why an asset was prioritized, the answer is already there in numbers, not a folder of screenshots.

score → evidence → framework, in dollars
Early access

Currently in pilot with select financial institutions

We are running guided pilots with a small group of banks and regulated organizations right now. Join the early access programme and we will score a representative slice of your environment so you can judge the output on your own data.

Join the early access programme
How it works

From scanner noise to a board decision, in five steps.

The overview before the detail. Every step is explainable, and nothing here replaces the tools you already run.

  1. 1

    Ingest

    Pull findings from Qualys, Tenable, Rapid7, cloud posture, IdP, and CMDB.

  2. 2

    Score

    FARS normalizes, weights by industry, and credits your controls. One score per asset.

  3. 3

    Prioritize

    Rank by real risk and dollar exposure, with your industry regulatory floors applied.

  4. 4

    Route

    Push the ranked queue to Jira and ServiceNow, with an owner on every item.

  5. 5

    Report

    Board-ready posture and audit-ready score lineage, on demand.

You keep discovery and remediation in the tools you own. RiskPrism is the scoring and prioritization layer in the middle.

Live Demo

Build a risk score. Watch it come apart.

Pick an industry pack and an asset, set the exploit signals, and switch on the controls you have in place. The score updates as you go, and every layer that produced it stays visible.

Scenario inputs

Adjust the signals. Everything recalculates as you move.

FCritical
487 / 500 FARS
Score 350 to 500, top of the stack
Estimated annual loss exposure about $4.2M

Why this score, layer by layer

Plain-English narrationAI Narration

RiskPrism can explain this score the way you would brief a board. Generate a short, plain-English summary of the breakdown above.

This is an illustrative model built to show how the methodology works. It is not the production scoring formula, which is proprietary and held stable across releases. Real scoring runs the full WAV to BRS to TAS to FARS to TRS to ORS chain.

How it fits

We do not replace your scanners. We make them make sense.

Your scanners are good at finding things. RiskPrism sits above them, reads what they find, and turns it into one score you can defend. Keep every tool you have.

DATA IN DECISIONS OUT
01
SOURCES
Your existing tools keep running
NO RIP & REPLACE
Qualys Tenable Rapid7 EDR IdP CMDB Cloud posture
FINDINGS FLOW IN
CVE-2026-21412 · Critical · Qualys
02
ENGINE
THE INTELLIGENT LAYERING METHODOLOGY BEHIND FARS

Normalize, weight, and score once

We deduplicate findings across every source, apply your industry pack, credit the controls you run, and produce one transparent score per asset.

FARS
ONE SCORE
WAVWeighting BRSBase risk TASThreat adj. FARSFinal score TRSTier rollup ORSOrg rollup
CLARITY FLOWS OUT
PAY-DB-07 at Grade C · $840K exposure
03
OUTCOMES
What your board and auditor see
DELIVERED VIA JIRA · SERVICENOW · SLACK · EMAIL · PDF
Fix these firstRanked remediation queue
Grade per assetA to F, defensible
Loss in dollarsFinancial exposure
Board reportingOne-page posture
Audit evidenceTraceable scoring

Moving to a scanner vendor's own platform means one company both finds and scores your risk. RiskPrism does not sell a scanner, so it stays neutral and works with all of them.

Explainable where others are opaque Dollars where others count severities Neutral where scanners score themselves
CapabilityRiskPrismOrchestration layers (Nucleus, Brinqa)Scanner-native scores (TruRisk, VPR)
Regulatory floor enforcement per industryYes, pack-defined floorsRule-based, build it yourselfNot a native concept
Loss expressed in dollarsYes, ALE on every assetVaries by product and setupNo, severity scores only
Explainable score decompositionYes, every layer visiblePartial, depends on configurationProprietary, largely opaque
Industry pack configurationYes, nine packsGeneric, manual tuningOne model for all industries
Multi-tenant MSSP architectureYes, native tenant isolationVariesPer-customer licences
Air-gapped and on-prem deploymentYesMostly SaaSMostly SaaS
Scanner neutralityYes, we sell no scannerYesNo, scores favour own findings

Competitor characteristics are stated in general terms and vary by edition and configuration. Verify against current vendor documentation for your shortlist.

Industry Packs

One engine. A pack for every industry you serve.

The scoring engine is the same everywhere. Each pack changes the weighting, the risk floors, and the language so the score reflects how that industry actually fails.

One RiskPrism scoring engine
In practice

What changes, by industry.

Anonymized from the regulated environments we work in. We show the pattern, not the customer, because early pilots run under NDA.

Where we are today. RiskPrism is in guided pilots with select financial institutions, and we are onboarding a small number of additional regulated organizations. You will not find customer logos here yet, by design, because early pilots run under NDA. In an evaluation we score a representative slice of your own environment, so you judge the output on your data, not ours.

Leaving Cisco Vulnerability Management (Kenna)

Do not trade independence for a scanner's badge.

Kenna's whole point was staying scanner-agnostic. The obvious replacements are scanner vendors who want you on their platform and their score. There is a better move.

Mar 10, 2026
End of sale
Jun 11, 2026
Last day to renew
Jun 30, 2028
Support ends
Frozen
No CVSS 4.0 or EPSS v4

Tenable, Qualys, and Rapid7 will each offer transition credits and a migration playbook. The catch is the same in all three: the vendor that finds your vulnerabilities also scores them, and each score (VPR, TruRisk, Real Risk) stays a black box. You give up the neutral, scanner-agnostic layer that made Kenna worth running.

1

Keep

Leave your scanners exactly where they are and connect them to RiskPrism.

2

Map

Translate your Cisco Security Risk Score history so your Top-N stays familiar.

3

Prove

Run in parallel with Kenna and review the Risk Parity Report together.

4

Switch

Cut over when you are ready, on your date. No big-bang weekend.

For MSSPs

Run a risk practice under your brand, not ours.

RiskPrism is multi-tenant from the ground up. Onboard a client in hours, keep every tenant isolated, and put your name on the reports.

Native multi-tenant

Each client gets its own dashboard, scoring history, and audit trail, with per-tenant encryption keeping every tenant's data isolated.

White-label by design

Your brand, your styling, your SLA. Clients see your practice, and we run the engine underneath it.

Hours to onboard

Config-driven tenant setup means a new client goes from contract to scored assets in hours, not the weeks a custom build takes.

Early voices

What early access participants say.

We finally stopped arguing about severity counts. The dollar figure next to each system changed the conversation with our practice leadership in one meeting.
RobertRaymond Zhou MD PC
The score comes with its reasons attached. When our compliance reviewer asked why a clinical system ranked where it did, we opened the trace and walked through it line by line.
JoyceNortheast Medical
We kept our scanners and our workflow. RiskPrism sat on top and the ranking it produced matched what our senior testers would have picked by hand, with the evidence to prove it.
PaulGreen Armory Labs

Shared with permission from early access participants.

Take it for a test drive

See your own risk, scored.

Send this over and we will set up a working session on a representative slice of your environment. No slideware.

  • A live scoring run on a real asset type from your world
  • A Risk Parity Report if you are leaving Kenna
  • The industry pack that fits you, with the floors that matter
Thanks. Your test-drive request is on its way to our team, we will be in touch shortly.
We could not send your request just now. Please try again in a moment, or email demo@cynetica.com directly.

Submitted securely to the RiskPrism CRM, which alerts the sales team by email.