Cisco sorted the to-do list.
RiskPrism scores the actual risk.
One explainable score per asset. Graded A to F, priced in dollars, defensible to any board or auditor.
Your board does not want a longer list. It wants to know which handful of things actually put the business at risk, and what the exposure is worth in dollars. RiskPrism answers both with FARS, our Final Adjusted Risk Score, and shows its working.
- WhatA scoring layer on top of the scanners you already run, not another scanner.
- WhoBanks, healthcare, government, and regulated enterprises.
- SolvesTurns thousands of scanner findings into one defensible, dollar based priority.
Keep the scanners you already run. No rip and replace. SaaS, on-prem, or fully air-gapped.
47,000 findings in. One clear order of what to fix, graded F to A.
The outcomes security leaders actually buy.
RiskPrism is not a scanner, a dashboard, or a CMDB. It is the scoring layer that sits on top of the tools you already run, so the thousands of findings underneath become a short, defensible list of what matters.
Risk in dollars, not counts
Every exposure carries an ALE figure. Leadership sees the financial consequence of leaving something unfixed instead of a spreadsheet with 47,000 rows.
A score you can read
FARS scoring gives you end-to-end transparency. Every FARS grade decomposes across organization, tier, asset, and CVE, so a CISO can show an auditor exactly why an asset scored what it did. No black box.
A hospital is not a bank
An infusion pump and a payment gateway fail in very different ways. Each industry pack weights confidentiality, integrity, and availability to match, and gives credit for the controls you have already deployed.
Scanner neutral by design
We sell no scanner. RiskPrism scores whatever you already run, so the ranking reflects your risk, not a vendor's catalog. Swap tools underneath and the score still holds.
Hand the auditor evidence, not screenshots
Every score carries the trail behind it, mapped to the framework you report against, and it ties back to the same dollar figure leadership saw. When the auditor asks why an asset was prioritized, the answer is already there in numbers, not a folder of screenshots.
score → evidence → framework, in dollarsCurrently in pilot with select financial institutions
We are running guided pilots with a small group of banks and regulated organizations right now. Join the early access programme and we will score a representative slice of your environment so you can judge the output on your own data.
From scanner noise to a board decision, in five steps.
The overview before the detail. Every step is explainable, and nothing here replaces the tools you already run.
- 1
Ingest
Pull findings from Qualys, Tenable, Rapid7, cloud posture, IdP, and CMDB.
- 2
Score
FARS normalizes, weights by industry, and credits your controls. One score per asset.
- 3
Prioritize
Rank by real risk and dollar exposure, with your industry regulatory floors applied.
- 4
Route
Push the ranked queue to Jira and ServiceNow, with an owner on every item.
- 5
Report
Board-ready posture and audit-ready score lineage, on demand.
You keep discovery and remediation in the tools you own. RiskPrism is the scoring and prioritization layer in the middle.
Build a risk score. Watch it come apart.
Pick an industry pack and an asset, set the exploit signals, and switch on the controls you have in place. The score updates as you go, and every layer that produced it stays visible.
Scenario inputs
Adjust the signals. Everything recalculates as you move.
Why this score, layer by layer
RiskPrism can explain this score the way you would brief a board. Generate a short, plain-English summary of the breakdown above.
This is an illustrative model built to show how the methodology works. It is not the production scoring formula, which is proprietary and held stable across releases. Real scoring runs the full WAV to BRS to TAS to FARS to TRS to ORS chain.
We do not replace your scanners. We make them make sense.
Your scanners are good at finding things. RiskPrism sits above them, reads what they find, and turns it into one score you can defend. Keep every tool you have.
Normalize, weight, and score once
We deduplicate findings across every source, apply your industry pack, credit the controls you run, and produce one transparent score per asset.
Moving to a scanner vendor's own platform means one company both finds and scores your risk. RiskPrism does not sell a scanner, so it stays neutral and works with all of them.
| Capability | RiskPrism | Orchestration layers (Nucleus, Brinqa) | Scanner-native scores (TruRisk, VPR) |
|---|---|---|---|
| Regulatory floor enforcement per industry | Yes, pack-defined floors | Rule-based, build it yourself | Not a native concept |
| Loss expressed in dollars | Yes, ALE on every asset | Varies by product and setup | No, severity scores only |
| Explainable score decomposition | Yes, every layer visible | Partial, depends on configuration | Proprietary, largely opaque |
| Industry pack configuration | Yes, nine packs | Generic, manual tuning | One model for all industries |
| Multi-tenant MSSP architecture | Yes, native tenant isolation | Varies | Per-customer licences |
| Air-gapped and on-prem deployment | Yes | Mostly SaaS | Mostly SaaS |
| Scanner neutrality | Yes, we sell no scanner | Yes | No, scores favour own findings |
Competitor characteristics are stated in general terms and vary by edition and configuration. Verify against current vendor documentation for your shortlist.
One engine. A pack for every industry you serve.
The scoring engine is the same everywhere. Each pack changes the weighting, the risk floors, and the language so the score reflects how that industry actually fails.
Included in every pack: regulatory floors, industry weighting profile, and report language your regulator recognizes.
What changes, by industry.
Anonymized from the regulated environments we work in. We show the pattern, not the customer, because early pilots run under NDA.
- Pressure
- PCI DSS, SWIFT CSP, and central bank rules such as SBP demand provable prioritization, not a raw severity list.
- Floor
- Cardholder and payment systems never score below a set floor, whatever the raw scanner severity says.
- Outcome
- One graded posture the board reads in a minute, with the dollar exposure behind every grade.
- Pressure
- HIPAA obligations sit alongside patient-safety systems that simply cannot go down.
- Floor
- Clinical and PHI systems carry a raised floor, so they cannot hide behind a low finding count.
- Outcome
- Remediation targets the assets that actually threaten care and compliance first.
- Pressure
- FedRAMP and FISMA reporting on a fixed cadence, with auditors who expect evidence.
- Floor
- Systems inside the authorization boundary are held to mandated minimums.
- Outcome
- Audit-ready score lineage for every asset, produced on demand rather than rebuilt each cycle.
- Pressure
- IT and operational technology are converging under new board scrutiny.
- Floor
- Safety-critical OT is weighted up so it cannot hide behind low CVE counts.
- Outcome
- One shared language for risk across a mixed IT and OT estate.
Where we are today. RiskPrism is in guided pilots with select financial institutions, and we are onboarding a small number of additional regulated organizations. You will not find customer logos here yet, by design, because early pilots run under NDA. In an evaluation we score a representative slice of your own environment, so you judge the output on your data, not ours.
Do not trade independence for a scanner's badge.
Kenna's whole point was staying scanner-agnostic. The obvious replacements are scanner vendors who want you on their platform and their score. There is a better move.
Tenable, Qualys, and Rapid7 will each offer transition credits and a migration playbook. The catch is the same in all three: the vendor that finds your vulnerabilities also scores them, and each score (VPR, TruRisk, Real Risk) stays a black box. You give up the neutral, scanner-agnostic layer that made Kenna worth running.
Keep Qualys, Tenable, and Rapid7 as data sources. RiskPrism does not sell a scanner, so it never has a reason to steer your priorities toward its own findings.
Free, before you commit Point a slice of your real Kenna data at RiskPrism and see your current Top-N next to our score, side by side, with the reasons each one moved. Decide with evidence, not a pitch.
Your risk acceptances, false-positive exceptions, risk meters, and SLA targets carry over, so the migration does not reset your program.
Keep
Leave your scanners exactly where they are and connect them to RiskPrism.
Map
Translate your Cisco Security Risk Score history so your Top-N stays familiar.
Prove
Run in parallel with Kenna and review the Risk Parity Report together.
Switch
Cut over when you are ready, on your date. No big-bang weekend.
Run a risk practice under your brand, not ours.
RiskPrism is multi-tenant from the ground up. Onboard a client in hours, keep every tenant isolated, and put your name on the reports.
Native multi-tenant
Each client gets its own dashboard, scoring history, and audit trail, with per-tenant encryption keeping every tenant's data isolated.
White-label by design
Your brand, your styling, your SLA. Clients see your practice, and we run the engine underneath it.
Hours to onboard
Config-driven tenant setup means a new client goes from contract to scored assets in hours, not the weeks a custom build takes.
What early access participants say.
We finally stopped arguing about severity counts. The dollar figure next to each system changed the conversation with our practice leadership in one meeting.
The score comes with its reasons attached. When our compliance reviewer asked why a clinical system ranked where it did, we opened the trace and walked through it line by line.
We kept our scanners and our workflow. RiskPrism sat on top and the ranking it produced matched what our senior testers would have picked by hand, with the evidence to prove it.
Shared with permission from early access participants.
See your own risk, scored.
Send this over and we will set up a working session on a representative slice of your environment. No slideware.
- A live scoring run on a real asset type from your world
- A Risk Parity Report if you are leaving Kenna
- The industry pack that fits you, with the floors that matter
Submitted securely to the RiskPrism CRM, which alerts the sales team by email.