Sentrio

Cyber risk glossary

The terms Sentrio uses when cyber risk is expressed as scenarios, controls and ranges rather than as High, Medium and Low. Each definition is self-contained: you can read a single entry without having read the rest of the page.

Terms

Risk

A named category of possible loss: a loss event on an asset type. A risk groups scenarios, and its aggregate view is where its scenarios add up, shown as bounds, never as a single value. Sentrio uses Open FAIR as the ontology of its quantitative model, which expresses a risk as its loss event frequency multiplied by its loss magnitude rather than as a rating on a subjective scale, and shows every result as a range with its provenance. That matters because qualitative scales cannot be summed, compared or budgeted against: two risks both called High can differ by an order of magnitude in expected loss, and an ordinal scale cannot justify a budget to a CFO. Ransomware that encrypts the servers running invoicing is one such named category; the scenarios beneath it are the different ways that loss arrives, each calibrated on its own and each adding into the aggregate view.

Scenario

One way a threat community produces that loss for a declared analysis population. It is the level at which frequency and magnitude are calibrated, and it exists before it has a number. The threat community carries its intent: the same actor by error and on purpose are two related scenarios, calibrated apart. In Sentrio a scenario hangs from a risk, and its topology says how the loss can happen: one or several paths toward the same loss event, made of segments. It is worth as much when it is general with a single path as when it is detailed with several, because depth is selective and the client goes deeper only where a decision deserves it. Adding paths is never a penalty; if the number rises when someone looks harder, Sentrio explains that knowledge changed, not management. Ransomware encrypting the billing servers, analyzed for the population of servers that run invoicing, is one scenario.

Threat community

The kind of actor a scenario is analyzed against, with its intent, deliberate or accidental. Open FAIR defines it as a subset of the overall threat population that shares key characteristics. Every Sentrio scenario declares which threat community it is analyzed against, because the community is what Threat Event Frequency counts: how often that kind of actor acts against the asset in a year, whether or not it succeeds. Intent is part of the declaration, not a footnote. The same actor acting by error and acting on purpose are two related scenarios, calibrated apart, since the attempts you can count differ and so do the paths available. A concern voiced in non-technical language, such as suppliers being hacked and affecting the organization through them, names its community before it has any number attached.

Analysis population

The assets, identities or processes for which a scenario is analyzed: the denominator against which coverage is calculated. A Sentrio scenario declares its population alongside its threat community, and does so before it has a number. Coverage is then how much of that population and of the scenario’s paths a control’s effects actually reach, which is why a control that only reaches part of it is shown as partial scope rather than as covered. The population is what makes that share readable. In the scenario of ransomware encrypting the billing servers, the population is the servers that run invoicing. Where the data needed to state the population is missing, the data map says which data is missing and what completing it unlocks.

Attack path

One complete route from entry to loss event within a scenario. A scenario can have one path or several toward the same loss; a chain is the simple case. Each path is made of segments, and each segment carries a plain-language description, the ATT&CK techniques that identify it, and a declared basis: observed, derived or candidate. Paths can mix IT and OT; a route from a phishing email to a PLC is one path. Sentrio always shows the counterfactual across them: this treatment reaches these paths, these others stay the same, evidence is missing here. Adding paths is never a penalty. A general scenario with a single path is worth as much as a detailed one with several, because depth is selective and the client goes deeper where a decision deserves it. If the number rises because someone mapped another path, Sentrio explains that knowledge changed, not management.

Segment

One stage of an attack path: a plain-language description, the ATT&CK techniques that identify it (Enterprise or ICS; one path may mix IT and OT), and its declared basis: observed, derived or candidate. When a scenario is analyzed, Sentrio walks each segment, looks in its reference knowledge (ATT&CK, NIST 800-53, NIST CSF 2.0) for which controls could act there, and crosses them against the client’s catalog, leaving the state in plain view: declared, blocked by dependency, evidenced without credit, partial scope, or covered. Where a segment is left without a control, it suggests the implementable control from NIST 800-53 and the expected outcome from CSF 2.0, and if the suggested control is not in the catalog an initiative is opened. If it has nothing to suggest, it does not invent. AI can propose the segments and techniques of a path from a library pattern, but a person accepts them, and the proposal keeps who generated it and who accepted it.

Control effect

One thing a control can do: the mechanism, named by the Open FAIR factor it moves, the point it acts on, its scope, its mode and its evidence. A control has several effects; an EDR resists execution and also enables response, and those are two different things. Detecting never reduces risk by itself; it enables the response, so a detector is never counted as reduction. A control that exists in the inventory gets no credit for existing either: what an effect earns depends on the evidence behind it and on the dependency chain it needs to work. Effects bound the loss distribution once their contribution is evidenced; they never hand back a precise number. Sentrio does not use FAIR-CAM or derived content; the causal layer that names which Open FAIR factor an effect moves is Sentrio’s own. Naming the mechanism is what lets the counterfactual be shown: this treatment reaches these paths, these others stay the same.

Coverage

How much of a scenario’s paths and population a control’s effects actually reach, evaluated with its dependency chain: are there logs, does the detector work, does detection arrive in time, is the response executable. Existing in the inventory earns nothing. Its denominator is the scenario’s declared analysis population, and the states Sentrio leaves in plain view are the answers: declared, blocked by dependency, evidenced without credit, partial scope, or covered. For each candidate control a person decides whether it applies in this scenario and why; Sentrio does not decide for the client. An EDR resists execution and also enables response, and those are two different effects with their own reach. Where a segment is left without a control, Sentrio suggests the implementable control from NIST 800-53 and the expected outcome from CSF 2.0, and opens an initiative if that control is not in the catalog.

Scenario quality

How well sustained the number is and where it comes from: the minimum of how well the scenario is defined, how its frequency is evidenced, and how its controls’ evidence is known. Always shown with its bottleneck. It describes the width of the range and its provenance; it never hides a number. Lack of data widens the estimate; it does not block it. A missing data point is “missing”, never zero, and an accepted estimate is a “declared estimate”, never a measurement. The bottleneck is what tells the client where to look next: a scenario whose frequency is a declared estimate, whose magnitude is documented, and whose control evidence is partial has frequency as its bottleneck, and completing frequency is what narrows the range. A map with wide ranges on the first day is honest; an empty one is a choice.

Data confidence

How a data item is known: measured, documented, declared estimate, or missing. It is read from how the data was obtained, never estimated, shown per item, and never aggregated into a score. It is the per-item counterpart of scenario quality, which reads its bottleneck from these items rather than from a rollup. A missing item is “missing”, never zero: its absence widens the estimate instead of blocking the calculation, and an accepted estimate stays a declared estimate rather than becoming a measurement. General organization data, data that belongs to a process or an asset, and scenario-specific data are loaded once and inherited, so an item’s confidence travels with it into every scenario that uses it. The data map shows which data Sentrio uses to calculate each scenario, which is missing, and what completing it unlocks. Telemetry narrows the picture, but nothing waits for it.

Sealed result

A reproducible, immutable result with its method, inputs, provenance, the versions of knowledge used, and what changed since the previous one. Nothing modifies a sealed result; a change produces a new one with its explanation. It is the only thing that moves the strategic map, and what reaches that map is what is complete: defined, calibrated with an accepted rationale, validated by the person who built it, shown with its range. A dynamic signal never moves one; it proposes a review, and the review, if warranted, produces a new sealed result. What is sealed is the annual loss distribution the Open FAIR engine produced, with its percentiles, its probability of a zero-loss year and its exceedance curve, before insurance or transfers. Because each figure traces back to its source, the call holds up in front of the board.

Strategic risk

The map presented to the board: the sealed results of scenarios that are complete. It changes only by a new sealed result. What reaches the board is what is complete: defined, calibrated with an accepted rationale, validated by the person who built it, and shown with its range rather than as a single expected value. Each figure traces back to its source, so the call holds up in front of the board, and a range can be compared honestly against the loss accepted for that scenario. A map with wide ranges on the first day is honest; an empty one is a choice. What is getting worse day to day is kept apart as dynamic risk: an expired initiative or a control that stopped reporting proposes a review of a scenario, and only the new sealed result that review produces changes the map.

Dynamic risk

What is getting worse and could affect the map if nothing is done. It exists without telemetry: an expired initiative, expired evidence, a control that stopped reporting are already signals. A signal proposes a review; it never moves a sealed result. It exists from day one, and telemetry widens the signals rather than enabling them. A review, if warranted, produces a new sealed result, and that new result is the only thing that changes the strategic map presented to the board. An initiative opened to close a segment without a control and then left un-updated past its date is already a signal. External intelligence behaves the same way: a campaign or a news item is contrasted against the organization’s assets and controls, and if data is missing to know whether it applies, Sentrio says which data to confirm instead of moving a number.

Appetite

The loss accepted for a scenario: a threshold, a probability and a horizon. Defined per scenario, not as a global number imposed by Sentrio. Sentrio suggests; the client decides, and it never imposes an order or a number, so the threshold belongs to the organization. Stating it per scenario is what makes an annual loss distribution actionable: the percentiles, the probability of a zero-loss year and the exceedance curve can be read against the accepted loss instead of against an opinion, and a board can compare a scenario with its appetite honestly. A single expected value cannot support that comparison, because it hides how wide the uncertainty is and how often a year passes with no loss at all.

Initiative

A persisted action to create, improve or measure a control, integrated with the organization’s ticketing. It is what Sentrio opens when a segment of an attack path is left without a control and the control it suggests, the implementable one from NIST 800-53 with the expected outcome from CSF 2.0, is not in the client’s catalog. Sentrio does not replace the client’s systems and does not build a ticket manager, so the initiative lives in the ticketing the organization already uses. Once persisted it stays visible as risk information: an initiative that expired and nobody updated is already a dynamic signal, and it proposes a review of the scenarios it was meant to change rather than quietly moving their sealed results. An initiative is narrower than a decision: it is one action on one control, not an alternative weighed across several scenarios.

Decision

An alternative to evaluate, possibly across several scenarios, with its baseline and expected effect. An investment in privileged access management and the set of scenarios it would move is one decision. Its baseline is the sealed results of the scenarios it touches, and its expected effect is stated as a counterfactual: this treatment reaches these paths, these others stay the same, evidence is missing here. Sentrio does not prioritize for the client; it suggests and shows, and the ranking of alternatives stays with the organization. The effect is bounded rather than precise, because controls bound the loss distribution once their contribution is evidenced and never hand back an exact number. Reading the alternative against the loss accepted for each scenario is what turns it into a call a board can make. Accepting it edits nothing: a new sealed result records what changed.

LEFLoss Event Frequency

How many times per year a loss event is expected to occur. It derives from how often a threat comes into contact with the asset, the probability that it acts, and the proportion of those attempts that defeat existing controls. A value of 0.5 means the event is expected once every two years. The gap between it and Threat Event Frequency is Vulnerability: the share of attempts the controls in place fail to stop. In Sentrio it is calibrated at the level of the scenario, as an accepted frequency for the whole scenario, and it exists as a range rather than a point, anchored on observed attempts and the controls in place. The engine draws it together with magnitude and produces the annual loss distribution. Where the frequency is a declared estimate rather than a measurement, quality names it as the bottleneck, and completing it narrows the range.

LEF = Threat Event Frequency × Vulnerability

TEFThreat Event Frequency

How often a threat community acts against the asset in a year, whether or not it succeeds. It is the observable anchor: attempts you can count, before the controls decide the outcome. Loss Event Frequency is this figure multiplied by Vulnerability, the share of attempts that defeat the controls in place, so the distance between the two is what the controls are credited with closing. The threat community named in the scenario is what makes it countable, since intent changes what gets attempted: the same actor acting by error and acting on purpose are calibrated apart. The asset side is the scenario’s declared analysis population. Sentrio calibrates it as a range with its provenance rather than as a point, and where it is a declared estimate instead of a measurement, that is what quality reports. Its absence widens the estimate; it is never treated as zero.

LMLoss Magnitude

What a loss event costs: primary loss the organization pays directly, plus secondary loss that follows. Primary loss is response, replacement, disruption. Secondary loss is what comes after: fines, litigation, lost customers. Sentrio monetizes only what the organization pays; harm to people is shown as a declared, non-monetized impact next to the number rather than converted into currency. It is calibrated as an accepted magnitude for the whole scenario and carried as a range, and the engine draws it together with frequency to produce the annual loss distribution, before insurance or transfers. In the scenario of ransomware encrypting the billing servers, the magnitude spans response, downtime and notification. Where the figures are documented rather than estimated, quality says so, and the bottleneck of the scenario falls elsewhere. Controls bound that distribution; they never give a precise number.

LM = Primary Loss + Secondary Loss

Read the method end to end

The methodology page walks these terms from frequency and magnitude to the distribution a board can act on.

See your estate as a map before the next budget cycle.

Thirty minutes with the team is enough to walk one route end to end.

Talk to the team