Sentrio

The cybersecurity decision compass

The cybersecurity team uses Sentrio every day to know which scenarios matter, which controls protect them and where paths remain open, what is worth attending to, and to build a number the CISO can explain and defend when a decision has to be made.

Sentrio suggests; the client decides. It never imposes an order or a number.

A scenario is born through one of four doors.

  • A concern

    From the CISO or from the business, in non-technical language: “that my suppliers get hacked and through them they affect me.”

  • A question about controls

    What do we have, what is missing, where does it fail.

  • Threat modeling

    Of a critical process or environment, which ends in scenarios.

  • External intelligence

    A campaign, a news item, a threat, which Sentrio contrasts with the organization’s assets and controls. If data is missing to know whether it applies, it says which data to confirm.

One concern can become several risks and scenarios, and from the concern you can see everything it generated. The four doors create the same object. If two entries describe the same loss, they are reconciled; a scenario is never duplicated to add risk.

In the first version, the intelligence door works with cases published by Sentrio; clients bring their own sources later.

One or several paths to the same loss, made of segments.

A scenario hangs from a risk, declares for which threat community and for which population of the organization it is analyzed, and exists even if it has no number yet. Its topology says how it can happen: one or several paths toward the same loss event, made of segments. Each segment has a plain-language description, the ATT&CK techniques that identify it, and a declared basis: observed, derived or candidate.

A general scenario with a single path is worth as much as a detailed one with five. Depth is selective, and the client goes deeper where a decision deserves it. Paths can mix IT and OT: a path from a phishing email to a PLC is one path.

Adding paths or telemetry is never a penalty. If the number goes up when you look harder, Sentrio explains that knowledge changed, not management.

The client does not start from a blank page. Sentrio maintains a library of scenario patterns, built from observed campaigns and threats, which the client adopts and adjusts as their own.

How much of what worries you is covered.

The client loads their control catalog once. When analyzing a scenario, Sentrio walks each segment, looks in its reference knowledge (ATT&CK, NIST 800-53, NIST CSF 2.0) for which controls could act there, and crosses them against the catalog. For each candidate, a person decides whether it applies in this scenario and why. The state is left in plain view: declared, blocked by dependency, evidenced without credit, partial scope, or covered.

  • No credit for existing

    A control that exists in the inventory gets no credit for existing.

  • Detection enables response

    Detecting never reduces risk by itself; it enables the response.

  • The counterfactual is always shown

    This treatment reaches these paths, these others stay the same, evidence is missing here.

Where a segment is left without a control, Sentrio suggests: from NIST 800-53 the implementable control, from CSF 2.0 the expected outcome. If the suggested control is not in the catalog, an initiative is opened, integrated with the client’s ticketing. If it has nothing to suggest, Sentrio does not invent.

A number the CISO can explain and defend.

When a scenario has its minimum inputs, it is calibrated: an accepted frequency and magnitude for the whole scenario. The engine, based on Open FAIR, produces an annual loss distribution with its uncertainty, before insurance or transfers. Not only a mean: percentiles, probability of no loss, exceedance curve.

  • Sealed

    Every result is sealed: method, inputs, provenance of each data point, versions of the knowledge used, and what changed since the previous one. Nothing modifies a sealed result; a change produces a new one, with its explanation.

  • Quality next to the number

    How well sustained is what was declared and measured, and where each input comes from. Quality describes the width of the range and its provenance; it never hides a number.

  • Missing is never zero

    Lack of data widens the estimate; it does not block it. A missing data point is “missing”, never zero. An accepted estimate is a “declared estimate”, never a measurement.

A map with wide ranges on the first day is honest. An empty one is a choice.

Controls bound the distribution; they never give a precise number. Everything Sentrio says shows where it comes from. No black boxes.

The map you present, and the day to day.

  • Strategic risk

    The map presented to the board. It changes little, and only through a traceable act: a new sealed result. What reaches the board is what is complete: defined, calibrated with an accepted rationale, validated by the person who built it, shown with its range.

  • Dynamic risk

    What is getting worse, what could affect the map if nothing is done. It exists from day one and without telemetry: an initiative that expired and nobody updated, expired evidence, a control that stopped reporting, are already signals. Telemetry widens the signals; it does not enable them. A signal never moves a sealed result; it proposes a review, and the review, if warranted, produces a new one.

AI proposes. A person accepts.

AI is what keeps the client from starting from zero. It turns a concern into a proposed scenario. It contrasts a news item with known assets and proposes scenarios or asks for the missing data. It proposes segments and techniques from a pattern, and candidate controls from the catalog.

  • Every proposal keeps who generated it and who accepted it.
  • AI does not produce risk numbers. Frequency, magnitude and control credit come from accepted calibrations, never from a language inference.
  • Everything that can be deterministic is deterministic: an analysis done once is stored and reused.
  • No organization’s data feeds proposals for another.

It runs on what you already own.

Sentrio integrates with what the organization already has: CMDB, SIEM, identities, tickets. It does not replace them. The data map shows which data Sentrio uses to calculate each scenario, which is missing, and what completing it unlocks, so the client decides what to complete first for the scenarios they care about most.

In the first version, data comes in by hand or through an importer of what the organization already has (spreadsheets, native exports); connectors to its systems come after.

What Sentrio does not do.

  • Does not accredit a control for being inventoried.
  • Does not treat missing evidence as zero.
  • Does not use a detector as reduction; detection enables response.
  • Does not prioritize for the client; it suggests and shows.
  • Does not let a dynamic signal move a sealed result.
  • Does not bring to the board a scenario that is not complete.
  • Does not replace the client’s systems or create a ticket manager.
  • Does not mix data across organizations.
  • Does not punish the client for learning more.
  • Does not use FAIR-CAM or derived content.

Everyone puts a dollar on risk. Nobody can prove theirs.

Capability comparison, Sentrio against seven cyber risk quantification vendors

Risk expressed in money

Table stakes. Everyone does it.

SentrioDocumented
SAFEDocumented
KPMGDocumented
AxioDocumented
KovrrClaimed or partial
X-AnalyticsClaimed or partial
SqualifyClaimed or partial
CyberSaintClaimed or partial

Every assumption explained

Most do. Depth varies.

SentrioDocumented
SAFEDocumented
KPMGDocumented
AxioDocumented
KovrrClaimed or partial
X-AnalyticsClaimed or partial
SqualifyClaimed or partial
CyberSaintClaimed or partial

Uncertainty shown, with what to check next

Three of seven. None end to end.

SentrioDocumented
SAFENot found
KPMGDocumented
AxioClaimed or partial
KovrrClaimed or partial
X-AnalyticsNot found
SqualifyNot found
CyberSaintNot found

Sealed, replayable runs: inputs, versions, fingerprint

Not confirmed in any of the seven.

SentrioDocumented
SAFENot found
KPMGClaimed or partial
AxioClaimed or partial
KovrrNot found
X-AnalyticsNot found
SqualifyNot found
CyberSaintNot found

New signal kept apart from the accepted result

Recalculate on change, yes. Approval, unverified.

SentrioDocumented
SAFENot found
KPMGClaimed or partial
AxioNot found
KovrrClaimed or partial
X-AnalyticsNot found
SqualifyNot found
CyberSaintNot found
DocumentedClaimed or partialNot found

GRC suites, ratings and scanners are adjacent, not rivals. We sit on their output and make it worth more.

You are not alone the first week.

The offer starts with a starter kit in which a specialist leaves at least one live scenario end to end, with its controls.

Talk to the team

See your estate as a map before the next budget cycle.

Thirty minutes with the team is enough to walk one route end to end.

Talk to the team