Product screencast · video

AI-driven cyber risk analysis

Know which cyber risks matter,
and prove it.

AI agents run the complete analysis end to end, turning your evidence into a quantified, traceable risk picture.

Get in touch

Who it's for

Meet NIS2 without a security team or a lengthy audit

Regulatory driver

Built for NIS2 obligations and mission-critical infrastructure

NIS2 requires an appropriate, risk-based analysis of your security posture. Aurelian delivers exactly that, as defensible and auditable evidence.

Force multiplier

Augment your security capabilities

Aurelian extends what your organisation can already do on security. The AI agents carry out the analytical work end to end, so a smaller team goes further and a larger one moves faster.

Time to result

Available in a fraction of the time

There is no lengthy engagement to scope and staff. You describe your organisation once, and the analysis begins.

Why Aurelian

Three frameworks, one knowledge graph

Aurelian combines the best methodologies in one application: a proven method to structure the analysis, real-world attack modelling, and quantification that puts numbers on the risk. They run on one shared knowledge graph, so the pieces connect into a single, defensible result.

  • A recognised European risk method
  • MITRE ATT&CK® attack modelling
  • Monte Carlo risk quantification
See how it works
Aurelian Risk Manager — Architecture
ingeststructureanalysegenerateDocuments & policiesPDF · DOCX · controlsThreat intelligenceexternal feeds · profilesExpert inputbriefings · conversational AIAI agent layercollects · structures · proposesModelling EngineEBIOS RMMITRE ATT&CK®Monte Carlobuilds the shared knowledge graphAnalysis engineskill-chains · coverage · quantificationDeliverablesaudit-ready reports · dashboardsAnalyst validates every step · runs on your infrastructure

The platform

Core capabilities, from data to decision

Every capability runs on one shared knowledge graph, so each step feeds the next into a single, traceable result.

St. Gerain Trauma Center · Baseline

EBIOS RM study · 5 workshops · 38 entities

ReviewReset
Workshop Progress54%
WS1Security Baseline
11 entities100%
WS2Risk Sources
6 entities100%
WS3Strategic Scenarios
9 entities80%
WS4Operational Scenarios
14 entities60%
WS5Risk Treatment
8 entities20%
FLOWEvent Flow
Cross-Workshop

Security Baseline

Identify business assets, supporting assets, and feared events.

TablesGraph
Agent · workshop 13 actions · 1.4 s
  • Searched the uploaded inventory and audit

    EHR · PACS · IAM · clinical core

  • Drafted the asset baseline

    4 business assets · 4 supporting systems · 4 feared events

  • Scored severity on a 1 – 4 scale

    criticality, recovery time, regulatory impact

Key findings

Business assetSEV 4

Patient Identity & Access

All clinical systems authenticate against the same directory. A compromise here cascades into EHR, PACS, and lab portal at once.

📄 hospital-inventory.pdf §2.1
Business assetSEV 4

Clinical Operations

Direct in-patient impact when EHR, imaging, or the lab portal is unavailable. Recovery target stated by the BSI audit: 4 hours.

📄 bsi-audit-2026.pdf §4.3
Feared eventSEV 4

Patient identity compromise

Plausible attacker path: phished credentials → directory takeover → silent privilege escalation across clinical systems.

inferred from 3 documents

Cascading dependency identified

Active Directory failure simultaneously disables EHR access, PACS authentication, and the lab portal. Beyond a 4-hour recovery window the hospital must divert incoming patients. Treat identity compromise as Severity 4.

Guided analysis, step by step

AI agents guide you through the risk-analysis workshops as a structured, step-by-step dialogue. Each step presents reviewable proposals (selectable tables, editable rows, choice buttons) that the analyst confirms, modifies, or rejects. Reasoning traces and source references stay visible inline. Every decision is recorded in the knowledge graph, traceable end-to-end.

Deliverables

What you walk away with

Risk analysis reports

Complete reports structured along the five-milestone analysis. Generated from the knowledge graph, every finding links back to its source.

Quantified risk assessments

Risk expressed as monetary loss ranges with transparent factor breakdowns, comparable across all scenarios.

ATT&CK® coverage dashboards

Visual coverage showing which techniques are addressed and where gaps remain. Export as PDF or interactive HTML.

Prioritised action plans

Roadmaps ordered by risk-reduction impact. Each recommendation traces from countermeasure to technique to business value.

How it works

Three steps to an audit-ready analysis

Import your existing documentation or start from scratch. The platform handles the methodology, the mapping, and the computation, so you focus on the decisions that matter.

01

Define your scope

AI-powered extraction

Upload existing documentation: security policies, architecture diagrams, audit reports. An agent extracts the entities and builds the initial knowledge graph. Or start from scratch, guided through a structured dialogue.

02

Run the analysis

Three frameworks, one workflow

Specialised AI agents guide you through a five-workshop analysis modelled on the established EBIOS Risk analysis methodology. ATT&CK® techniques are mapped automatically, kill-chains are built visually, and Monte Carlo simulation quantifies each risk. All outputs converge in a single knowledge graph.

03

Generate deliverables

Audit-ready output

Export audit-ready risk reports, quantified risk assessments, ATT&CK® coverage dashboards, and prioritised action plans. Every finding is traceable from business value to countermeasure, ready for management review or a regulatory audit.

From context to countermeasure

Turn your context and threat landscape into risk-based decisions and a clear view of where to invest. Import your existing documentation or start from scratch; the platform handles the methodology, the mapping, and the quantification, so you focus on the decisions that matter.

Aurelian Risk Manager — Process Flow
Milestone 1Security FoundationBusiness Values5 identifiedSupporting Assets12 mappedFeared Events7 documentedSecurity BaselineISO 27001Milestone 2Risk SourcesRisk Sources3 actorsStrategic Objectiveslinked to FEThreat GroupsMITRE enrichedAttack Motivationper actorMilestone 3Strategic ScenariosEcosystem Mappartners & depsStrat. Scenarios3 scenariosAttack Vectorsentry pointsStakeholder Eval.trust levelsMilestone 4Operative ScenariosKill-Chainsstep-by-stepMITRE Techniques21 mappedTargeted Assetsfrom Milestone 1Coverage Gaps16 openMilestone 5Risk TreatmentRisk AssessmentquantifiedSecurity Measures19 proposedResidual Riskper scenarioAction Planprioritisedanalysemodeldetailtreat

Hover over any entity to explore the analysis flow.

Resources

Latest insights

Guide

What NIS2 actually expects from your risk analysis

Read more

Insight

Quantified risk: from colour-coded registers to loss ranges

Read more

Method

Modelling real attack chains with ATT&CK®

Read more

Data-driven decision-making for your organisation

Agentic experts generate a full, auditable risk analysis for your organisation — no in-house security team required.

Get in touch

Contact

Let's talk

Whether you are preparing for your NIS2 obligations, looking to streamline risk analysis engagements, or exploring structured threat modeling for research, describe your use case and we will get back to you.

  • Walkthrough tailored to your infrastructure and threat context
  • Discussion of deployment and integration options
  • Information on early access availability

This website uses cookies and similar browser storage, along with selected third-party services. The site remains usable without consent. Details in the privacy policy.

Privacy