Skip to content

Cyber Risk Distance

See how cyber risk reaches your critical business processes.

CRD connects business processes, systems, identities, suppliers and AI agents into understandable risk paths to help you identify relevant controls.

Connect dependencies to business impact

CRD — Cyber Risk Distance — models how systems, identities, suppliers and AI agents connect to critical business processes. Start with a process that must keep working, map its dependencies and identify relevant controls.

Illustrative example; not a discovered attack path.

External messageAI agentService accountCRMCustomer billing

Which control influences which path?

An agent identity, limited write permissions or human approval need to be considered in the context of their access routes. CRD makes modelled relationships to business processes visible and helps prioritise further checks. The agent extension is undergoing acceptance testing.

MODEL → PRIORITIZE → TEST → RETEST → PROVE

Model dependencies, prioritise controls, test their effectiveness and document change. Evidence and historical comparisons are planned extensions. A self-assessment does not produce technical evidence.

CRD complements risk registers and risk matrices. It is not a scanner, penetration test or complete GRC or ISMS suite. It does not automatically discover exploitable technical attack paths or calculate actual attack probabilities.

Continue with CRD

CRD requires a user account. Open the application and sign in. The application currently runs in a test environment; CRD Quick is available in German. Your answers from the free security check are not transferred automatically.

Open CRD

Start without registration: Open the free AI Agent Security Check