Riskform / Risk Reduction Platform

Stop prioritizing vulnerabilities. Prioritize the work.

Riskform turns fragmented vulnerability and threat intelligence into explainable remediation campaigns, ordered by the risk they can remove and the effort required to remove it.

Public data firstNo CMDB required to start
Policy as codeVersioned YAML rules
Explainable decisionsEvidence → score → campaign
riskform.engine / decision pipelinepolicy:v1.0
inputVulnerability data

NVD · CWE · CPE · CVSS · EPSS · KEV

engineRiskform policy

Taxonomy · threat modifier · grouping · planning

outputAction campaigns

Now · Next · Later · API · alerts

EXPLOIT_ACTIVITY
88
TECH_SEVERITY
76
RISKFORM_INTEL
+9
$ riskform explain CVE-XXXX-YYYY
category = INTERNET_ENTRY [MITRE:T1190]
cisa_kev = true
intelligence_modifier = +9 [3 independent signals]
campaign = upgrade_exposed_gateway_family
Signal layer NVDCWECPECVSSEPSSCISA KEVCISA RansomwareAlienVault OTXRiskform Intelligence
The problem

Severity is abundant. Engineering capacity is not.

Most vulnerability programs produce more findings than teams can remediate. Riskform changes the unit of prioritization from individual CVEs to coordinated actions that remove meaningful risk.

01 / SIGNAL

Too many disconnected indicators

CVSS, EPSS, KEV, ransomware use, vendor advisories and threat reporting all describe different parts of the same decision.

02 / ACTION

CVEs are not work packages

Engineering teams patch products, upgrade releases, change configuration and deploy controls. They do not remediate abstract vulnerability IDs one by one.

03 / CONTEXT

Enterprise context arrives late

Useful prioritization should begin with public intelligence and improve when inventory, VM, CMDB, network and identity context become available.

The decision engine

From raw vulnerability data to a bounded portfolio of actions.

The engine is transparent by design. Taxonomy, scoring, grouping and planning logic are externalized in versioned YAML policies so every recommendation can be reproduced and explained.

STEP_01

Normalize & enrich

Build one CVE intelligence object from NVD, weakness, product, severity, exploitation and threat signals.

STEP_02

Classify adversarial use

Map public evidence into a stakeholder-friendly adversarial taxonomy anchored in MITRE ATT&CK.

STEP_03

Score & explain

Combine exploitation activity, technical severity and Riskform proprietary intelligence without hiding source evidence.

STEP_04

Generate campaigns

Group vulnerabilities by the remediation or mitigation action that can retire the most risk with the least effort.

01 / T1190Internet Entry
02 / T1203Client Exploit
03 / T1068Privilege Gain
04 / T1212Credential Compromise
05 / T1210Lateral Exploitation
06 / T1211Stealth via Exploit
07 / T1687Defense Impairment
08 / T1499.004Availability Impact
09 / CATCH-ALLOther ATT&CK Exploitation
10 / GENERALGeneral Exposure
Riskform intelligence

Public signals tell you what is known. Our intelligence tells you what is changing.

Riskform continuously converts vendor updates, security research, news, blogs, underground reporting and other intelligence into a controlled scoring modifier, using source reliability, recency, independence and duplicate suppression.

V
Vendor advisoriesPatch bypasses, mitigations, exploit notes
verified
R
Security researchPoCs, weaponization, exploitation detail
clustered
N
News & blogsEmerging activity and secondary corroboration
deduped
D
Dark-web / undergroundCredible actor chatter and exploit trade signals
weighted
A
Analyst reviewHuman validation for high-impact evidence
audited
Explainable priority calculationexample / illustrative values
PPS = 0.60(EAI) + 0.40(TSI) + TIM

TIM (Threat Intelligence Modifier) can increase priority when new independent evidence appears. It cannot reduce priority simply because the internet is quiet.

Exploit Activity Index88public
Technical Severity Index76public
Threat Intelligence Modifier+9Riskform
Final Public Priority92explained
The unit of action

Campaigns, not CVEs.

A campaign is a set of vulnerabilities for which one coordinated remediation or mitigation action removes a meaningful amount of risk. That is what engineering teams can schedule, own and complete.

Upgrade exposed gateway family

Shared vendor release · Internet Entry · 17 CVEs · strong exploit activity

Now92
Apply browser stable-channel update

One rollout pattern · Client Exploit · 24 CVEs · high action reuse

Next73
Disable legacy management interface

Configuration mitigation · Lateral Exploitation · reusable control

Next69
Legacy library maintenance bundle

Low current exploitation signal · bounded exposure · monitor for change

Later38
Capacity-aware planning

Now / Next / Later

NOW
Gateway upgradeKnown exploitation + high intelligence momentum
Identity bridge patchHigh enterprise path leverage
NEXT
Browser releaseShared rollout with broad coverage
LATER
Legacy familyMonitor for exploit or exposure change
One engine, two deployment models

Start immediately. Add enterprise context when it creates more value.

Riskform uses the same decision semantics in both models. The difference is how much customer-specific context the engine can use and where the customer data resides.

01 / SaaS subscription

Riskform Intelligence

For teams that want immediate search, prioritization and campaign intelligence without a deployment project.

Search the enriched public CVE universe
Add lightweight inventory, vendor and technology watchlists
Receive campaign priorities and Now / Next / Later views
Get email, webhook and API notifications when risk changes
Inspect the evidence and policy behind every decision
Good fit for vulnerability management, product security, technology risk, MSP/MSSP and security leadership teams.
02 / Customer-hosted

Riskform Private Engine

For enterprises that want actual asset, exposure, ownership, controls and attack-path context without exporting sensitive findings.

Connect VM platforms and CMDB / asset inventory
Add Internet exposure, network, identity and control context
Prioritize actual findings instead of generic CVEs
Model remediation impact across attack paths
Keep enterprise asset and finding data inside the customer environment
Same Riskform taxonomy, YAML policies and campaign logic. Deeper customer context changes the decision, not the method.
First offer / design partner

30-day Risk Reduction Pilot

Prove that campaign-based prioritization can produce a smaller, clearer and more defensible remediation plan before committing to broader integration.

Fixed scope. No agent. No CMDB project required.Begin with public intelligence + your lightweight technology inventory
Week 1Technology scopeImport a product/vendor list or build the target watchlist with your team.
Week 1 to 2Risk baselineEnrich relevant CVEs and expose public, CISA and Riskform intelligence signals.
Week 2 to 3Campaign portfolioGroup vulnerabilities into shared-action campaigns and tune effort assumptions.
Week 3Prioritization workshopReview Now / Next / Later decisions with security and engineering stakeholders.
Week 4Executive readoutShow highest-leverage actions, evidence, assumptions and remaining uncertainty.
DecisionSelect operating modelContinue with SaaS or scope the customer-hosted private engine and integrations.
Questions buyers ask

Designed to be challenged.

Riskform keeps a traceable chain from source evidence to taxonomy, score, campaign and planning decision.

Yes. Public-only mode is a complete product: enriched CVE intelligence, adversarial categorization, proprietary threat signals, campaign generation, technology watchlists and notifications. Enterprise integrations increase precision later.

No. Scores are inputs to a decision model. The primary output is an explainable remediation or mitigation campaign and its relative priority.

Yes. The How It Works layer exposes source evidence, taxonomy rule, score components, Riskform intelligence events, grouping logic, confidence and policy version.

Yes. Taxonomy, classification, scoring, campaign logic, notifications and planning are externalized as versioned YAML policy so changes are governed and reproducible.

Riskform / The Risk Reduction Platform

Make vulnerability management answer one operational question.

What should we change next to remove the most meaningful risk with the capacity we actually have?

Start with the 30-day pilot →