ISO 27005 · NIST SP 800-30

Living Safety Cases for Cyber Risk

An ISO 27005/NIST SP 800-30-style risk matrix scored across Confidentiality, Integrity and Availability, with live bowtie diagrams tracing every threat scenario from source to consequence.

Book an Engineering Walkthrough Interactive Bowtie Demo ↗
πŸ”

ISO 27005 and NIST SP 800-30, Scored Across the CIA Triad

SAFOPS's cyber risk project template starts from an ISO 27005/NIST SP 800-30-style matrix, scoring each threat scenario against the CIA triad rather than a single generic severity scale, as a reviewable baseline you adjust to your own organisation's risk appetite. Run it standalone, or alongside an OT/engineering safety case in the same installation via Multi-Project Management, so a cyber risk register and a mechanical fault sequence sit in one place instead of two disconnected tools. An automated consistency check keeps the template and its example project aligned, so a new project always starts from the reviewed baseline.

πŸ•ΈοΈ

Interactive Bowtie Diagrams: Every Threat Path Traced to Its Controls

Threat sources, the vulnerabilities they exploit, and preventative, detective, and corrective controls are modelled as interactive bowtie diagrams rather than rows in a static risk register. Hover any control to see its zone of influence, spot single points of failure, and open deficiencies directly on the diagram β€” the same live model your treatment plan is built from. Deficiencies flow straight into the Deficiencies Schedule, and a control shared across several threat scenarios is recognised once rather than credited twice.

πŸ”’

A Tamper-Evident Audit Trail, Air-Gapped Where It Needs to Be

Every edit to the risk assessment, whether made by an engineer or suggested by the optional AI copilot, is logged in a SHA-256 hash chain β€” a verifiable record for internal review and third-party audit alike. For organisations that require it, SAFOPS also runs fully on-premise or air-gapped, so nothing about your own risk register has to leave your network; see Security & Deployment. Scrub back through that history with Time Machine, or freeze an approved version as a formal issue.

🀝

Software, With Safety Engineers Behind It

You don't have to adopt SAFOPS alone. Our engineers can do the work in the platform for you β€” performing the threat modelling and risk assessments, building and managing the hazard log, and keeping the register current as your threat landscape evolves β€” from a one-off migration of a legacy spreadsheet to ongoing management between periodic reviews. Use SAFOPS as a tool, a fully managed service, or anything in between.

Ready to build your first Living Safety Case?

Book an Engineering Walkthrough Interactive Bowtie Demo ↗