Pillar 06 Companion — The Enterprise Risk Register
Seed to sale for risk: from the engagement that found it to the purchase order that closes it. Offensive scoping, a coverage matrix that knows what has gone stale, treatment as a budgeted project, and priced solutions with the ROI attached.
What this actually gives you
- Four methodology packs ship as data — MITRE ATT&CK, OWASP WSTG, NIST 800-115 and a generic assessment pack — 141 entries carrying their own decay windows.
- The seed is a populated enterprise risk register with a coverage map: 8 assets, 4 engagements, 116 coverage rows, 11 scored risks, 6 solution options.
The hub of the register family, and the engineered companion to Pillar 06 — The Fractional CISO Operating System. Sold on its own, as the family, and as both sides of the seam.
The question your tools don't answer. Finding aggregators aggregate findings. Control platforms track controls. Reporting tools write reports. None of them answer the question a security leader is actually asked in the meeting that matters: we have this risk — what can we buy, how much does it cost, how long until we are protected, and how much risk actually goes away? And if we only fund one thing this quarter, which one? Answering it needs four things in one place — the engagement that found the risk, the coverage that says whether the finding is still true, the treatment modelled as a budgeted project, and priced options with a defensible reduction estimate. Each exists somewhere. They do not exist together, and joining them is the whole product.
The first-class object is the engagement, not the risk. That single decision produces five entities nothing else in the category models properly: the engagement with its scope, rules of engagement and authorization; coverage, which knows what was exercised by what method and what has decayed; the deliverable as a controlled artifact with re-test obligations; the treatment as a project with tasks, a budget and a blocked state; and priced solution options with reduction, time-to-protection and ROI.
Six lanes on a chain of custody. SEED, ASSESS, DECIDE, TREAT, VERIFY, CLOSE. A risk carries full custody from identification to closure or formal acceptance, and nothing appears or disappears without a logged transition carrying who, when, why, and what the AI recommended against what the human decided. The schema enforces that with CHECK constraints rather than describing it in prose: an engagement cannot go active unauthorized, a risk cannot be accepted without a named actor and a written rationale, and an audit event cannot claim to be both machine suggestion and human decision.
The coverage matrix is the centrepiece. Rows are methodology references, columns are assets or business units, and cells are coloured by recency and result rather than by pass and fail alone. It answers what has actually been tested and when, what has never been tested at all, what passed eighteen months ago and is now telling you nothing, and where the next engagement should point. Four methodology packs ship as data — MITRE ATT&CK, OWASP WSTG, NIST 800-115 and a generic assessment pack — with 141 entries carrying their own decay windows. The generic pack is the one a fractional CISO uses most: run it and you have a coverage map on day one, before any technical testing has been scoped, and that map is the scoping conversation. Expect your first map to be mostly grey. That is the product working — the gap between what a team believes it has tested and what it can evidence is the most valuable single output of the build.
Confidence is reported beside the score and never inside it. A risk whose supporting assessment has aged has not become less true; it has become less known, and those are different things most registers conflate. Fold them together and an unknown looks like a lower risk, which is precisely backwards. A stale critical is still a critical; what you lack is knowledge, not severity.
Scoring with every modifier derived. Base is likelihood times impact, human set. Then exposure, exploitability, asset criticality and asserted control effectiveness, all derived — so moving one asset behind a gateway re-scores every risk on it without anyone touching a risk row. Exploitability is evidence-backed and stores its basis, because "our team thinks this is easy" is not evidence.
The money question, answered. Solution options are ranked on time-weighted efficiency — risk reduced per annualised dollar, discounted by how long you wait for protection — with reduction_basis as a required field, so a vendor's claim and a tested figure never quietly become the same number. The incumbent check runs first: which tools already paid for could treat this risk if configured differently. In most estates that query's first honest answer pays for the guide several times over, and it is the one solution source no vendor will ever surface for you.
The seam, held deliberately. This register asserts that a risk is treated by control X. The Living ISMS owns whether X is implemented, tested and evidenced. The register asks; the control graph answers. control_ref carries an id and six facts and never grows — the schema, the tests and the guide all check it. Without a control graph you type an effectiveness figure, and the guide is blunt about what that number is worth.
Multi-entity and portfolio, at every tier. An entity registry with hierarchy and 19 fail-closed scoped views — they return nothing with no scope set, rather than everything — plus five cross-entity rollup views including an attention board, and a tenancy test suite that proves isolation, fail-closed behaviour and one-directional hierarchy. Portfolio views are asserted free of client detail, so a roll-up cannot leak a rationale or a quote reference between clients.
Ninety seconds to a working register. Load the schema, load the generated seed, load the packs, and query. That is a populated enterprise risk register with a coverage map — 8 assets, 4 engagements, 116 coverage rows, 11 scored risks, 6 solution options. The seed is generated by gen_seed.py from the scoring model rather than typed, so it can never drift from the worked examples in the guide.
What deliberately is not in the box: a finished application. A shipped app dates in nine months, buyers land on Workers, Postgres and isolated SQLite in roughly equal numbers, and a register you generated yourself is one you can extend when the first field you need turns out to be the one nobody modelled. You get the data model and the prompts because those are the parts that keep their value. Vendor pricing is also excluded on purpose — it goes stale within a quarter, and a build system with a maintenance obligation on pricing becomes a subscription nobody intended to sell.
Every file ships at every tier. The tiers differ by licence scope, not by contents — you should never discover that the thing you needed was behind a higher price. Includes the 32-page guide, 55 build prompts with acceptance criteria plus four recovery prompts, the six-lane schema with four views and the constraints that enforce the house rules, the multi-entity and portfolio extensions, generated seed data and its generator, four methodology packs with an authoring guide and validator, the pack loader, the tenancy test suite, the tenancy-isolation and client-onboarding docs, a white-label board deck template with the query behind every figure, and the solution provider interface with local, quote and incumbent providers shipping.
The register family. RR-01 — The 2026 AI Risk Register and the pillar registers federate in as streams on shared canonical entity names, so owning several gives you one register with several ingest lanes rather than several that disagree at the board meeting. Pillar 06 is the practice that owns it, and the managed fractional CISO pillar is the done-for-you version. Treatment briefs route out to the advisor network, and MicroSec Tools assessments can feed the intake lane.
Also available in 2 bundles
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
Register & Machine
The Enterprise Risk Register plus The Living ISMS. The register asks whether a risk is treated by control X; the control graph answers whether X is real. Both sides of the seam. 25% off buying separately.
The Register Family
Pillar 06 plus both registers — The Enterprise Risk Register as the hub and The 2026 AI Risk Register as the AI stream. The hub, the stream, and the practice that owns them. 25% off buying separately.
What's included
- PDF — fully editable
- Build System (.zip) — 55-prompt pack, six-lane schema, four methodology packs, tenancy suite — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
Complete your toolkit
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee