The Risk Scenarios page is where you assess potential threats and calculate your Value at Risk (VaR). It centralizes critical financial metrics, including expected financial loss, estimated annual attack incidence, and total VaR, while enabling risk owners to formally approve decisions to mitigate, transfer, avoid, or accept specific risks. Additionally, it clearly maps out the exact security controls required to protect your related assets once a mitigation strategy is chosen
Go to app.maplegrc.com.
Log in with your account credentials.
In the left sidebar, navigate to the Risk Scenarios page under the Identify section.
Ensure all assets are added first. In the left sidebar, navigate to the Assets Inventory page under the Organization section and verify that all assets are listed. This is crucial to ensure that the security controls for relevant assets appear correctly.
Finalize your Cyber Risk Strategy page, navigate to this page under the Governance section, by completing the Risk Strategy Inputs, Cyber Risk Tolerance, Cyber Risk Appetite, Current Residual Risk, and Financial Risk Capacity. These baseline financial metrics are required to accurately calculate your Value at Risk (VaR).
This page displays a comprehensive list of potential risk scenarios, including their current risk treatment status and calculated value at risk. You can click the column headers to sort the data and prioritize your mitigation plan.
Click the Access scenario button next to a specific threat to open its detailed view.
Click the Calculate Risks and Controls button located at the top right to generate the risk metrics.
Review the calculated figures in the Value at Risk (VaR) section. You can click the ? icon next to individual metrics to view more detailed explanations.
Finalize your risk management strategy by selecting the appropriate treatment action at the top of the page: MITIGATE, TRANSFER, AVOID, or ACCEPT.
When you set a risk to MITIGATE, a threat matrix appears below to show how attackers operate and the exact security steps needed to stop them.
The matrix is divided into two main parts:
Tactics (Left side): Broad categories that show the attacker's goals, such as "Credential Access" or "Lateral Movement".
Techniques (Specific Cards): The exact methods attackers use to achieve those goals, like "OS Credential Dumping".
Each technique card acts as a simple checklist, displaying:
Control Status: Your current progress in blocking the threat (e.g., "Not Started" or "Partially Done").
Assets: The systems that need protection, such as Microsoft 365 or Windows.
Controls: The specific security rules you must apply, like "AC-2: Account Management".
Incident Response Plan: Shows if a recovery plan is linked, or "N/A" if one is missing.