From January till June 2026, Riscomp has been collaborating with a highly motivated student team from OST – Eastern Switzerland University of Applied Sciences. The research project`s goal was to address one of the key challenges in modern risk management: connecting cyber security risks with enterprise risk management through a shared business-oriented perspective.
The Outcome: hybrid framework for monetary cyber‑risk quantification in Enterprise Risk Management (ERM)
The framework focuses on the role of Information Assets as a common denominator between cyber security and enterprise risk management. It offers a structured methodology that enables organizations to assess cyber risks in the context of business-critical assets and communicate their impact in a way that supports management decisions.
Why it matters: While IT and security teams typically assess and fix vulnerabilities, threats, and technical risk vectors, management needs a consolidated view of how these risks affect business operations, strategic objectives, and financial performance. IT risk is enterprise risk — but this theory collides with reality, with far‑reaching implications.
• CISO organizations struggle to demonstrate security’s value, and top management lacks a clear picture of risk exposure. A translation gap between IT and the business is one of the most significant organizational silos, causing inefficiencies and misdirected investments.
• Another challenge is the architecture: multiple monitoring, asset‑management and other IT solutions coexist, while business process, compliance and other risks are often managed in disconnected silos that don’t integrate risks at the data level. AI‑driven automation and reasoning risk implosion here: AI cannot fix poor data architecture. To deliver value, AI needs structured processes, clean data, semantic consistency and context.
Conclusion: The bright, shiny, agentic future isn’t just about adding an LLM on top of existing security and GRC platforms — it requires both methodological and architectural rethinking of how risk and compliance data are modeled so that agents can reason, connect, and support better decisions.
Building on established frameworks and standards such as BSI IT‑Grundschutz, the OWASP Risk Rating methodology and the FAIR methodology, the project team developed the Asset Risk Linkage Model (ARLM). The model extends Riscomp’ s asset‑centric approach and refines a structured methodology for:
- identifying and categorizing business-relevant information assets;
- evaluating threats, vulnerabilities, and control effectiveness;
- assessing both gross and net risk exposure;
- quantifying business impacts, including financial implications;
- visualizing risks through management-oriented dashboards and reporting views.
As part of the project, approximately 30 representative SAP-related information assets were defined and assessed using a dedicated evaluation framework.
A key outcome of the project is a methodology that enables organizations to move beyond purely technical security assessments.
Key Insights:
#1 An asset-centric approach is not just a design decision—it is the prerequisite for making risk assessments understandable and actionable for everyone.
#2 The translation gap is not closed by a sophisticated formula, but by consistently translating all assessment dimensions into a single business language: the monetary value of risk.
#3 Ignoring dependencies between assets leads to an underestimation of risk. In integrated ERP environments, cascading effects across interconnected assets can significantly increase overall risk exposure.
#4 A model that is actually applied in practice delivers greater value than a theoretically perfect model that fails due to excessive data collection and assessment effort.
Looking ahead
The results of the project provide a strong foundation for further development of Riscomp’s Digital Risk & Compliance Platform and support our vision of bringing cyber security and enterprise risk management closer together.
We look forward to connecting with you at the following events:
- WTT Young Leader Award (28. Oktober 2026 ab 17 Uhr, Tonhalle St.Gallen, Switzerland)
Details and registration: https://www.ost.ch/de/forschung-und-dienstleistungen/wirtschaft/ism-institut-fuer-strategie-und-marketing/wissenstransfer-innovation/wtt-young-leader-award - SAP Academic Community Conference DACH 2026 (Sep. 7. – 8. 2026 – St. Gallen Switzerland)
Details & registration: https://www.sap.com/swiss/events/2026-09-07-ch-sap-academic-community-conference-dach-2026.html
We would like to thank the entire OST project team for their commitment, professionalism, and valuable contributions throughout this collaboration.
