From January till June 2026, Riscomp has been collaborating with a highly motivated student team from OST – Eastern Switzerland University of Applied Sciences. The research project`s goal was to address one of the key challenges in modern risk management: connecting cyber security risks with enterprise risk management through a shared business-oriented perspective.  

The framework focuses on the role of Information Assets as a common denominator between cyber security and enterprise risk management. It offers a structured methodology that enables organizations to assess cyber risks in the context of business-critical assets and communicate their impact in a way that supports management decisions. 

Building on established frameworks and standards such as BSI IT‑Grundschutz, the OWASP Risk Rating methodology and the FAIR methodology, the project team developed the Asset Risk Linkage Model (ARLM). The model extends Riscomp’ s asset‑centric approach and refines a structured methodology for: 

  • identifying and categorizing business-relevant information assets;  
  • evaluating threats, vulnerabilities, and control effectiveness;  
  • assessing both gross and net risk exposure;  
  • quantifying business impacts, including financial implications;  
  • visualizing risks through management-oriented dashboards and reporting views.  

As part of the project, approximately 30 representative SAP-related information assets were defined and assessed using a dedicated evaluation framework. 

A key outcome of the project is a methodology that enables organizations to move beyond purely technical security assessments. 

#1 An asset-centric approach is not just a design decision—it is the prerequisite for making risk assessments understandable and actionable for everyone. 

#2 The translation gap is not closed by a sophisticated formula, but by consistently translating all assessment dimensions into a single business language: the monetary value of risk

#3 Ignoring dependencies between assets leads to an underestimation of risk. In integrated ERP environments, cascading effects across interconnected assets can significantly increase overall risk exposure. 

#4 A model that is actually applied in practice delivers greater value than a theoretically perfect model that fails due to excessive data collection and assessment effort.

The results of the project provide a strong foundation for further development of Riscomp’s Digital Risk & Compliance Platform and support our vision of bringing cyber security and enterprise risk management closer together. 

We look forward to connecting with you at the following events: 

We would like to thank the entire OST project team for their commitment, professionalism, and valuable contributions throughout this collaboration.