The international reference standard for cyber risk management, natively implemented and AI-automated in Galea.
ISO 27005 is the international standard for conducting cyber risk management. It structures the analysis into clear phases and produces a comprehensive view of the threats facing your organisation.
Galea fully implements ISO 27005:2022 and automates the most time-consuming parts: AI scenario generation, score suggestions, and security measure identification.
Definition of scope, business values, supporting assets and existing security baseline.
Identification and characterisation of risk sources (RS) and their targeted objectives (TO).
Construction of strategic scenarios. AI generates realistic attack paths.
Breakdown into technical action sequences. MITRE ATT&CK mapping.
Security measures prioritised according to the G·P·D·R model.
In minutes, Galea generates, for each of your assets, realistic attack scenarios, scored and mapped to known adversary techniques. Here’s a glimpse — the full analysis awaits you in a demo.
RS: Organised cybercriminal group (SR-CRIME) → TO: Financial extortion
The attacker conducts public LinkedIn reconnaissance on finance staff, sends a spear-phishing email with a malicious macro, gains initial access to an accounting workstation, performs lateral movement to the SAP server, then deploys ransomware encrypting financial data and demands a ransom.
Negligible impact on missions
Notable impact, manageable
Strong impact on essential missions
Endangers the organisation
Unlikely, significant resources required
Realistic with moderate resources
Probable, standard resources sufficient
Very likely, scenario already observed
Galea guides you through each phase.
Join the companies that trust Galea to drive their cyber-résilience. 30-minute demo.
Already a customer? Go to the platform