Home / ISO 27005
International ISO 27005 standard

ISO 27005 :2022

The international reference standard for cyber risk management, natively implemented and AI-automated in Galea.

The ISO 27005 risk management approach

From scope identification to risk treatment
Workshop 1
Scoping & Framework
Scope, business values, supporting assets, security baseline
Workshop 2
Risk Sources
Identification of attackers, motivations, SR/OV pairs
Workshop 3
Strategic Scenarios
Attack paths, feared events, severity assessment
Workshop 4
Operational Scenarios
MITRE ATT&CK techniques, likelihood, attack path mapping
Workshop 5
Risk Treatment
G·P·D·R measures, action plan, residual risk, final report

The international risk standard

ISO 27005 is the international standard for conducting cyber risk management. It structures the analysis into clear phases and produces a comprehensive view of the threats facing your organisation.

Galea fully implements ISO 27005:2022 and automates the most time-consuming parts: AI scenario generation, score suggestions, and security measure identification.

Recognised internationally and by ENISA
Compatible with ISO 27001, NIS2, LPM
Recognised by auditors and insurers
Adaptable to organisations of any size
5
Workshops
4
Severity levels
4
Likelihood levels
16
Matrix cells
4
G·P·D·R categories
AI scenarios

How Galea implements each step

Workshop 1

Scoping and security baseline

Definition of scope, business values, supporting assets and existing security baseline.

What Galea does
  • Import of existing IT inventory
  • Automatic categorisation of business values
  • Identification of associated supporting assets
  • Assessment of initial security baseline
Generated deliverables
  • Business values table
  • Supporting assets map
  • Security baseline assessment
  • Documented study scope
Workshop 2

Risk sources

Identification and characterisation of risk sources (RS) and their targeted objectives (TO).

What Galea does
  • Pre-loaded RS catalogue by sector
  • Attacker motivation, capability and activity
  • RS/TO pairs assessed automatically
  • Retained / not retained with justification
Generated deliverables
  • List of assessed RS
  • Retained RS/TO pairs
  • Attacker profile
  • Threat map
Workshop 3

Strategic scenarios

Construction of strategic scenarios. AI generates realistic attack paths.

What Galea does
  • AI generation of 3–5 scenarios per pair
  • Path: Recognise → Enter → Find → Exploit
  • Severity assessment G1–G4
  • Likelihood V1–V4
Generated deliverables
  • Documented strategic scenarios
  • Strategic heat map
  • Assessed feared events
  • Identified business impacts
Workshop 4

Operational scenarios

Breakdown into technical action sequences. MITRE ATT&CK mapping.

What Galea does
  • Automatic MITRE ATT&CK mapping
  • Adversary techniques contextualised
  • Targeted supporting assets identified
  • Attack path visualisation
Generated deliverables
  • Detailed operational scenarios
  • Attack path graph
  • Mapped MITRE techniques
  • Operational risk matrix
Workshop 5

Risk treatment

Security measures prioritised according to the G·P·D·R model.

What Galea does
  • AI recommendations ranked by G·P·D·R
  • Governance, Protection, Defence, Resilience
  • Residual risk estimation
  • ROI-prioritised treatment plan
Generated deliverables
  • Risk treatment plan
  • Documented residual risk
  • Full ISO 27005 report (PDF)
  • Executive board summary

Concrete scenarios, ready to act on

In minutes, Galea generates, for each of your assets, realistic attack scenarios, scored and mapped to known adversary techniques. Here’s a glimpse — the full analysis awaits you in a demo.

V4 × G4 = 16
Reduce

Ransomware via targeted phishing on the Finance ERP

RS: Organised cybercriminal group (SR-CRIME) → TO: Financial extortion

Recognise Enter Find Exploit

The attacker conducts public LinkedIn reconnaissance on finance staff, sends a spear-phishing email with a malicious macro, gains initial access to an accounting workstation, performs lateral movement to the SAP server, then deploys ransomware encrypting financial data and demands a ransom.

ReconnaissanceInitial AccessLateral MovementImpact
V3 × G3 = 9
Reduce

Patient data breach via Active Directory compromise

RS: State-sponsored attacker (SR-STATE) → TO: Espionage, collection of health data

Recognise Enter Find Exploit

Full attack chain detailed — public vulnerability on remote access, lateral movement, privilege escalation, exfiltration to adversary infrastructure.

See full analysis in demo
V2 × G3 = 6
Accept

Salesforce CRM unavailability via amplified DDoS

RS: Hacktivist (SR-HACKTIV) → TO: Business activity disruption

Recognise Enter Find Exploit

Full attack chain detailed — public vulnerability on remote access, lateral movement, privilege escalation, exfiltration to adversary infrastructure.

See full analysis in demo

Severity and likelihood

Severity scale

G1
Minor

Negligible impact on missions

G2
Significant

Notable impact, manageable

G3
Serious

Strong impact on essential missions

G4
Critical

Endangers the organisation

Likelihood scale

V1
Minimal

Unlikely, significant resources required

V2
Significant

Realistic with moderate resources

V3
High

Probable, standard resources sufficient

V4
Maximum

Very likely, scenario already observed

Start your ISO 27005 analysis

Galea guides you through each phase.

Request a demo
Free trial — No credit card

Ready to secure your organisation?

Join the companies that trust Galea to drive their cyber-résilience. 30-minute demo.

Already a customer? Go to the platform