Keel
Live demo · read-onlyStart free →
This is a live, read-only demo. You’re exploring a fictional company, “Tailwind Systems.” Nothing here can be edited, and the data resets nightly. Create a free workspace to build your own program.
Start freeLearn more
Total
12
Open
10
High
1

Risk heat map

Effective (residual where assessed) likelihood × impact. Closed risks are excluded.

Almost certain·····
Likely···1·
Possible···2·
Unlikely·1231
Rare····1
InsignificantMinorModerateMajorSevere
Low (1-3)Guarded (4-7)Elevated (8-14)High (15-25)Rows = likelihood · Columns = impact
RiskCategoryLevelTreatmentMitigating controlsStatus
Critical vendor data breach
A breach at a critical sub-processor could expose customer data.
Third-party / vendormediummitigateNone linkedopen
Single cloud region outage
A regional outage of the primary cloud provider could disrupt the service.
AvailabilitymediummitigateNone linkedopen
PII mishandled causing privacy breach
Improper handling of personal data could trigger regulatory exposure.
Legal / compliancemediummitigateNone linkedopen
DDoS attack on public API
A volumetric attack could degrade availability of the public API.
AvailabilitylowtransferNone linkedopen
Non-compliance with a SOC 2 control
A control operating ineffectively could result in an audit exception.
Legal / compliancelowmitigateNone linkedopen
Insider misuse of admin access
A privileged insider could misuse access to data.
PeoplelowmitigateNone linkedopen
Phishing leads to credential compromise
Staff targeted by phishing could expose credentials to production systems.
PeoplehighmitigateNone linkedtreating
Unpatched CVE exploited
A known vulnerability left unpatched could be exploited.
TechnologymediummitigateNone linkedtreating
Secrets committed to source control
Credentials accidentally committed could be harvested.
TechnologymediummitigateNone linkedtreating
Backup fails silently
An undetected backup failure could prevent recovery.
AvailabilitymediummitigateNone linkedtreating
Laptop theft exposes local data
A lost or stolen device could expose locally cached data.
PhysicallowacceptNone linkedaccepted
Departing employee retains access
Access not revoked promptly at offboarding could be misused.
PeoplelowmitigateNone linkedclosed