Skip to content

Evaluating Risk. Informing Decisions.

Identify technology risk and shape an action plan without spreadsheet-heavy assessment cycles

Aegis101 combines guided scope, dynamically routed questions, progressive reporting, and prioritised actions to move assessment work from scattered inputs to decision-ready direction.

Aegis101 provides answer-based risk interpretation and decision support. It does not replace audit, certification, evidence validation, or accountable risk judgement.

Context-aware assessment
Save and resume
Controlled interim reports
Risk-led action
Comparison and trends

From context to action

A disciplined route through complex technology risk

Aegis101 brings scope, assessment logic, risk interpretation, ownership direction, and reassessment into one coherent workflow.

01

Scope

Define the service, lifecycle, exposure, criticality, and data context.

02

Assess

Follow dynamically routed questions with plain-language guidance.

03

Progress

Save automatically, resume later, and defer information that is not yet available.

04

Report

Generate an interim or completed position without disguising uncertainty.

05

Act

Focus owners on treatment, evidence, decisions, and outstanding confirmation.

06

Reassess

Compare compatible reports and track change after remediation or review.

What you receive

Reports built for decisions, ownership, and follow-through

Interim and completed reports show the current assessed position without hiding important exceptions or unavailable information. Category analysis and action roadmaps then connect findings to practical treatment.

  • Controlled interim position: useful analysis from the available answer basis, with uncertainty retained.
  • Executive position: headline risk, material drivers, and decision boundaries.
  • Risk by category: domain themes and leading assessed controls.
  • Action roadmap: owner direction, remediation focus, and closure evidence.
  • Outstanding-item register: what remains and the direct route back to complete it.
  • Assurance boundary: what is answer-based or still needs validation.
Aegis101 Security report executive summary showing risk distribution and top category drivers
Authentic product view shown with retained regression data. Public sample content is fictional and sanitised.

Distinct risk domains

One assessment discipline, domain-specific interpretation

Security and Operability are not blended into a single generic score. Each domain keeps the concepts and language needed for credible risk decisions.

Security

Residual security risk and control weakness

Assess exposure, control strength, material exceptions, treatment priorities, and the evidence needed to support closure. Security reporting does not publish impact as a separate score.

Operability

Service consequence and operational control

Assess supportability, recoverability, monitoring, change, resilience, and operational ownership. Service consequence is interpreted from context and described qualitatively.

Aegis101 Core

A stable assessment foundation

Core Security and Operability logic provides the risk foundation: contextual routing, answer interpretation, prioritisation, remediation direction, and reassessment.

Framework portfolio

Framework-specific views without losing their meaning

Frameworks are added through governed, framework-specific mappings and language. NCSC CAF v4 is the first implementation, presented as a mapped screening view and direction for further review, not a formal CAF assessment.

How Aegis101 approaches frameworks

Bring structure and clarity to your next risk conversation

Register your interest to discuss Security, Operability, framework-specific reporting, or a controlled evaluation of Aegis101.