Skip to main content

From risk to treatment Plan: how to link risk and actions in Tenacy

In Tenacy, an action is never linked directly to a risk: it always goes through a security measure. Understand this mechanic and how it connects suggested measures, implementation actions, and treatment plans.

When facing a risk, a CISO's instinct is often the same as in any risk management approach: define actions to address it. This is a legitimate reflex, but in Tenacy, these actions are never linked directly to a risk. They always go through an intermediary: the security measure. This article is aimed at CISOs and pilots who want to understand this mechanic specific to Tenacy, so they can naturally translate their risk treatment instinct into the platform's model.

Why Tenacy reasons in measures, not actions, when facing a risk

In everyday risk management language, people readily speak of "risk treatment actions" or "remediation actions." This is a natural shortcut: it is indeed concrete actions that ultimately reduce risk on the ground.

In Tenacy, this shortcut does not match the data model. An action is never linked directly to a risk: it is always linked to a security measure. It is this measure, and this measure alone, that is linked to the risk.

This choice is not arbitrary. The security measure is Tenacy's pivot object: the one that consolidates compliance and risk treatment. A single measure can both satisfy a requirement from a compliance framework (ISO 27001, NIS2, etc.) and reduce one or more identified risks. If actions were linked directly to risks, this consolidation would disappear: each framework and each risk would require its own actions, without building on work already done elsewhere on the same measure.

💡 The key translation to remember: when you think "I need to launch an action to treat this risk," think in Tenacy "I need to identify the suggested measure for this risk, then implement it via an implementation action." The link to the risk is then made automatically, as described in the following sections.

What is a risk treatment plan?

When a risk is created in Tenacy, whether from the catalog or a risk analysis, the platform proposes a set of security measures likely to reduce it: these are called suggested measures. The risk treatment plan is the set of measures you have chosen to target — meaning those you commit to having implemented or improved, as they form the strategy selected to reduce this risk.

Each targeted measure contributes to defining the target level of the risk: the level it will reach once all the measures in its treatment plan are fully implemented and effective.

How a suggested measure connects to an action or an implemented measure

When you target a suggested measure, Tenacy automatically determines its progress by checking, for the risk's scope, whether an action or measure already exists:

  • If the risk's scope already benefits from an implemented measure derived from this suggested measure (the security control concretely in place), Tenacy links this implemented measure to the treatment plan: it appears as implemented.

  • Otherwise, if the scope benefits from an ongoing implementation action for this measure (the project aimed at putting it in place), Tenacy links this action to the treatment plan: the measure appears as being implemented.

  • Otherwise, the measure simply appears as targeted, pending an action or implemented measure to make it concrete.

💡 Note that in the first two cases, it is always the measure that carries the link to the risk: the action, when it exists, is only visible in this link through the measure it implements.

The automatic link between implementation actions and risks

This link, though indirect, does not only work at the moment of targeting: it also updates automatically as you work on your actions.

  • Creating an implementation action or adding a beneficiary: when a scope becomes a beneficiary of an implementation action (including at creation), Tenacy checks each risk in that scope. If the measure implemented by the action was targeted in the treatment plan, the measure is updated and moves to in progress, and the risk is therefore indirectly linked to the action.

  • Removing a beneficiary: if a scope is removed from the beneficiaries of an implementation action, the link between that action and the risks in that scope is deleted.

💡 The same principle of automatic association and dissociation applies to implemented measures: adding or removing a beneficiary scope from an implemented measure updates its links with the risks in that scope, following the same logic as for implementation actions.

What happens if you remove a measure from the treatment plan?

Removing a measure from a risk's treatment plan triggers the following rules:

  • If an implemented measure was linked to the risk, the final action is no longer linked to the risk to be treated.

  • If an implementation action was linked to the risk, the final implementation action is no longer linked to the risk to be treated.

💡 To learn more about a risk's treatment rate, refer to this article.

Expected result

Once your measures, actions, and risks are linked, your treatment plan stays up to date in real time in Tenacy. Every progress update on an implementation action, or any status change, is automatically reflected in the current risk level, with no manual re-entry on your part. The target level, on the other hand, only changes if you explicitly modify the composition of the treatment plan.

Did this answer your question?