Skip to content

FAQ

How does risk acceptance work in the platform?

Section titled “How does risk acceptance work in the platform?”

Within the Adversarial platform, the risk acceptance process is driven by assigned Urgency and the Due Date. When we accept a risk, we are really referring to downgrading the urgency of a risk. With a lowered urgency and an “accepted risk,” the security team may be determining that this risk is not worth fixing, so an urgency of Info would allow you to capture the details and track the risk without assigning a due date.

Additionally, the concept of transferring a risk would really be downgrading/lowering the impact of a risk (e.g., covered by Cyber Insurance). Finally, avoiding a risk is really downgrading/lowering the likelihood.

How do I handle issues and policy exceptions?

Section titled “How do I handle issues and policy exceptions?”

Issues are captured in how we use the term “Risks.” You can think of “Risks” as what ServiceNow calls “Issues, Problems, or Threats (IPTs)” – inclusive of vulnerabilities, audit findings, self-reported issues, and more. The approach is to be source-agnostic so all sources can be scored with the same rubric.

Policy Exceptions: The platform’s approach is inclusive of policy exceptions. Example: 25 workstations that cannot have full disk encryption. Log the exception as a risk, copy or author the supporting details, and use AI scoring to assess likelihood and impact. The recommended path is to capture these as a Risk with the Type set to Control Deficiency or Procedural.

Empty risk records can be deleted if there are no data or tickets associated with them. Deletion will not cause auto-renumbering. Additionally, if no data was inputted, the risk record can be reused for a new risk.

Filter Views help users quickly organize the data in the registers. Custom filter views are private to the user.

  • To create: Select the filter icon, choose fields and values, click Save then Create New View.
  • To update: Add or remove filters, click Save then Update.
  • To rename or delete: Open the filter drop-down and select the pencil icon.

Filter Views complement Item Tags for granular views.

Quick Filters are one-click filters available to all users directly in the filter bar. The platform has built-in filters for the below:

  • Overdue — surfaces records that are past their Due Date and not yet closed. Available only for the Risk Register.
  • Assigned to Me — narrows the register to records assigned to the current user. Available on both the risk and incident registers.
  • Mentions Me — narrows the register to records with at least one comment that @-mentions the current user. Available on both the risk and incident registers.
  • Upgraded — Displays risks whose urgency has increased compared to their initial assessment recorded via the Initially Reported Urgency field. Logic: - Current Urgency > Initially Reported Urgency (IRU). This filter is a risk register item only.
  • Downgraded — Displays risks whose urgency has decreased compared to their initial assessment recorded via the Initially Reported Urgency field. Logic: Current Urgency < Initially Reported Urgency (IRU). This filter is a risk register item only.
  • Show Child Risks — Displays risks that have been associated to a Parent risk. Prior to searching for a child risk, ensure this filter is enabled.
  • Parent Risks Only — Narrows the register to risks that have at least one child risk linked under them. This filter is a risk register item only; the incident register has the equivalent Parent Incidents Only.

How do I select a range of users in a filter?

Section titled “How do I select a range of users in a filter?”

The Opened By, Updated By, and Assigned To filters support shift-click range selection: check one user, hold Shift, and click another to select everyone listed between them. This is quicker than clicking each user individually when selecting most of a long list. See Quick Tips for this and other multi-select shortcuts.

Can I share a filter view with another user?

Section titled “Can I share a filter view with another user?”

Filter views are user-specific and cannot be shared directly. However, you can share via URL: open the filter view, copy the page URL, and send it to another user. They will see the same filter parameters applied.

How do I handle new information and rescoring?

Section titled “How do I handle new information and rescoring?”

When subsequent investigation surfaces new information, record it in Comments and re-run AI Suggest Score. Review Likelihood and Impact. If the rationale aligns, save the updates. Previous AI comments can be deleted before rescoring to avoid influencing the new run. Rescoring is also useful when a risk has been partially mitigated via a compensating control.

There are three ways to track risks:

  1. Follow an RSK – Updates are communicated via in-platform notifications (bell icon).
  2. Assigned To – Users in this field automatically receive notifications for all changes.
  3. Notification Subscriptions – Via Settings, subscribe to urgency-driven risks, severity-driven incidents, threat-based incidents, and new entries.