ForgeScore · Portfolio intelligence

One living picture of portfolio cyber risk.

Portfolio-scale cyber-risk intelligence for those who carry risk across many organisations — regulators and peak bodies, insurers, large enterprises, and the members, clients and supply chains connected to them. Assessed entirely from the outside, maintained as a living assessment, and closed with measured intervention.

The intelligence workspace

This is what a portfolio looks like.

The same console our analysts work in. Explore it: switch between graph, bar, pie and trend views, segment by risk band, BEC exposure or any of the four control clusters, and open a single organisation to inspect it. It runs on genuine ForgeScore data.

forgescore · intelligence workspace · … organisations
Segment by

Loading the workspace…

Intelligence-led · source-linked · calibrated likelihood
Third-party risk

You don't operate in a vacuum.

You can run your own controls impeccably and still inherit the cyber risk your third parties carry — your supply chain, your clients, your members. That exposure is real, and it sits beyond your own walls, where you have no visibility. ForgeScore assesses those third parties from the outside, so you can see the exposure, weigh it, and manage it — before it becomes yours.

The assessment

One score. Four dimensions of maturity.

ForgeScore is an intelligence assessment, not a verdict. Using analytical tradecraft, it collects against a set of diagnostic indicators for each of the four control clusters — the observable tells of how an organisation manages its cyber risk. From what those indicators reveal it derives a probabilistic assessment of maturity across the whole cluster: the reasoning being that where a handful of indicators show lapses, it is likely those lapses run through that cluster more broadly. The judgement is expressed in calibrated estimative language — Highly Likely to Highly Unlikely, with a separate confidence rating — and decomposes to the named factors beneath it. So “assessed as unlikely to hold positive control of its digital assets” is a defensible intelligence judgement — not the definitive, and indefensible, “has no control.” One score, 0–100, across four control clusters. No black-box numbers.

Cluster 01

Positive Control

Active, accountable management of an organisation's digital assets.

Cluster 02

Technical Controls

Assurance that security is competently applied and maintained.

Cluster 03

Proactive Security

Signals of active monitoring and response, not static defence.

Cluster 04

Identity Protection

How well identity is protected from impersonation and abuse.

A living assessment

Updated and adaptive to a dynamic risk environment.

A static score ages the moment it is issued. ForgeScore is maintained as a living assessment — run on a re-assessment cycle, and its indicators and weighting re-tuned by our analysts against RIPOSTE's DarkRose intelligence as the cyber-risk environment shifts. Because it is re-baselined rather than issued once, the assessment you act on reflects the environment as it is now — not a snapshot already ageing on the shelf.

Material indicator

Business Email Compromise

Most signals describe conditions that raise risk. BEC exposure identifies where the mechanism for direct client fraud already exists — a first-class indicator, surfaced, not buried.

Re-baselining is the feature

Honest to today's threat

When the method sharpens, some assessments move — and you are always told why. That is your risk picture staying true to today's threats, not last year's.

The difference

Control strategic risk strategically — and measure whether it's working.

Ratings grade the problem. ForgeScore closes the loop. It turns the risk picture into a campaign, holds a control group where you choose to, and re-assesses to measure the movement against it — an operations cycle, not a report. So “we ran a program” becomes an evidence-based read on whether the intervention moved the risk.

01

Collect

Assess the whole portfolio from the outside — no questionnaires, nothing to install.

02

Assess

Score, band and prioritise every organisation on one comparable scale.

03

Act

Auto-assign each cohort its response; hold a control group back to measure against.

04

Measure

Re-assess and quantify the movement versus control — measured improvement, not assumed.

Proof

A whole portfolio, measured in one pass.

Assessed to date

14,000+ organisations

across multiple continents and industry sectors.

Proven scale

10,000-org portfolios

run in a single pass — thousands down to one, on one system.

Zero participant burden

No one lifts a finger

Every organisation assessed externally — including the ones that would never return a survey.

Who it is for

Anyone who carries risk across a portfolio.

Regulators and peak bodies. Insurers and MGAs. Large enterprises — and the members, clients and supply chains connected to them. You may run your own controls impeccably, yet still be exposed to the risk those third parties carry. ForgeScore lets you see that exposure across the whole portfolio, and be serious about it.

How it works

Your portfolio in. Intelligence out.

You give us the portfolio — the organisations, plus any enriched detail you hold. The system does the rest, from external observation only: nothing installed, no questionnaires — read from your public, externally observable signals; findings scored, weighed and prioritised. Share more and we return more — add geography, for instance, and we surface geographic risk concentration too. Data-protection-by-design and GDPR-aligned. A partnership, priced by portfolio: RIPOSTE works alongside you on strategy and intervention, mission by mission.

See your whole portfolio clearly.

Book a walkthrough of the workspace, or bring us the book and we will show you what it looks like as one picture — assessed, prioritised, and ready to act on.

Start the conversation