Skip to content
Fig platform · protect

Exposure ModellingConnected to the bigger picture.

Model how assets, vulnerabilities, suppliers and control gaps interact so teams can act on likely impact, not isolated findings.

IT specialist inspecting computer hardware
What this means for your team
  • Link technical exposure to business services.
  • Forecast risk concentration.
  • Support better risk and insurance conversations.
The practical difference

Understand how small weaknesses combine into business risk.

Individual risk scores do not show how weaknesses may combine across services and suppliers. Without a shared scenario view, teams struggle to compare exposure and plan a response.

01

Risk Aggregation

Bring available vulnerability, configuration and control-gap records into scenario views. Review input coverage, scoring assumptions and uncertainty before using a portfolio score to support a decision.

02

Scenario Modelling

Model exposure impact if a vulnerability remains unpatched, a supplier is breached, or a framework deadline is missed. Board-ready risk impact summaries.

03

Attack Path Mapping

Explore possible paths using connected vulnerability, configuration and permission records. Validate missing topology or permissions before ranking remediation options.

04

Customer-Controlled Evidence

Use documented scenarios and control records to prepare for a conversation with your chosen insurer, broker or underwriter. You decide what to share; the recipient makes its own underwriting and pricing decisions.

Inside Fig

See the work.
Keep the evidence.

Explore the asset mind map view within the Fig platform.

A tailored walkthrough lets you review the relevant workflows, supported connections and reporting before deciding whether Fig is right for your team.

See it in a demo
Fig asset mind map connecting internet exposure, identity, sensitive data, endpoints and critical suppliers
Fig mobile app Home screen showing framework compliance, monitoring coverage and device posture
Fig platform · Asset mind map
Built around your role

One platform. Different responsibilities.

Bring delivery, oversight and assurance together without losing sight of who owns the next action.

Colleagues working together with laptops in an office

MSPs & MSSPs

Portfolio-level risk aggregation across all clients. Scenario models and attack path analysis strengthen your managed security services pitch.

Explore Fig for MSPs
Business team discussing shared priorities

In-house teams

Board-ready risk dashboards showing exposure trends. What-if scenarios inform budget allocation and strategic risk decisions.

Explore Fig for organisations
Reviewing business records and supporting documentation

Compliance & audit teams

Risk assessment models and remediation prioritisation evidence for enterprise risk management and governance audits.

Discuss your requirements
A considered start

Evaluate the fit. Then agree the rollout.

Start with the outcomes you need. We will discuss scope, delivery and commercial terms with you before you commit.

  1. 1

    Tell us what matters

    Discuss your current approach to exposure modelling, the teams involved and the requirements you need to meet.

  2. 2

    Review the workflows

    See the relevant features in a tailored demonstration. Confirm integration coverage, responsibilities and any configuration needed.

  3. 3

    Agree your next step

    Review the proposed scope and pricing. Set implementation priorities, ownership and review points around your organisation or client portfolio.

Platform functionality and automation depend on the agreed scope, configuration and connected systems. Software supports your compliance programme; it does not replace an independent assessment or guarantee certification.

Before you decide

Your questions, answered.

Need to discuss a specific requirement or client scenario?

Speak to Fig
Is exposure modelling just a risk heat map?

No. Fig Group connects the available asset, vulnerability and control data to scenario analysis. A score is an estimate based on recorded inputs and assumptions, not a measured probability of breach or a forecast of insured loss.

Can we model third-party breaches?

Yes. You can model the impact of a supplier breach by running scenarios where that supplier's access rights are compromised, then tracing downstream exposure to your critical systems.

How does attack path mapping work?

Fig Group analyses connected vulnerability, topology, permission and configuration records for possible chains of weaknesses. Review source coverage and assumptions with your security team before acting on a ranking.

Can we use exposure models to justify budget requests?

Yes. Teams can use scenario outputs in budget discussions, with the source inputs, financial assumptions and uncertainty made clear. Validate any monetary estimate against your own business data before presenting it as an expected loss.

How often are exposure scores recalculated?

Scores can be recalculated when connected inputs change. Their freshness depends on each source and its last successful update; review stale or missing inputs before relying on a scenario.

Take the next step

See how exposure modelling could work for you.

Tell us what you would like to achieve. We will arrange a relevant conversation about the platform, your requirements and the right next step.

  • A walkthrough focused on your priorities
  • Clarity on scope, connections and delivery
  • A discussion of pricing for your requirements

Speak to Fig

Tell us what you need. We’ll help you take the next step.

A brief message is all we need to get started.