← All guides

Interpretation · Guide 09

Assumptions the tool makes

Defaults, conservative choices and modelling shortcuts that must remain visible before anyone treats the output as a decision.

Begin reading

Every risk model contains assumptions. A trustworthy tool does not hide them behind polished diagrams or precise percentages; it makes them visible, configurable where appropriate and reviewable over time.

Cyberkit Bowtie uses several defaults to keep assessments consistent. They are starting points, not universal truths.

New roadmap measures start at Defined

When the improvement roadmap evaluates adding a missing measure, it assumes the proposed capability will be implemented at Defined maturity. The candidate means “implement this measure properly,” not “buy a tool and operate it ad hoc.”

Scoring every proposed measure at Initial would make additions appear nearly useless. The roadmap assumption creates a comparable target, but the resulting benefit depends on actually reaching that maturity.

Template measures start at Initial

A template can suggest which measures should exist, but it cannot know how well a specific organization operates them. Template-instantiated measures therefore begin at Initial maturity until assessed.

The first real task after using a template is to walk the shared measures, identify owners and enter supportable maturity levels. A pre-filled diagram is not a completed assessment.

Environmental threats do not gain from attacker levels

Motivation and adaptive capability make sense for human adversaries, not storms, component failures or other environmental sources. The model limits the security-level interpretation used for environmental threats.

This avoids crediting protection because it can withstand a sophisticated attacker when the relevant question is resilience against a non-adaptive event.

Missing external capability defaults conservatively

When an external actor capability is not supplied, Cyberkit uses a conservative default rather than silently selecting the easiest attacker case. The exact default belongs to the methodology configuration and should be visible to the analyst.

The better response is to document the relevant actor range and test how the result changes across plausible capabilities.

Chains override manual downstream frequency

When a downstream threat receives a propagated frequency from an upstream consequence, that value drives the active calculation. The manually entered value is retained but inactive until the chain is removed or switched to link-only mode.

This prevents two competing frequencies from being combined silently.

Bowtie risk uses the maximum path

The summary risk for a bowtie is the highest risk among its threat–consequence pairs. It does not average good and bad paths.

This is deliberately conservative for prioritization. Management should still inspect the distribution of paths; two bowties with the same maximum can have very different risk profiles.

Independence is asserted, not discovered

The multiplication of barrier reductions depends on independence. The software can warn about obvious duplication, but it cannot prove that organizational, technical and human dependencies are absent.

Analysts must challenge shared credentials, shared platforms, common administrators, correlated outages and other common-cause failures.

Manage assumptions as assessment data

For material decisions, record:

  • the assumption and why it was needed;
  • the owner or methodology authority;
  • the affected paths;
  • the version of matrices and templates used;
  • the date and trigger for review; and
  • the result of reasonable sensitivity tests.

If a small assumption change flips the decision, the model is telling you where better evidence is valuable.

Trust comes from inspectability

No default removes the need for judgement. The purpose of consistent defaults is to make two assessments comparable and to prevent missing data from creating accidental optimism.

Before accepting the output, reviewers should be able to answer: which values came from evidence, which came from methodology configuration, which were conservative fallbacks, and which uncertainties could change the decision?

Go to the source

Sources and further reading

Apply the method

Want to discuss this in your own risk model?

Keep the details high-level. We can start with scope, terminology and evaluation approach.

Ask about your use case