Risk AssessmentMITRE ATT&CKRisk AssessmentFinancial Services

Threat-Informed Risk Assessment

Methodology for mapping MITRE ATT&CK techniques to control environments in financial services, with evidence-based coverage validation.

Updated 2026-07-18

Interactive artifacts included below — CRI Assessment Workpaper, CRI Threat Advisory Report.

Situation

Community bank needed to demonstrate CRI Profile v2.2 coverage to regulators. Traditional keyword-matching approaches produced inconsistent results that didn't survive examiner scrutiny. No existing methodology mapped controls to CRI diagnostic statements with evidence traceability.

Responsibility

Tristan designed the entire assessment methodology end-to-end — from control profiling taxonomy through multi-stage reasoning pipeline to final coverage workpapers. No existing template or framework to follow; built from first principles using NIST, CRI, and MITRE source materials.

Judgment

Chose a threat-informed approach (MITRE ATT&CK techniques mapped to CRI requirements) rather than simple keyword matching. Designed deterministic rules for consistency with AI-assisted analysis only where human judgment would be inconsistent. Built in human review gates — AI never makes final coverage determinations unsupervised.

Deliverable

Complete assessment methodology with: control profiling classifier (18-verb taxonomy, 7 dimensions), CRI Response Guidance decomposition into assessable capabilities, multi-stage coverage pipeline, interactive workpapers with Coverage Decision Records, and findings taxonomy.

Evidence

PR.AA-01.01 workpaper assessing 568 controls against 16 capabilities. Every verdict traceable from requirement → control → evidence → rationale → conclusion.

Outcome

Methodology produces defensible coverage determinations. 31% Covered, 69% Partial for pilot DS — identifies specific gaps (service account governance, continuous privilege monitoring) with remediation guidance. Assessment artifacts survive examiner review because every conclusion links to source material.

What I Would Discuss in an Interview

How I balanced AI-assisted analysis with human accountability. Why threat-informed (MITRE) context matters for severity calibration. How the methodology handles disagreement between automated and human assessments. The design decision to separate knowledge, reasoning, quality, and reporting layers.

Artifacts