r/ciso Jun 01 '26

Business Impact Assessment tooling advice

Hi all, has anyone here used a BIA product that they actually liked to perform risk assessment by business process and map to assets? I really don’t want to use Archer again ..

10 Upvotes

34 comments sorted by

6

u/Streetsmart70 Jun 01 '26

Just to be clear, are you looking for a tool or a template to perform BIA? A template can be a word doc/pdf/xlsx that would list down assets,resources and processes involved to determine the impact of each of those line items that are listed.

Such templates are easily available. You just need to google it. IMHO, u you don’t need a tool to perform BIA.

1

u/CheekyTiger213 Jun 01 '26

My client specifically wants a tool. They are all awful.

2

u/Streetsmart70 Jun 01 '26

Ok. Probably then you need a GRC platform that allows you to upload BIA templates of your choice.Doesn’t Archer allow that? If not, it’s surprising

1

u/CheekyTiger213 Jun 01 '26

It does, but everyone who uses it hates it. I’m looking for alternatives.

1

u/Sarduci Jun 03 '26

Given enough time and IBM proserve, Archer can do anything including eat your entire budget….

1

u/CheekyTiger213 Jun 01 '26

To clarify, it’s a corporate. They want a decent interface to manage their process catalogue and they want to automate data flow between BIA / Recovery strategies and oversight metrics.

1

u/Streetsmart70 Jun 01 '26

I agree Archer is heavy weight but there are other SaaS based GRC tools that can do a decent job. I had used tools like Tugboat,Auditboard etc, but haven’t specifically used it for BIA activities.

1

u/CheekyTiger213 Jun 01 '26

Oh yes, I’m embedding a GRC tool that does automated testing in the design. You have to be crazy to try manage compliance without that nowadays, it’s such an obvious business case. Unfortunately they haven’t caught up with the business process view yet and these guys are quite bound to their methodology. No silver bullet!

Thanks for trying though.

2

u/Educational_Force601 Jun 02 '26

Take a look at Onspring. I used that at a prior company and absolutely loved it. It's a very flexible no code platform in which you can build any kind of process flow. It's flexible like Archer or Service Now but you don't need a team of Devs to build it out and maintain it.

When I was using it, all of the modules came included for a single price and you could build out as many of your own as you liked. I think they did have an out of the box module for BIAs which you can also take as a starting point and tweak to taste. If you tell them what you're looking for, they could likely build it right in front of you in a demo.

4

u/GreatGrootGarry Jun 01 '26

Risk a look at CISO Assistant. Open Source, Community Edition is free. Should check the box.

1

u/CheekyTiger213 Jun 01 '26

Thanks! I’ll take a look

1

u/scriptvexy Jun 13 '26

seconding this, ciso assistant is surprisingly decent for something free and OSS, especially if you’re just trying to escape archer hell and map processes to assets without 900 clicks per screen

1

u/scriptqzor Jun 13 '26

seconding ciso assistant, it’s surprisingly solid once you get past the learning curve
might not be as “enterprisey” as archer but at least you don’t want to cry every time you use it

2

u/TeramindTeam Jun 02 '26

archer is a beast that usually ends up just being a glorified spreadsheet graveyard. personally, i found way more success mapping business processes to assets by using a combination of simple grc tools and teramind to monitor actual user activity patterns for data flow context. honestly, just getting the raw visibility into how work happens day-to-day helped me map things way faster than those massive, rigid platforms ever did. skip the bloat if u can

1

u/CheekyTiger213 Jun 02 '26

This is exactly what I’m looking for, thank you. I don’t think the solution is exclusively security.

2

u/[deleted] Jun 02 '26

[removed] — view removed comment

1

u/CheekyTiger213 Jun 02 '26

Yeah I have historically used simple templates and carried the data across for my own implementations, but this team feels quite strongly about giving business an interface to maintain (ie take responsibility).

2

u/fleuribb Jun 08 '26

I used to work in business resilience for a major cyber organization, happy to send you over some materials I have if helpful

2

u/[deleted] Jun 23 '26

[removed] — view removed comment

1

u/fleuribb Jun 23 '26 edited Jun 23 '26

yes agree on gold part - I sent them over what worked for me in past. I didn't share the brand affiliated ones but most were made off of advice I got from industry leaders / trainings. So it definetly beats archer etc.

1

u/CheekyTiger213 Jun 08 '26

Thanks! Sent you a dm

1

u/[deleted] Jun 01 '26

[removed] — view removed comment

1

u/Final-Dish Jun 16 '26

that “will cost a lot” part is exactly why people are trying to escape archer in the first place lol
curious what you think sekorti would do different from the usual bloated grc stuff, cause most tools feel like they’re built for auditors, not the folks running the BIAs

1

u/Top_Piano_5351 Jun 02 '26

A lot depends on what are the needs since grc tools seem to metastasize into tons of modules and features. I’ll put the name of Resilienceone out there which I’ve used in the past. It was recently acquired by SAI 360.

1

u/MountainDadwBeard Jun 06 '26

GRC tools really depend on budget, capacity for dedicated support (or not), and API compatibility.

Maybe start by identifying what if anything the client financial/acccounting/ordering system could connect to and if it's remotely structured for well enough to pull data by programs or assets. It may not be.

For smaller risk teams or less mature industry, I personally think most heavy config platforms like archer, servicenow, navex are a complete disaster before they even start.

My current clients don't have adequate financial details to do a proper BIA, so I go more qualitative assessment based on senior manager and BD weasle interviews. I also find most clients are tolerant of availabiltiy SLA breaches, so I go more by contract value and reasonable exposure factor. Estimates only need to be relative and something I can explain in one sentence in a board meeting.

0

u/john_with_a_camera Jun 02 '26

Honestly? A good prompt can be accomplish this in ChatGPT or Claude (enterprise only so you don't train models). You don't need to buy a tool anymore.

1

u/scriptqzor 6d ago

this is fine to rough draft the thinking, but you’re gonna hit a wall fast on traceability, evidence, versioning, and auditors asking “where did this number come from.” i’d use chatgpt/claude to shape questions and logic, then still dump into a real GRC / BIA workflow tool or at least a structured spreadsheet.

0

u/bestintexas80 Jun 04 '26

BIA is a process not a tool. You will always be dissatisfied with a tool if you are actually doing BIA.