MetricStream enables customers to quantify risks in monetary terms, identify cloud risks and report climate-related financial metrics

DigitalCFO Newsroom | 4 April 2022

MetricStream announces it’s latest product release, Danube, designed to enable customers to successfully navigate an increasingly connected GRC world

MetricStream, the global market leader in integrated risk management (IRM) and governance, risk, and compliance (GRC), today announced its latest product release, Danube, designed to enable customers to successfully navigate an increasingly connected GRC world. The Danube release includes advanced risk quantification, automated compliance across cloud environments, and support for the Task Force on Climate-Related Financial Disclosures (TCFD), providing a framework to assist customers with climate-related financial risk disclosures. Key innovations include the following: 

  • Enhanced risk quantification for enterprise and operational risk management enables customers to score, prioritize, manage, and report risk and loss exposure in monetary values.  
  • Continuous control monitoring for cloud environments allows organizations to follow best practices by actively and continuously monitoring critical cyber controls, identify risks, measure effectiveness, and automate compliance. 
  • Customers can now leverage the TCFD standards as a framework to capture climate-related risks and generate standard financial impact reporting.  

“The common theme for today’s announcement is centered on providing advanced measurement tools, whether evaluating risk across the enterprise, developing a cyber strategy, or establishing ESG metrics,” said Prasad Sabbineni, Chief Technology Officer, MetricStream. “Gone are the days that heat maps drive risk decisions. Much like we measure financial risks, GRC professionals now have access to risk metrics that enable them to more accurately identify, manage, and report risks in a language that board members can understand and with the speed that is required to be proactive.” 

BusinessGRC: Advanced risk quantification across the enterprise 

New risk quantification capability is built on MetricStream Intelligence, an advanced analytical and artificial intelligence (AI) engine that enables multiple scoring models and data science tools. This includes Monte Carlo simulations and modeling based on multiple variables. Customers can also generate a range-based estimate and predict the probability of different outcomes for annual loss expectancy. Risk quantification allows the board and executive management to gain a quick and accurate understanding of the relative importance of each risk, prioritize strategies, and make more informed decisions. 

CyberGRC: Automated compliance for cloud environments 

Customers with cloud-hosted environments now have the option of automating compliance and control testing through Continuous Controls Monitoring (CCM). With automated validation of cloud environments across multiple cybersecurity standards and frameworks, CCM delivers continuous testing, measurable results, and verifiable evidence. This alleviates the need to invest in labor-intensive efforts to identify risks while ensuring compliance with cybersecurity standards and frameworks. 

ESGRC: Simplified disclosure of climate-related financial risks  

MetricStream ESGRC now supports the TCFD framework for organizational governance best practices associated with climate-related financial risks and opportunities. MetricStream ESGRC’s TCFD features enable users to automate data gathering for a broad range of metrics required for ESG financial risk disclosure and centralizes management of disclosure reporting. 

The Danube release represents more than two dozen new product innovations and includes self-service reporting, low code and no code tools for easy configuration, and advanced AI and ML capabilities to identify and rationalize duplicate controls. Anonymous case and incident reporting for witnesses and observers, enhanced data on third-party financial reporting, and sustainable sourcing practices are also included. Customers can additionally benefit from the inclusion of more than 900 cybersecurity controls and best practices pre-built into the product, as well as evidence management for audits.