Visiminds Technologies, home

Thematic analysis, risk and threat modelling

Turns the findings you already have into decisions

Ivy Farsight reads the security findings your company already has, from audits, scanners and reviews. It groups them by the problem behind them, shows where the risk sits, and plans the actions that lower it most. It runs on your own machine.

For security leaders, risk and compliance teams, and the engineers who fix what the findings show.

A dataset of thousands of findings becomes a few themes and one plan that says what to do first and the risk it removes

How it works

From a findings file to a plan of actions

A findings dataset (A table of the security findings a company already has, from audits, scanners and reviews, with one finding on each row. Usually an Excel workbook or a CSV file.) goes in. Themes, a risk view, a plan for three kinds of reader and threat models come out. Fixed rules set every number, so the same data and settings always give the same result.

  1. Read

    Your Excel, CSV (Comma separated values. A plain text table, one row per line, that any spreadsheet can open.), TSV (Tab separated values. A plain text table with a tab between the columns.), JSON (A plain text file format for data.) or BSON (Binary JSON. The file format MongoDB exports its records in.) export. Ivy Farsight suggests a column mapping (Which column of your file holds which field Ivy Farsight reads. It suggests a match for each column, with its reason, and a person approves it.), and a person approves it. Each finding keeps its row in your file.

  2. Group

    Findings with one cause become one canonical issue (One underlying problem that many findings describe. Findings that agree on their control, threat path, text, assets and timing are grouped into one canonical issue.). Issues roll up into risk themes (A group of canonical issues that management can steer as one topic, such as vulnerability management or access control.) for management.

  3. Rate

    Inherent risk (The risk before any control is counted: how likely it is, multiplied by how much harm it would do.), residual risk (The part of a risk that is left once the controls in place are counted.) and a priority, each with its formula and its inputs.

  4. Plan

    Control options, an order of actions, and the risk left after each one.

Findings become canonical issues, then themes, then risk concentration, then actions, then a measured risk reduction

An overview first, detail when you need it

The overview

The total findings and the assets they touch, with a short summary of the threats, the vulnerabilities and the controls. Then the themes and control domains, each with the number of assets affected.

Two views

An executive view of the whole picture, and an asset owner view of one owner's assets, findings and remediation priorities.

Down to one finding

Open a theme or a domain, filter to an asset, and inspect one finding. Each level says what needs to be done, and you can ask how to mitigate a finding.

Explain and confidence

An Explain button on each figure shows how it was worked out, with the likelihood and the impact behind a risk. A confidence score shows how sure the analysis is.

Grouped by cause, not counted one by one

Thousands of findings often come down to a few problems. Ivy Farsight finds them, and shows its working.

Four findings that describe the same problem merge into one canonical issue under five weighted checks, while a weaker match waits for an analyst

Findings that describe one problem become one issue

Many findings share one weak control. Counted one by one, the cause stays hidden. Ivy Farsight compares findings on five parts, and groups the ones that agree.

Each member of an issue shows its score, the points of each part, and the reason in words.

  • 80% or more: the finding joins the issue
  • 65% to 79%: a near duplicate (A finding that is close to a canonical issue, but not close enough to join it by rule. An analyst decides whether it joins.), held for an analyst to confirm, move or keep apart
  • Below 65%: the finding stays on its own

The score, with weights you can set

Shared control
30%
Threat path
25%
Finding text
20%
Asset and exposure
15%
Recurrence and time
10%
The portfolio opens into a theme, the theme into a canonical issue, the issue into a service and the service into one finding

Themes you can open, down to one row

Issues roll up into themes that management can steer, such as access control or patch hygiene. Themes form from a shared control weakness, a shared threat path and where the assets concentrate. Each theme says why its issues belong together.

Every level opens to the one below it: theme, issue, service, finding, and the original row of your file.

Two bars per theme compare the first and the second quarter, with one theme improving, one persistent and one deteriorating

Quarter against quarter

Each theme compared with the quarter before: improving, persistent or deteriorating.

Findings placed by how long they have been open, some past the service level agreement line, with the oldest flagged

How long findings stay open

Findings by days open, with the ones past their SLA (Service level agreement. The number of days a finding of its severity may stay open. After that it is overdue.) flagged, oldest first.

Risk with its working shown

Every score has a formula and its inputs. Rules draft the options and the plan. People decide.

Likelihood four times impact five gives inherent risk twenty, controls at sixty per cent effectiveness leave residual eight, inside the appetite of ten

Risk you can work out again

Inherent risk is likelihood multiplied by impact. Residual risk is the inherent risk multiplied by one minus the control effectiveness (How much of a risk the controls in place remove, as a share from 0 to 100 per cent.).

The priority then adds the context: how critical the asset is, how exposed, how easy to exploit, and whether the problem keeps coming back. For any issue, "How is this calculated?" shows each input, so you can work the score out again.

  • Each top issue says why it ranks where it does
  • Try another business context and see the ranking move. Nothing is saved
Three control options for one issue compared on risk reduction, residual risk, effort and time, with one recommended and the work phased into now, next and later

Options side by side, and a path to take

For each issue there are two or three control options. Each shows the risk it removes, the risk it leaves, the effort, the days, and what may block it. Each names the issues and findings it covers.

A recommended path follows: a quick win, a strategic fix and a compensating control, with the risk left after each.

  • A person accepts, modifies or rejects each step, with a reason
  • Change an option's effectiveness, and every number that depends on it follows
  • Each decision keeps the name of the person and the time
A step chart of residual risk that falls with each planned action, crosses the risk appetite line after the fourth action, and ends at the risk left after the plan

The risk after each action, against your appetite

The plan applies the actions in order and works out the risk again after each one. A chart shows the risk falling, your risk appetite (The amount of risk a company decides it is willing to accept.) line, and the action that brings the risk within it.

Each step equals the step before, minus what that action removes. So the chart and the numbers always agree.

A remediation plan for each reader

One remediation plan shown three ways: leadership sees the risk fall and the top five issues with the decisions to make, managers and leads see the work on a 30, 60 and 90 day board with accept, modify and reject, and security staff and developers see numbered steps with the version to reach and the CVEs to close

One plan, three readers

The remediation plan is one set of figures. Each reader gets the view they need, so management and the engineers talk about the same numbers.

Every step names the issues and findings it addresses, and the rule it came from.

Leadership team

The risk now and after the plan, the top five issues and why, and the decisions to make.

Managers and leads

Work for each owner on a 30, 60 and 90 day board, and the recommended path to accept, modify or reject.

Security professionals and developers

Numbered steps with commands and checks, the host, the IP address and the version to reach, and the CVEs (Common Vulnerabilities and Exposures. The public identifier for one known vulnerability in one product.) each step closes.

The steps come from 1,162 remediation rules written by Visiminds, each with references to NIST SP 800-53 Rev. 5, ISO/IEC 27001:2022 Annex A and CIS Critical Security Controls v8 safeguards. The effectiveness of each step is a planning assumption until a person validates the fix.

Assets and known vulnerabilities

The vulnerability data covers 18 products today, and it is updated only when a person chooses.

An asset with its product and version is matched against vulnerability data kept on the machine, gets its CVEs with one known to be exploited and a fix version on the same release line, and is placed in one of four bands from fix now to monitor

Every asset, its version and its CVEs

Each asset's product and version are matched to the CVEs that affect it. The vulnerability data is kept on your machine: version ranges from the NVD (National Vulnerability Database. The public database of CVEs kept in the United States, with the product versions each one affects.), the CVE List, CISA's (Cybersecurity and Infrastructure Security Agency. The cybersecurity agency of the United States. It publishes the list of known exploited vulnerabilities.) Known Exploited Vulnerabilities (Known Exploited Vulnerabilities. CISA's list of vulnerabilities that attackers are known to have used.) catalogue and FIRST's (Forum of Incident Response and Security Teams. A global forum of security response teams. It publishes the EPSS scores.) EPSS (Exploit Prediction Scoring System. A daily score for how likely a vulnerability is to be exploited in the next 30 days.) scores.

Each asset falls into one of four groups, Fix now, Next 30 days, Plan or Monitor, with the reasons. An asset with a known exploited CVE is never below the second group.

  • The fix version stays on the installed release line (The versions of a product that share their first numbers, such as 5.15. A fix on the same line is a smaller change than a move to a new line.) where that line has a fix. Otherwise the step names the newer line it needs.
  • Each step says how many of the asset's CVEs it closes

Two threat models

A threat model (A list of what could go wrong in a system: its parts, the boundaries between them, and the threats against each, with how serious each one is.) of the estate drawn from the findings, and one of a running application drawn from its files.

Zones and services drawn from the dataset, with a rated threat list and a path resting only on findings that exist

A threat model of your estate, from the findings

Ivy Farsight draws the zones, the services in them and the trust boundaries (Where data passes from something you do not control into something you do.) between them, with a rated register of threats. Each threat has its STRIDE (Spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege. The six kinds of threat used in threat modelling.) category and the findings behind it.

A path is drawn only where findings show it. Anything inferred is labelled as inferred.

The application's deployment files, each fact kept with its file and line, become a data flow diagram with internet, data zone and third party boundaries, a threat is marked on one flow, and after a fix the threat is rated again and validated by a person

A threat model of an application, from its own files

Ivy Farsight reads an application's deployment files: its container setup, its OpenAPI (A file that describes an API: its routes, its inputs, and how callers sign in.) description and its software bill of materials (Software bill of materials. The list of every part your software is made of, with versions.). Every fact keeps its file and line. It drafts a DFD (Data flow diagram. A drawing of the parts of a system and the data that moves between them, with the trust boundaries the data crosses.) with the trust boundaries, and threats against named parts and flows.

A person confirms, edits or rejects each part. For each high threat there are two or three options, and a ticket a developer can act on. After a fix, the threat is rated again once a person validates the fix.

  • Each threat shows why it scored as it did, and which facts moved the score
  • The turnaround time (The time from a request to its signed off result, such as a threat model from intake to sign-off.) is measured stage by stage, from intake to sign-off

Figures you can trace and check

A figure with a source chip opens a panel that shows its formula and inputs, the columns it used, the original row of the uploaded file with the cells it used marked, the outside records with their dates, and the fingerprint of the file

Every figure opens to its source

Each score, theme, issue, asset, CVE and threat carries a Source button. It shows what the figure is, its formula and inputs, the columns and rows used, and the original row of your file with the cells it used marked.

Outside records show their dates. The file keeps its SHA-256 (A code worked out from every byte of a file, used as its fingerprint. Any change to the file gives a different code.) fingerprint, so you can prove which file an analysis read. This is the figure's provenance (Where a figure comes from: the file and its row, the columns and formula used, the outside records, and the person who decided.).

Seeded benchmark answers stay behind a wall while the engine runs and are compared with its output only afterwards

Checked against expected answers

Visiminds checked Ivy Farsight on an anonymised reference sample that came with expected answers. The expected answers are never inputs: they are kept apart during the run and compared only afterwards.

Measured on 2 October 2026: Ivy Farsight found all 12 canonical issues and all 10 themes of the expected answers, in 100% agreement.

Questions answered from your own analysis

A question answered from the dataset and the rules inside the product, with the figures it used linked, and nothing sent away

Ask Farsight

Ask questions in plain words: why these findings were grouped, what drives a score, what to fix first. The answers come from the analysis and from fixed rules. This is rule-based AI (AI built from fixed rules that can be read, not from a trained machine learning model. The same data and the same question always give the same answer.): the same question always gets the same answer, and a question it cannot answer is declined.

It understands the ids of findings, issues and themes, hostnames, IP address ranges, CVEs, versions, conditions such as "residual above 15", and requests to group or rank.

  • A local language model (A text model that runs on your own machine, with no internet connection. In Ivy Farsight it only words the facts the rules worked out, and never changes a number.) can word the answer, on your machine only. You switch it on or off
  • The model never changes a number. A check names any number in its text that is not in the facts

Live datasets of your own

For exports of the same kind, again and again: Excel, CSV, TSV, JSON or BSON, with no size limit by default.

An export with its own column names is mapped to the schema, each column with a confidence, approved by an analyst and saved as a profile, then later snapshots arrive on a schedule or through an inbox, and two snapshots are compared

Your own export, mapped once and run again

Ivy Farsight finds the header row and the sheet, also in untidy files. It suggests which column holds which field, with a confidence and a reason, and saves the approved mapping as a profile for the next export.

Before a run it shows what it will tidy, such as dates and severities, and it keeps every original value.

  • Snapshots (One export of your findings at one point in time. Two snapshots can be compared.) on a schedule, every hour, every 6 hours, every 12 hours, every day or every week, from an address on your local network or an inbox folder
  • The same file is not analysed twice. Two snapshots can be compared
  • Measured on 2 October 2026: a 100,000 row export, end to end, in about 40 seconds
A spreadsheet with only some of the columns passes the check gate, the present columns are ticked and the missing ones are listed

A file with fewer columns still runs

The full schema has 142 columns, and only 4 are required: an id, a status, a severity and a title. Ivy Farsight uses what is there.

Each part of the analysis names the columns it lacked, so a gap is never mistaken for a clean result.

Reports, the API and the limits

One analysis producing an HTML report to read in the browser and a PDF report with chapters to file

Reports, and files for other tools

Every analysis writes an HTML report to read and filter, and a PDF report to file. Both come from the same content, so they agree.

Ticket files for Jira, ServiceNow, Azure DevOps and CSV, and a risk register for an IRM (Integrated risk management. The tool where an organisation keeps its risk register.) tool. Your team imports them. Ivy Farsight sends nothing to them by itself.

On one machine, the console and your own scripts call the same API, which drives the engine, the analyses kept on disk, the vulnerability data and an optional local language model, while a cloud outside is crossed out because nothing is sent away

One machine, and every action through the API

Ivy Farsight runs on your own machine, with no internet connection. The analyses, the vulnerability data and the optional language model stay on it.

Everything the console does is a call to its API (Application programming interface. The interface one program uses to talk to another.), with a published description and a guide. Your team can script the same steps.

  • Rules, reports and mappings can be adapted to your needs, and to the regulations of your country or region

Ask for a demo of Ivy Farsight

Write to info@visiminds.com. We can show it on a sample dataset, or on an export of your own findings, on your own machine.