🎉 VSEC Test v4.3.1 is now live! Release Notes ↗

Creating Risks

Click New Risk at the top of the Risk Manager page to open the New Risk dialog. It has two tabs: Create manually and Import from file.

Create Manually

  • Assets — the asset(s) this risk applies to. At least one asset must exist in Asset Manager before you can create a risk. The first asset you pick becomes the primary asset; you can select more than one, and add or remove assets later from Risk Details.
  • Heading — a short title for the risk. Optional at this point — you can add or change it later.
  • Priority, Status, and Assignee — set these up front if you already know them, or leave them as-is and set them later from Risk Details.

Evidence (optional)

Below the fields above, click Add evidence to open the evidence section — it’s collapsed by default so a quick risk (heading and asset only) doesn’t feel like a long form. Attaching evidence here is exactly the same as adding it later on the Evidence card, it just saves a trip back to the risk once it’s created:

FieldDescription
SourceManual, Design, Test, or Monitor — where this finding came from. Defaults to Manual
ReferenceA CVE number, report id, or other external identifier
SummaryA short description of the finding
CVSS score0–10; feeds the risk’s Likelihood and Impact
Weakness stateThe ISO/SAE 21434 Clause-8 state — Event, Weakness, Vulnerability, or Not Applicable. Marking Not Applicable requires a Rationale
AttachmentsAttach one or more files to this evidence item — click Attach files

If you record evidence with source Design, Test, or Monitor, that source becomes the new risk’s origin (see Risk Origins). Leaving evidence out — or recording it as Manual — leaves the risk without an origin, shown as — until later evidence sets one.

A risk with no evidence can’t be scored yet. You can still create it and add evidence anytime — the dialog just warns you so a risk doesn’t sit unscored by accident.

Once you click Create risk, the new risk is created in Triage and the app opens its Risk Details page immediately so you can continue filling it in.

Import from File

Switch to the Import from file tab for bulk or automated intake from an Excel workbook:

  • Asset — a single asset (import only ever targets one).
  • Risk type — only Design can be selected; Test and Monitor are disabled because the importer only understands Design-shaped workbooks.
  • Risk file — an .xlsx workbook. See Import & Export for the required sheet and column layout.

Imported risks are created with the Design origin directly — there’s no evidence step here, since the workbook’s threat-model data (threat scenarios, attack paths, damage scenarios) is what feeds the score.

After Creation

From Risk Details:

  • Accept the risk to move it from Triage to Open.
  • Archive to set it aside (reversible from any state).
  • Click Edit (top right) to open the Edit risk dialog — change the Heading, Priority, or Status, then Save (or Cancel).
  • Use the Context tab to let the AI curate an understanding of the risk and propose field updates or suggested actions.
Last updated on