Risk Management - Business Model

This page contains the business model for the Risk Management tool. The ENACT Risk Management helps to detect, identify and assess the risks of the IoT application along with the mitigation actions which are actionable items against DevOps cycle.

Alt text

Main Contributor

Partner: Beawre

Category: Industrial

Type: Risk Management Software Provider

Lean Canvas

Problem

Customer needs, requests and opportunities from the market

Companies in highly regulated markets lack mechanisms for continuously monitoring risk evolution. In particular: - Systems and processes complexity grows, human control is the new risk - There are no tools to effectively monitor mitigation efficiency - Risk is multi-stakeholder and assets need to be understood in context

Existing Alternatives

Companies are currently using not suitable mechanisms such as excel (which does not allow for real-time control, specially when complesity scales up) or commercial tools for risk management (which tend to focus on risk management at design time).

Solution

ENACT Result

Risk Management Enabler (Tool)

Exploitation Form

Exploitation of Risk Management Technology through making core technology available through the Eclipse Open Source Community using an EPL license and offering a commercial version following a SaaS model

IPR Background 

MUSA Risk Assessment tool was developed by us (when still at CA Technologies) and made available as open source to the community.

Description 

We are offering a SaaS solution to efficiently perform continuous risk management in highly regulated environments.

Type

We will offer 2 versions: Open Source (through Eclipse Foundation) / Propietary Software (as SaaS)

Key Metrics

KPIs

KPI1: At least 2 potential customers testing the tool by the end of 2019, KPI2: At least 4 paying customers using the tool by the end of 2020

Time To Market / TRL at the end of the project

We expect to have a first minimum viable product (TRL 7-8) by the end of 2019. We expect to have a full commercial version with paying customers by the end of the project.

Unique Value proposition

Value added by the solution

Thanks to Beawre's Risk Management Enabler: - Process-based real-time risk analysis and mitigation automation will be possible: Real-time risk re-assessment based on current system status. Live dashboards to control system health - You will be able to measure mitigation effectiveness through evidence collection: Feature implementation monitoring, operations’ data, etc. Including both privacy and security mitigation - Support for legal regulation compliance with multiple stakeholders will be enabled: Transparent mechanisms for multi-actor accountability and response orchestration when risk control is mandatory

Unfair Advantage

We have a strong network of potential customers we have been nurturing for several years and this gives us market penetration capacity.

Customer Segments

Type

App Developers, App Operators and App Owners

Potential customers

Software companies building Trustworthy IoT Systems in highly regulated markets or dealing with highly sensitive information. i.e. software companies creating e-health solutions in the IoT space to monitor patients remotely. In general, these customers need to be compliant with existing regulations that impose risk management (e.g. ISO27001)

Segment

Early adopters: e-health system providers through IoT systems. The core technology is generic and it can be exported to other highly regulated sectors such as construction or the automotive sector.

Channels

Promotion

We will use different channels including at least: - Our direct network of potential customers - EclipseCon to reach the Eclipse community and through the Eclipse Foundation dissemination and promotion tools - Our website: beawre.com - Attending to fares such as the IoT Solutions World Congress - Through our own salesforce

Distribution

The solution will be distributed as open source through Eclipse Foundation communities and repositories. The commercial version to be offered as SaaS and hosted in our own servers.

Cost Structure

Cost of implementation 

Cost related to the implementation of the MVP

Cost Sources

- 2 full-time engineers developing the MVP - cost of servers to host our SaaS - cost of 2 resources managing business aspects and sales

Revenue Streams

Sources of financing foreseen after the end of the project 

We expect our company to be sustained by our customers. We may look for additional funding from innovation and research programs as a way to continue investing in innovative approaches.

Revenue Sources

Customers through a pay-as-you-go license to use our risk management solution Customers through ad-hoc project to create tools adapted to their needs and integrate our solution with their digital ecosystems.