Mercury Platform · Layer 03

Aurora™

Normalize. Score. Quantify. Optimize.

Aurora™ is Mercury’s proprietary scoring and quantification engine — transforming normalized asset, control, risk, and business-context intelligence into defensible, near-real-time risk scores. Using Mercury’s proprietary methodology, Aurora helps organizations understand where risk exists, what is driving it, and where action can create the greatest business impact.

Mercury MethodologyMulti-Domain ScoringBusiness-Context DrivenNear-Real-Time

From Evidence to Defensible Risk Intelligence

Aurora receives normalized intelligence from across the Mercury platform and applies Mercury’s methodology to calculate, contextualize, and continuously refine enterprise risk. The result is risk intelligence grounded in evidence, control performance, asset value, and business context.

Normalize

Create Comparable Risk Intelligence

Aurora brings structured risk inputs into a consistent scoring model so different technologies, controls, findings, assets, obligations, and business contexts can be evaluated on a comparable basis.

Score

Apply Mercury Methodology

Mercury’s scoring methodology applies asset value, control effectiveness, exposure, business impact, and contextual factors to produce numeric and explainable risk scores.

Quantify

Measure Risk That Matters

Aurora quantifies risk at the individual risk, asset, business process, domain, and enterprise level — allowing organizations to understand both individual exposures and accumulated risk.

Optimize

Prioritize by Business Impact

Aurora connects risk to business value so leaders can prioritize remediation and investment based on the risk reduction and value protection each action can deliver.

How Aurora Produces Defensible Risk Intelligence

Aurora combines asset intelligence, control effectiveness, risk conditions, business impact, and organizational context within Mercury’s methodology to calculate risk in a consistent and explainable way.

INPUT 01

Asset & Business Intelligence

A.D.A.M.™ provides normalized intelligence about the organization’s assets, products, processes, technologies, people, relationships, and business context — establishing what matters and why it matters.

INPUT 02

Controls Intelligence from ACET™

ACET™ provides evaluated control intelligence, including implementation, effectiveness, evidence, gaps, and related findings. Aurora incorporates actual control performance into its risk calculations rather than relying solely on assumed control states.

AURORA PROCESS

Mercury Risk Scoring

Aurora applies Mercury’s proprietary methodology across the available intelligence — combining exposure, asset value, control effectiveness, business impact, and contextual factors to calculate explainable risk scores.

OUTPUT

Enterprise Risk Intelligence

Aurora produces risk intelligence that can be analyzed at the individual risk, asset, business process, domain, and enterprise level — supporting prioritization, remediation, reporting, and executive decision-making.

From Inherent Risk to Residual Risk

Aurora evaluates the risk that exists before controls, incorporates actual control effectiveness, and calculates the resulting residual risk. This creates a defensible connection between the underlying risk, the controls intended to manage it, and the risk that remains — giving leaders a clearer basis for deciding where additional action or investment is warranted.

One Engine. Multiple Risk Domains.

Aurora applies a consistent risk methodology across multiple enterprise risk domains, helping leaders understand interconnected risk rather than relying on separate, isolated assessments.

C

Cyber Risk

Evaluate vulnerabilities, threats, attack exposure, security control performance, and potential business impact in the context of the assets and services at risk.

T

Technology Risk

Analyze technology dependencies, infrastructure, architecture, resilience, lifecycle conditions, and other technology risks in relation to business operations.

C

Compliance Risk

Connect regulatory and policy obligations to controls, evidence, findings, and business context to understand where compliance exposure creates meaningful enterprise risk.

O

Operational Risk

Evaluate process failures, third-party dependencies, people-related risks, physical impacts, and other operational conditions within the same risk framework.

Traditional Risk Assessment
Siloed assessments · Qualitative ratings · Periodic snapshots
Aurora
Connected intelligence · Quantified risk · Dynamic business context

Risk Intelligence for Every Decision Maker

CISO / CRO

Present defensible risk positions to executives and boards using evidence-based scoring tied to actual business context.

Risk & GRC Teams

Move beyond isolated qualitative assessments with connected, evidence-driven risk intelligence across the organization.

CFO / Finance

Understand where risk threatens business value and make more informed decisions about remediation, investment, and priorities.

Internal Audit

See risk in the context of actual control performance, supporting more focused audit planning and stronger evidence-based analysis.

Compliance

Connect obligations, controls, evidence, findings, and risk to understand where compliance issues create meaningful exposure.

Boards & Executives

Receive clear, business-aligned risk intelligence through Executive Dashboards to support informed strategic decisions.

From Enterprise Data to Executive Decisions

Aurora sits at the analytical core of the Mercury platform. A.D.A.M.™ creates the normalized enterprise intelligence foundation. ACET™ evaluates and validates control performance. Aurora applies Mercury’s scoring methodology to transform that intelligence into quantified risk. Executive Dashboards then make the results understandable, actionable, and decision-ready.

01

A.D.A.M.™

Aggregate • Discover
Analyze • Measure

02

ACET™

Validate • Verify
Assure • Track

03

Aurora™

Normalize • Score
Quantify • Optimize

04

Executive Dashboards

Visualize • Monitor
Prioritize • Decide