· intuitem · News  · 7 min read

What's New in CISO Assistant — Week 42, 2026 (v4.1.0)

v4.1.0 brings a large rework of the EBIOS RM module (study framing, RO/TO radar, standard and advanced likelihood methods on kill-chain steps), arithmetic in workflows with a CEL compute action, MCP write tools for a full risk review, a delegated user-creator role, entity-assessment exports, the BSI C5:2026 framework, German email templates, and a breaking change to the current-user API.

v4.1.0 brings a large rework of the EBIOS RM module (study framing, RO/TO radar, standard and advanced likelihood methods on kill-chain steps), arithmetic in workflows with a CEL compute action, MCP write tools for a full risk review, a delegated user-creator role, entity-assessment exports, the BSI C5:2026 framework, German email templates, and a breaking change to the current-user API.

This post covers v4.1.0, published on October 3. It is the first minor release of the 4.x line. The headline is a large rework of the EBIOS RM module, which now follows the method’s guidance sheets much more closely. The release also adds arithmetic to workflows, extends the MCP server so a risk review can run end to end, and lets non-admins create users. API consumers should read the breaking change on the current-user endpoint.

EBIOS RM: Closer to the Method

PR #4959 is a long list of improvements across the five workshops. Most of them map to a specific item of the ANSSI method, so studies built in CISO Assistant are easier to defend in a review.

Workshop 1 — framing the study

  • Protection marking — a study can carry a classification level. It shows as a badge on the study and the Workshop 1 page, is repeated in the margin of every page of the printed report, and is available as a column and filter on the studies list.
  • Study frame — objectives, constraints and hypotheses, ETA and due date, and a link to a RACI matrix. The RACI matrix can be created inline by typing a name, and starts with the default roles. The frame appears on an always-visible card, in the report and in the XLSX export.
  • Executive summary — the observation field becomes the study’s executive summary and comes first in the report.

Workshop 2 — risk origins

  • Target objective categories on RO/TO couples, with six editable defaults from the method’s guidance.
  • Pertinence computed from motivation and resources through the study’s risk matrix, configurable per matrix.
  • RO/TO radar with two views, by risk origin or by target objective category. The most relevant couples sit at the centre and retained couples are shown in red.

Workshop 3 — strategic scenarios

  • Forced gravity on a strategic scenario is carried through to attack paths, operational scenarios and the risk assessment, with a pin marker so you can see where a value was set by hand.
  • Stakeholder criticality panel that compares entity defaults, current and residual values, and pins intentional changes.

Workshop 4 — operational scenarios

  • Kill-chain steps are now graph nodes with stable identities. Antecedents link steps to steps (existing data is migrated), the same elementary action can appear more than once in an operating mode, and each step can point to supporting assets.
  • Four likelihood methods — two express variants (direct estimate, or the most likely operating mode), standard and advanced. The standard method rates a success probability and technical difficulty per step and rolls them up along the graph. AND steps take the weakest branch. Cumulative values update live on each node and the critical path is highlighted. The scenario’s likelihood is that of its most likely operating mode.
  • Switching methods is reversible — likelihoods typed by hand are kept aside rather than overwritten, and you are asked to confirm before leaving the direct estimate.
  • Forced likelihood on an operational scenario wins over the computed one.
  • A default attack-sequence catalogue — the EBIOS RM “standard attack sequence” is loaded automatically as a TTP catalogue: four phases, eight categories, 32 observed techniques. The elementary-action form has a technique autocomplete that works over any TTP catalogue (EBIOS or MITRE ATT&CK) and prefills the name and description. The rating help from the method is shown in the step editor.

Risk matrices gain an optional ebios_rm section for the RO/TO scales, the success-probability and difficulty scales and the likelihood grid. It is editable in the library builder and reusable across studies; defaults apply when it is absent. The graph editor also gets a step edit modal (pen icon or double-click), and the MCP tools now use step ids for antecedents.

Thanks to @ab-smith.

Workflows: a Compute Action

Until now, {{ }} in a workflow only substituted values, and the only computed step was a date offset. A new Compute action evaluates CEL expressions, so a workflow can compute a risk score from likelihood and impact, a ratio between two counts, a loop counter, or an SLA chosen by severity (PR #4936).

  • A compute step is a list of rows, each a variable name and an expression. Rows run in order and can use earlier rows. They see the same context as templating: variables, the outputs of previous nodes, the payload, and the loop item and index.
  • Helpers include sum, avg, min, max, round, floor, ceil and abs. min and max also work on ISO dates.
  • The editor shows a live preview next to each row — the result and its type, or the engine’s own error — evaluated on the server.
  • Syntax errors and reserved names are caught when the workflow is published. Runtime errors such as division by zero fail the step without retrying.
  • AI provenance fencing follows values through compute steps, so a value derived from an AI answer is still blocked from fenced fields.

Thanks to @nas-tabchiche.

MCP: a Full Risk Review

It was not possible to run a qualitative risk review end to end through the MCP server: some tools sent values the backend rejected, and others lacked fields the backend accepted (PR #4939).

  • Applied controls use the real status values, with the old planned and inactive mapped to their equivalents. They can be created with a reference control (by UUID, URN, ref_id or name), assets, owner, priority, ref_id and CSF function.
  • Risk scenarios accept qualifications (as C/I/A/D/T/P letters, names or UUIDs) and an owner, and the inherent and residual probability and impact, treatment and justification can be set at creation.
  • Risk assessments and perimeters can now be updated, with new update_risk_assessment and update_perimeter tools. Risk tolerance is accepted as a matrix index or a risk-level name.
  • Owners and assignees accept an actor UUID, an email or a name. The tools used to expect actor ids while the only lookup returned user ids, which caused 400 errors.

Thanks to @JohnGanem.

Delegated User Creation (Pro)

Creating a user used to be reserved to global administrators: a domain administrator could add a user to a group, but could not create the user. Pro editions now have a built-in Global - User creator group, enabled by default (PR #4960). Its members can create users and see the user list, but cannot assign groups at creation, nor edit, deactivate or delete users. A domain manager with this role can then add the new user to groups in their own domain. Service accounts can use it too, and the role can be turned off in the configuration. Thanks to @eric-intuitem.

Breaking Change: the Current-User API

If you call GET /api/iam/current-user/, update your client. On an instance with 10,000 domains the response was large enough to make the interface slow. v4.1.0 stops repeating the same permission list for every folder (PR #4950):

  • a new permission_sets array lists each distinct set of permission codenames once;
  • domain_permissions now maps each folder ID to an index in that array instead of holding the codenames.

To get a folder’s codenames, read permission_sets[domain_permissions[folder_id]]. The CISO Assistant interface is updated accordingly. Thanks to @eric-intuitem.

TPRM, Assets and Localisation

  • Export entity assessments — the entity assessments list can be exported to CSV and XLSX. The export follows the current filters, search and domain permissions, and includes the entity, solution, questionnaire, status, completion, review progress, dates, criticality, conclusion, author, reviewer and representative (PR #4926). Thanks to @Mohamed-Hacene.
  • Asset dependency map — the experimental asset board gets a second mode focused on a single asset. Double-click an asset to explore its dependency chain or connected assets, adjust the link depth, and create, link or unlink assets from the map. Assets you are not allowed to see appear without identifying information (PR #4967). Thanks to @ab-smith.
  • German email templates — German users received the built-in notifications in English. All 29 templates are now translated, with correct German singular and plural for durations (PR #4941). Thanks to @hlederhaas.
  • Czech localisation — missing terms are translated in line with the new Czech Cybersecurity Act No. 264/2025 Coll. and its Decree No. 409/2025 Coll. (PR #4910). Thanks to @zdenek-pergl.

Framework & Library Updates

  • BSI C5:2026 — the 2026 edition of the German Federal Office for Information Security’s Cloud Computing Compliance Criteria Catalogue, in English and German (PR #4923). Welcome to @tobmay, who makes their first contribution with this framework.

For full details, see the v4.1.0 release notes on GitHub.

Back to Blog

Related Posts

View All Posts »
What's New in CISO Assistant — Week 41, 2026 (v4.0.8 – v4.0.9)

What's New in CISO Assistant — Week 41, 2026 (v4.0.8 – v4.0.9)

v4.0.8 and v4.0.9 let you set a custom score scale on an audit without cloning its framework, bring the SCF 2026.3 framework and a proper ASD Essential Eight (November 2023) model, make every linked-object tab on applied controls able to link existing objects, load long autocomplete lists in batches, and fix a seat-count regression that made readers count as editors.

What's New in CISO Assistant — Week 40, 2026 (v4.0.7)

What's New in CISO Assistant — Week 40, 2026 (v4.0.7)

v4.0.7 brings an in-app notification centre, a risk trajectory view that plays a risk assessment forward in time, X-rays that cover governance and operations and point at active controls with no evidence behind them, per-user module visibility, Mermaid diagrams in documents and PDFs, and workflows that can draft and review documents.

What's New in CISO Assistant — Week 39, 2026 (v4.0.5 – v4.0.6)

What's New in CISO Assistant — Week 39, 2026 (v4.0.5 – v4.0.6)

v4.0.5 lands a mapping table beside the graph, relation graphs on detail pages, a command palette that can now search and create, workflow steps that record measurements and file scan results — and a Power BI connector release that anyone who upgraded to 4.0 needs to install. v4.0.6 follows with an evidence-upload fix worth taking straight away.

What's New in CISO Assistant — Week 38, 2026 (v4.0.4)

What's New in CISO Assistant — Week 38, 2026 (v4.0.4)

A single patch after the busy 4.0.2/4.0.3 pair — but it carries a real behaviour change for dynamic frameworks, honest loading states on list views, and a container-hardening step that operators need to read before upgrading.