Most security teams know which controls they have. Very few know which MITRE ATLAS AI threats those controls actually cover — and which ones they don't. The Security Mapping Tool™ closes that gap: select your controls, get your threat coverage, see your compliance gaps, find your blind spots, and export everything to CSV.
Select your AI systems and security controls. Get 5 result views: coverage overview, gap analysis, compliance mapping, vendor recommendations, and coverage matrix. Free CSV export.
The standard approach to AI security is additive: implement controls, accumulate them over time, and assume coverage improves. The problem is that AI security controls aren't uniformly distributed across the threat landscape. Most organisations end up with multiple overlapping controls for prompt injection (the most visible threat) and zero controls for agent tool governance, RAG access control, and AI supply chain security (the fastest-growing threat categories).
Without explicit mapping from controls to threats, this imbalance is invisible. An organisation might have 15 security controls that collectively cover 6 MITRE ATLAS techniques — while 30+ other techniques remain completely uncovered. The Security Mapping Tool makes this visible, so investment decisions become rational rather than reactive.
Risk-weighted coverage score, coverage by ATLAS threat category, and executive summary narrative
Uncovered techniques with risk severity, blind spot identification, "what-if" investment simulation, and prioritised recommendations
Coverage mapped to SOC 2, ISO 27001, NIST AI RMF, and EU AI Act — with specific gap identification per framework
Product recommendations mapped to your specific gaps — tools most likely to improve your coverage score
Visual grid of controls vs ATLAS techniques — heat-mapped to show where coverage is concentrated and where it's absent
A key differentiator of the Security Mapping Tool is its compliance output. Most AI security tools tell you your coverage against threats. This tool also tells you what that coverage means for your compliance obligations.
Maps controls to Trust Services Criteria: Security (CC6-CC9), Availability (A1), and Confidentiality (C1).
Maps to Annex A controls as they apply to AI systems and LLM deployments.
Maps to Govern, Map, Measure, and Manage functions for AI risk management.
Maps to technical and governance requirements for high-risk AI systems under the EU AI Act.
General input validation exists but wasn't designed for semantic prompt attacks. Standard WAFs and input sanitisation detect SQL injection and XSS but are blind to "ignore previous instructions" variants. Gap: AML.T0051, AML.T0054 partially uncovered despite existing controls.
IAM controls manage human access to systems. They don't govern which tools AI agents can call, with what permissions, or under what conditions. Most organisations have zero formal control over agent tool scope. Gap: AML.T0080, AML.T0090 completely uncovered.
Data access controls govern who can read files and databases. They don't automatically apply to which chunks get retrieved from a vector database. A user authorised to read a document category may still receive retrieval results from restricted documents. Gap: cross-tenant leakage techniques uncovered despite strong underlying data controls.
SIEM, logging, and anomaly detection capture network events, authentication events, and file access events. They don't capture prompt anomalies, output anomalies, agent behaviour deviations, or retrieval scope violations. Gap: runtime monitoring ATLAS techniques uncovered despite substantial general monitoring investment.
Vendor risk management assesses financial stability, SLAs, and general security posture. It rarely evaluates AI-specific criteria: training data terms, model behaviour, inference security, or model version change management. Gap: supply chain ATLAS techniques largely uncovered despite mature vendor risk programme.
Validate that your AI security architecture actually covers the ATLAS techniques you think it does — and identify the architectural gaps before they become incidents
Map existing controls to SOC 2, ISO 27001, NIST AI RMF, and EU AI Act in minutes — identify specific gaps per framework without manual cross-reference work
Use the "what-if" investment simulation to model the coverage impact of specific control investments before budget requests — justify spend with data, not intuition
Use blind spot analysis to identify the ATLAS techniques most likely to succeed against your current control stack — focus your testing where defences are weakest
The visual coverage matrix shows all your controls against all MITRE ATLAS techniques in a single heat-mapped grid. Instantly see where coverage clusters and where the gaps are.