CybersecurityThreat DetectionCloud SecurityAI App
CompletedRiskAudit - AI Cybersecurity Risk Assessment Platform
AI-powered platform that assesses an organization's cybersecurity posture against the NCA ECC 2-2024 framework with smart scoring and executive PDF reports.
Live — Risk ai
147 views
NDA Protected Project
This project is under a Non-Disclosure Agreement. Source code and certain details cannot be shared publicly.
Development Progress History
A transparent look at our daily development progress, challenges faced, and solutions implemented
Loading development history...
Project Details
Started
February 24, 2026
Delivered
March 5, 2026
Technologies
NCA ECC 2-2024 FrameworkSix Security DomainsProgressive QuestionnaireRisk Level Classification (Low/Medium/High/Critical)Weighted Risk Scoring EngineAI Executive Reports (GPT-4.1)Multi-Page PDF ExportTop 5 Risk IdentificationECC Gap MappingDomain Breakdown ChartsToggleable 3x3 & 4x4 Risk Matrix60+ Weighted QuestionsRisk Score GaugesShort/Medium/Long-Term Remediation Plans
Key Features
- NCA ECC 2-2024 Framework
- Six Security Domains
- Progressive Questionnaire
- Weighted Risk Scoring Engine
- Top 5 Risk Identification
- Short/Medium/Long-Term Remediation Plans
Project Gallery
1 images · Scroll for long images
Please wait, loading...1 / 1
View Full Size
1 / 1
Project Details
RiskAudit is a cybersecurity risk assessment platform built for organizations that need to evaluate their security posture against Saudi Arabia's NCA Essential Cybersecurity Controls (ECC 2-2024) framework.
The platform walks users through a structured questionnaire covering six security domains: Governance & Risk Management, Identity & Access Management, Data Protection, System & Network Protection, Monitoring & Detection, and Awareness & Third-Party Security. Each question carries a risk weight, and the system calculates domain-level and overall risk scores using a weighted scoring algorithm.
Once the assessment is complete, the platform sends the results to an AI engine powered by GPT-4.1, which generates a detailed executive report. This report includes a risk summary, top five identified risks, remediation plans broken into short-term, medium-term, and long-term actions, ECC gap mapping across all six domains, and a risk matrix summary.
Users can view results through an interactive dashboard featuring risk score gauges, domain breakdowns, and toggleable 3x3 or 4x4 risk matrices. The executive report can be exported as a multi-page PDF with charts and visual summaries.
The backend runs on Node.js with Express and MongoDB, handling assessment storage and AI report generation. The frontend is built with React, Redux for state persistence, and Tailwind CSS for a clean, responsive interface with smooth animations.
What Clients Say
I feel lucky to have found him here . He is not only a coding expert but also a very understanding person . I thank you so much sir for the help and excellent delivery..