Knowledge BaseRisk Map Operating ModelTemplates ServicesAboutStart an Engagement
Risk Intelligence

The Map Your Risk Register Has Never Had

Natural hazards, public cloud regions, provider outages, and standing geopolitical watchpoints, on one canvas, pulled live from the agencies that publish them, with every source named. Nothing loads until you press the button.

Score any site in ten seconds

Type an office, data centre, or supplier address into the map and it returns an inherent risk score on the same 5×5 likelihood × impact scale your register already uses. Likelihood rises with how much is happening in range and how close it is; impact takes the worst thing in range, weighted by proximity. Jurisdictional exposure is scored chronically, a country under a Level 4 advisory rates high whether or not anything is in the feeds today.

It is a screening number, not an assessment

It knows where a site is and what is happening around it. It knows nothing about what runs there, which processes, which people, which upstream dependencies, and what the business loses per hour when the building is unreachable. Turning inherent scores into residual ones, across a whole estate, is a location risk assessment, and it is most of the evidence base a business impact analysis needs.

Assess My Locations Why most BIAs fail
Why this exists

A risk register tells you what could happen. A map tells you where you already are.

Most risk programs hold geography as a text field. The business impact analysis names a site, the vendor register names a hosting region, the continuity plan names a recovery location, and none of those three fields are ever compared to each other, or to what is happening in the world today. The moment you put them on a shared coordinate system, questions that were invisible become obvious: how many of our critical processes recover into the same metro, how many of our vendors sit in the region that just flooded, whether our failover target is two hundred miles from our primary or two.

This map is a working prototype, and the public version stays free. It plots the hazard picture and the cloud footprint that every organization shares, because those are the two layers anyone can verify. The version that matters is the one I build for you, where the third layer is your sites, your vendors, and your recovery targets, and it runs on a platform that meets your security and privacy requirements rather than on mine.

Everything here is deliberately auditable. Each signal names the agency that published it and links back to the record. Where a provider does not expose a feed a browser can legitimately read, this map says so rather than quietly routing around it. That is the same standard I would hold a vendor's risk dashboard to.

An Active Investment Area

Geospatial intelligence is an active investment area for PivotRisk, not a side project. This map is the public face of that commitment, and PivotRisk is excited to keep enhancing it with customer feedback and best-practice research: new signal layers, sharper scoring, and better ways to put an estate's own sites, vendors, and recovery targets on the same canvas as the hazards around them.

If your program needs geography treated as a first-class dimension instead of a text field, this is work PivotRisk is building a practice around. Tell me which signal you wish this map carried, or bring your estate and we will put it on the map.

Read: GIS in Risk & Resilience Map your own footprint →
How to read it

Layers, conditions, and tripwires

Shape carries category, circles are events that happened, squares are infrastructure, diamonds are standing political conditions. Colour carries severity, and nothing else.

Natural hazard

Floods, cyclones, earthquakes, volcanic activity, wildfire and drought from GDACS, USGS, NASA EONET, and the US National Weather Service. Colour is the publishing agency's own alert level, not mine, I do not re-score other people's science.

Cloud & infrastructure

Every announced AWS, Azure, and Google Cloud region, drawn from published documentation. Google Cloud incidents are read live and light up the specific regions they affect. Hover any region for its code and geography.

Geopolitical

A short, hand-maintained watchlist of chokepoints and conflict zones with real operating consequences, shipping lanes, semiconductor concentration, subsea cable corridors. Curated and dated, and labelled as such rather than dressed up as a feed.

Country advisory

Live UK FCDO travel advice for every country that hosts a public cloud region, so a region's dot carries its jurisdiction's advisory level alongside its provider. A travel advisory isn't an outage signal; it speaks to staff movement, vendor site visits, audit access, and duty of care around infrastructure you depend on. The US State Department publishes the same thing but without cross-origin headers, so it isn't readable here.

INFORM country risk

Switch the INFORM layer on and every country shades by the EU Joint Research Centre's INFORM Risk Index, the open, fully documented counterpart to the proprietary country ratings sold by risk vendors. Scores and the five-class palette are fetched straight from JRC's API, edition named on the map, so the classification is always theirs, never mine. Hover any country for its overall score and the three pillars behind it: hazard and exposure, vulnerability, and coping capacity.

Active crises

Where INFORM risk shows what a country is structurally exposed to, the Active crises layer shows what is actually happening in it now: every crisis the EU JRC and ACAPS currently track, scored 0 to 10, with its drivers named and its direction of travel stated. Read it as humanitarian crisis severity rather than a security threat level, because that is what it measures. JRC publishes the score but not the boundaries of its severity classes, so this layer ramps their score continuously instead of inventing classes and calling them theirs. Crises are published per country, so they shade countries rather than dropping pins.

OFAC sanctions programs

Which countries the US Treasury names a sanctions program after, each one linking to OFAC's own page for that program. OFAC publishes no browser-readable export, so this is a dated snapshot rather than a feed, and it says so. It is drawn in one flat tone on purpose: OFAC publishes no severity, and a program's scope runs from a comprehensive embargo to a handful of designated individuals, so any gradient here would be one I invented. Thematic programs like counter terrorism and cyber name no country and shade nothing. Treat it as a pointer to where to read, never as a compliance determination.

Power stations

Every station of 1,000 megawatts and above, from the World Resources Institute's open database, switched on as an extra layer rather than instead of one. Stations appear as you zoom in, drawn as outline squares because a power station publishes no severity and on this map a solid colour always means one. The mark inside each square is its fuel, so nuclear reads at a glance, and the square's size follows its capacity. Every business impact analysis names power as a dependency and almost none of them say which station or how far away. Worth being plain about the limit: this is an inventory of what exists, not a grid model. The source carries no transmission data, so it can show you the station and cannot tell you which one serves you.

Seaports

Every seaport the US National Geospatial-Intelligence Agency catalogues, with its harbour size, harbour type and maximum vessel draft. Ports arrive in order of consequence as you zoom: the large and medium harbours first, small ones further in, and the smallest last, so the world view is not carpeted by seventeen hundred minor anchorages. Like power stations they are drawn as outline squares, because a port publishes no severity. This is the layer that makes the shipping chokepoints on this map concrete: the Red Sea and Panama entries have always asserted a supply-chain risk without plotting a single berth it would actually happen to.

Declared military sites

Installations that are publicly named in OpenStreetMap: bases, naval bases, military airfields and barracks, drawn as ordinary infrastructure in the same neutral outline as power stations and ports. This layer exists for readers who work in or around the defence sector, where a question like "what sits near our facility" is routine. Two things it deliberately is not. It is not discovery: nothing is inferred, nothing is derived, and unnamed training and danger areas are excluded, so what you see is the publicly acknowledged picture and every marker says so. And it is not a threat assessment: there is no severity here and no colour implying one, because the source publishes none. Data © OpenStreetMap contributors, under the Open Database Licence.

Emergency hospitals

Hospitals that OpenStreetMap records as able to receive emergency cases, which is the version of this question a duty-of-care conversation actually asks. This layer comes with a warning the others do not need, because the misleading part of it is the empty space rather than the markers. Mapping completeness varies enormously by country: measured from this snapshot, France carries roughly fifty times Nigeria's mapped emergency hospitals per head of population. France does not have fifty times the emergency medical capacity. Rather than tuck that into a footnote, the map shows you the measurement whenever the layer is on, so you can see which parts of the world you are entitled to draw conclusions about. Absence of a marker here is never evidence of absence of care. Data © OpenStreetMap contributors, under the Open Database Licence.

Airports

Large and medium airports worldwide with their IATA codes, large ones first and medium ones as you zoom in. Small airstrips, heliports and closed fields are left out, because plotting forty thousand private grass strips would bury the airports that staff movement, evacuation and the arrival of parts and people actually depend on. Military airfields live on their own layer and carry the same aircraft mark under a chevron, so the two read as related without being confusable. Public domain, in the publisher's own words, which makes OurAirports the cleanest licence of any source on this map.

Tripwires

Eight thresholds, each stating what normal looks like before it reports. That is the difference between a monitoring board and a news feed, a green row is evidence a threshold was checked, not an absence of information. They read across every other layer: a severe hazard within 300 km of a cloud region, a Kp index above 5, a CVSS 9 with a high exploitation probability.

Global conditions & vulnerabilities

Space weather from NOAA, the Kp index and the R/S/G storm scales that quietly degrade GNSS timing, HF comms and satellite operations. Plus the week's highest-severity CVEs from NVD, scored by CVSS and by FIRST's EPSS: how bad it would be, next to whether anyone is actually exploiting it. Neither is geographic, so both get a readout rather than a pin.

Service health

Live status for the providers a control environment quietly runs on, Cloudflare, GitHub, Slack, Twilio, Datadog, Snowflake, Stripe, DigitalOcean. They publish a global status rather than a located one, so they get a rail instead of a pin.

Score one of your sites, then do it properly

Type any office, data centre, or supplier address into the map above and it will return a 5×5 inherent risk score for that point, the same scale your register already uses. That takes about ten seconds and gets you an honest screening number.

What it cannot tell you is what runs there: which processes, which people, which upstream dependencies, and what the business actually loses per hour when the building is unreachable. Turning inherent scores into residual ones (controls, recovery targets, workarounds, and the staff-impact picture for every location) is a location risk assessment, and it is most of the evidence base a business impact analysis needs. I do that work across whole estates.

Assess My Locations See the BIA Template