The present invention provides a system and method designed to continually monitor and evaluate an IT system. More specifically, the present invention teaches a system and method which continually monitors and evaluates the software, networks and devices of an IT system while providing reports and analysis for identified risks. Further, the present invention teaches a system and method which provides analysis and reports regarding the value and costs of identified risks.