QRadar Risk Manager (QRM) is a separately installed appliance that monitors device configurations, simulates changes to your network environment, and prioritizes risks and vulnerabilities. QRM is a part of the QRadar family.
QRadar Risk Manager is accessed by using the Risks tab on your IBM Security QRadar SIEM Console.
QRadar Risk Manager uses data that is collected by QRadar. For example, configuration data from firewalls, routers, switches, or intrusion prevention systems (IPSs), vulnerability feeds, and third-party security sources. Data sources enable QRadar Risk Manager to identify security, policy, and compliance risks in your network and estimate the probability of risk exploitation.
QRadar Risk Manager alerts you to discovered risks by displaying offenses on the Offenses tab. Risk data is analyzed and reported alongside all other data QRadar processes. In QRadar Risk Manager, you can evaluate and manage risk at an acceptable level based on your company’s risk tolerance.
You can also use QRadar Risk Manager to query all network connections, compare device configurations, filter your network topology, and simulate the possible effects of updating device configurations.
You can use QRadar Risk Manager to define a set of policies (or questions) about your network and monitor the policies for changes. For example, if you want to deny unencrypted protocols in your DMZ from the Internet, you can define a policy monitor question to detect unencrypted protocols. Submitting the question returns a list of unencrypted protocols communicating from the Internet to your DMZ, and you can determine which ones pose security risks.
With the version of QRadar 7.5.0 patch UP14, QRadar Risk Manager (QRM) now supports Check Point HTTPS integration
QRadar Risk Manager now receives firewall rule event logs directly from Check Point Security Management Servers (SMS). This enhancement enables real-time monitoring of firewall rule event counts, helping customers manage and optimize the effectiveness of their firewall rule policies across all managed devices. The benefits are as follows:
- Identify the most and least used Checkpoint HTTPS firewall rules
- Detect rules that might unnecessarily block network access
- Highlight frequently triggered rules that might impact performance
- View detailed rule event data for analysis
- Schedule reports to improve policy management and visibility
This feature helps users to monitor and optimize Check Point firewall rules in real time for improved security and network efficiency.
As of 2026, QRM is available to install in 7.6.0 according to IBM documentation.

