New in vCISO Lite · live now

Risk you can see coming— priced in dollars, before the loss.

A vendor gets breached and you already have a defensible exposure number — the same hour the news breaks. The single points of failure that would actually take you down are ranked by what fixing them is worth, not by who yelled the loudest. And the next risk is on the screen while it’s still forming.

Three engines, one layer. We call it Allotrope — one element, three forms.

You can predict the future

Most risk tools tell you what already happened, in colors. Allotrope tells you what’s about to happen, in dollars— so the decision is obvious before the loss, not the post-mortem.

The week, as it actually goes

Three repeating fires. Each one eats a week of senior time— and the next time it happens, you start from zero.

Three to ten days of CTO and security time per fire. Multiplied across a year of vendor disclosures, dependency wobbles, and audit cycles, you’re paying for the same fire-fighting over and over — while the work itself never compounds. Allotrope ends each fire with the engine built for it, on one layer that gets smarter with every one.

Today
With Allotrope

A vendor you depend on gets breached.

≈ 3 days · 6 people · a guess for the CEO

War room. The same question for two days: are we affected? You ship a hedged answer and hope.

01 Refraction

A defensible exposure number in the first hour.

Probability the incident reaches you, what it would cost, the cheapest move that cuts it most. The scramble never starts.

See it

A single point of failure quietly trips.

Unknown — visible in spreadsheets nobody opens

The dependency that took you down was knowable weeks ago. The post-mortem writes itself, then sits in a folder.

02 Keystone

The single points of failure, ranked by what fixing them is worth.

Concentration scored against your board-ratified limits, blast radius priced in revenue, mitigations with first-year ROI attached.

See it

Audit or board season hits.

≈ 2 weeks of senior time · rebuilt from scratch

Re-pull the same evidence. Re-write the same KRI section. Re-explain why the heat map is still amber. Repeat next quarter.

03 Continuous Indicators

The board report your GRC tool can’t write.

Leading indicators derived live from your environment. Every decision and attestation compounds as evidence for the next audit.

See it

Engine 01 · Refraction

End the vendor-breach war room.

Your CTO will love this.

The headline says a vendor you depend on was breached. Today that’s an all-hands scramble — war room, six people, two days, no number to give the CEO. Refraction gives you the number the same hour the news breaks: the probability the incident reaches you, what it would cost if it did, and the cheapest move that cuts it most. The scramble never starts.

Nobody else is doing this. Vendor risk today stops at a contract-time questionnaire and an annual DPO review — defensible on paper, useless when the headline drops. Refractionis the first quantified, conditional answer to the only question that matters when someone else’s breach hits the news.

  • In the first hourA defensible exposure number, not a guess. Re-derived hourly while the incident is live.
  • Math you can showP(in scope) × P(affected) × P(exploitable), with your live config driving every term.
  • Cheapest move firstMitigate / Reduce / Exit ranked by risk-adjusted cost. The recommended row is the recommended move.
  • Tailored to your businessThe three highest-impact actions, in order — the patch first when there’s a fix, each one named for the affected component and the function it threatens. Not a generic checklist.

↓ An exposure number only means something if you know which functions in your business actually depend on that vendor.

CRITICALASSESSING

Vendor disclosure · 4 hours ago

GitHub credential-exfiltration campaign

Disclosed by GitHub. 14 customer orgs confirmed affected, +3 in the last 48h.

Exposure analysis

P(In scope)30%

Your tokens are org-wide; you’re in the affected population.

P(Affected | In scope)85%

No secret rotation in 92 days; 3 repos with long-lived keys.

P(Exploitable | Affected)70%

IP allowlist on, but token scopes broad enough to reach prod CI.

34%exposure probability
$1.8Mloss if affected
$612Kexpected exposure · 2.4× tolerance

Decision — ranked by risk-adjusted cost

Accept the risk$612K residual
Reduce dependency on GitHub$95K residual · $40K cost

Engine 02 · Keystone

Find what your business actually rests on.

Your auditor will love this.

A handful of vendors quietly carry your whole business. Keystonereads your live dependency graph, finds the single points of failure, and prices each one in revenue at risk — so you spend on the fix that’s actually worth the most, and hand your auditor live proof that you’re running the resilience process, not just describing it.

  • Concentration, rankedEvery vendor scored by how many critical functions ride on it — against the limit your board ratified.
  • Cascade pricedIf this vendor goes, here’s the revenue that stops — per hour, per day, by function.
  • Fix with the ROI attachedEvery mitigation comes with risk-removed and first-year return — spend that defends itself.
  • Live BCP/DR evidenceThe graph is continuously re-derived. Your auditor sees the process running, not the binder describing it.

↓ The risk forming right now isn’t in your vendor list yet — it’s in the live signals coming off your own environment.

Single-vendor concentration · critical functions

3 risks past your board-ratified limit of 2.

!AWS us-east-15critical functions
!Okta SSO3critical functions
Stripe2critical functions

Blast radius — if Okta drops

  1. Customer authentication$1.2M/day
  2. Order management$890K/day
  3. Support & data access$340K/day

If Okta goes down for 4 hours

Revenue stopped$2.4M/day
First impact at< 2 min
24hr impact$847K
RecoveryVendor-dependent

Add a backup identity provider$45K cost · 4,900% first-year return

Engine 03 · Continuous Indicators

The board report your GRC tool can’t write.

Your board will love this.

Most “Key Risk Indicators” were typed into a spreadsheet years ago and predict nothing. Continuous Indicatorsderives them live from your own environment — each one leading, priced in dollars, with a named owner and the reasoning shown. It’s the one-page risk briefing a CTO can forward straight to the board.

  • ConditionalExposure during a live vendor incident — the Refraction number, surfaced as an indicator.
  • StructuralConcentration drift, straight from the Keystone graph. The signal moves with the structure.
  • BehavioralAttack-surface drift and config anomalies, observed live — not self-reported.
  • FinancialLoss expectancy and value-at-risk in dollars, threaded through all three.

Three engines, one Risk Posture Index. Forwardable to the board as-is.

Behavioral indicator attack surface 4 → 18 in six days, accelerating
A live behavioral indicator: internet-exposed AWS resources up from 4 to 18 in six days, accelerating at +0.6 per day. Two of them already match active exploit campaigns.

Why no one else has done this

Four properties that have to be true together.

Plenty of products do one of these. Nothing else does all four on one layer.

One dependency graph

Every signal — from a vendor incident to a scanner anomaly — resolves to the same model of functions, processes, systems, vendors, people. Numbers compare. Decisions compound.

Why it matters no orphan dashboards

Priced in dollars, not colors

Every output is a probability and a number. Boards understand it. Insurers underwrite against it. Spend defends itself with first-year ROI on every mitigation.

Replaces heat maps & H/M/L

Live, not annual

Re-derived hourly during incidents, on graph change for structure, continuously from scanners. The number you see is the number that’s true right now — not from last quarter.

Replaces annual reviews

Compounds, doesn’t decay

Every decision — every mitigation taken, every threshold breach, every audit attestation — becomes evidence for the next audit, board pack, and incident. The work accumulates instead of starting over.

Auditor view live BCP/DR evidence

It’s already in your Reporting view.