Pricing cyber risk in M&A
Quantitative Cyber Diligence
Five pillars, each producing a dollar score, summed and risk-adjusted to a single Cyber Cost of Deal — defensible at the investment committee, comparable across a portfolio.
Briefs & Specs
The frameworks vCISO Lite is built on — each as a one-page executive brief for the boardroom, and the peer-style paper with the full math behind it. Published methodology, working implementations.
Pricing cyber risk in M&A
Five pillars, each producing a dollar score, summed and risk-adjusted to a single Cyber Cost of Deal — defensible at the investment committee, comparable across a portfolio.
Responding when a vendor gets breached
Quantified exposure conditioned on the incident, loss priced by failure mode, and a defensible accept / mitigate / reduce / exit decision against your risk tolerance — with a record that compounds.
Maturity that decays without fresh evidence
Point-in-time maturity goes stale the day it's signed. CMA makes the score decay as evidence ages, counts a practice as sustained only once it's been exercised over time, and requires human attestation and machine evidence to converge for full credit — a posture number defensible on any day, mapped to Test of Design / Test of Effectiveness.
Certifying an AI agent to act on its own
Two gates over a provenance substrate and a graduated autonomy ladder: an agent's right to act is measured, certified, and proven — never asserted. One verdict, defensible to a board.
Published under Mechanical Animal Publishing. The executive briefs are free to share; the papers are working artifacts — cite the posted version.