Briefs & Specs

The methodology library

The frameworks vCISO Lite is built on — each as a one-page executive brief for the boardroom, and the peer-style paper with the full math behind it. Published methodology, working implementations.

QCD

Pricing cyber risk in M&A

Quantitative Cyber Diligence

Five pillars, each producing a dollar score, summed and risk-adjusted to a single Cyber Cost of Deal — defensible at the investment committee, comparable across a portfolio.

DC-TPIR

Responding when a vendor gets breached

Dependency-Centric Third-Party Incident Response

Quantified exposure conditioned on the incident, loss priced by failure mode, and a defensible accept / mitigate / reduce / exit decision against your risk tolerance — with a record that compounds.

CMA

Maturity that decays without fresh evidence

Continuous Maturity Assessment

Point-in-time maturity goes stale the day it's signed. CMA makes the score decay as evidence ages, counts a practice as sustained only once it's been exercised over time, and requires human attestation and machine evidence to converge for full credit — a posture number defensible on any day, mapped to Test of Design / Test of Effectiveness.

TA

Certifying an AI agent to act on its own

Trustworthy Autonomy

Two gates over a provenance substrate and a graduated autonomy ladder: an agent's right to act is measured, certified, and proven — never asserted. One verdict, defensible to a board.

Related

  • Press releases— announcements and media resources for each framework as it’s launched.
  • Changelog— every product and methodology release worth marking, reverse-chron.
  • Blog— the editorial series behind each framework, organized as themed clusters.

Published under Mechanical Animal Publishing. The executive briefs are free to share; the papers are working artifacts — cite the posted version.