All releases
Cyber Maturity · Assessment v2

Cyber Maturity Assessment — rebuilt on real Monte Carlo math

Progressive-disclosure UI backed by live FAIR-style Monte Carlo simulation. Loss Exceedance Curves from real percentiles, per-finding ALE and remediation cost derived from BLS + Gartner data, assessment findings that flow into the operating program instead of a shelved report.

The Cyber Maturity Assessment got rebuilt from the UI down to the math. The previous version showed customers a red/yellow/green rating and a hardcoded cost methodology; the new version is a progressive-disclosure interface backed by real FAIR-style Monte Carlo simulation and per-finding remediation cost derived from live BLS and Gartner data.

What changed in the release

  • Progressive disclosure UI. The top-level view is a status bar with domain-level maturity grades. Click a domain, get expandable practice rows. Click a practice, get evidence tiers, narrative context, and a practice-specific roadmap. The detail is there for anyone who wants it; the summary is there for the board meeting. Same page, different depth, no context switch.
  • Real Monte Carlo underneath, not a lookup table. Loss Exceedance Curves now use live CRQ Monte Carlo percentiles instead of a hardcoded methodology. If the customer’s business context, threat model, or control coverage changes, the LEC changes with it — not on the next quarterly refresh, on the next simulation run.
  • Tabular per-finding cost breakdown.Every finding gets an Annualized Loss Expectancy (ALE) and a remediation cost line item — both derived from the FAIR model, both broken down into observable inputs, both defensible to the board. No more “security is important” hand-waving.
  • Hours-based remediation cost.Remediation cost per finding is now derived from an hours-per-finding estimate multiplied by a BLS-derived blended labor rate, not from a hardcoded “low/medium/high” category. The rate is documented and cited (BLS + Gartner), and customers can override it if their actual labor cost differs.
  • Assessment task integration.Findings from the assessment now flow into the platform’s task system with the right owner, priority, and evidence hooks — so the assessment isn’t a report that gets read once and shelved, it’s the input to the operating program.
  • Auto-triggered on first page load.New customers don’t have to click a “run assessment” button — the platform runs the first assessment automatically once the customer has enough business context in place. Zero friction from onboarding to first grade.

Why the rebuild

The compliance industry runs on red/yellow/green ratings that no one can defend to a board and no one can act on operationally. Progressive-disclosure UX plus real quantification math means the assessment now produces two outputs that most maturity tools cannot: a defensible dollar figure a CFO will accept, and a specific set of actions ranked by ALE reduction per remediation dollar — the prioritization the operating team can actually run.

Related reading

Cyber Risk Quantification for Mid-Market — the CRQ discipline the maturity assessment feeds when quantifying risk from the assessment output.