All press releases

For Immediate Release

vCISO Lite Launches Allotrope — Forward-Looking Cyber Risk on One Dependency Graph, Priced in Dollars Before the Loss

The vCISO Lite risk-intelligence umbrella brings vendor-incident exposure (Refraction / DC-TPIR), operational resilience (Keystone / ORE), and continuous key risk indicators onto one dependency graph — so a KRI can trip a resilience scenario, a resilience scenario can raise a vendor alert, and the composition insight stops getting lost.

ATLANTA — June 4, 2026 — vCISO Lite today launched Allotrope, the risk-intelligence umbrella on vCISO Lite that brings three forward-looking risk engines — vendor-incident exposure, operational resilience, and continuous key risk indicators — onto a single dependency graph. Allotrope is generally available today on Business tier and above (Business, Ultra, and Enterprise), with no separate SKU. Existing customers see it in the navigation automatically.

Forward-looking cyber risk today lives in three separate places that don’t talk to each other: dark-web and threat-intelligence feeds for third-party incidents, business-impact and resilience tooling for single points of failure, and KRI dashboards for indicator monitoring. Buyers stitch the answers together by hand every time a vendor headline breaks, a dependency wobbles, or an audit cycle turns over. Because none of the three know about the others, the composition insight — the thing that would let a KRI threshold trip a resilience scenario, or a resilience scenario raise a vendor alert — is exactly what gets lost. Allotrope answers that fragmentation.

“Every forward-looking risk product on the market lives in its own silo — the dark-web feed doesn’t know the dependency graph, the resilience tool doesn’t know the KRIs, and the KRI dashboard doesn’t know either,” said Yolonda Smith, founder of vCISO Lite. “That’s what Allotrope answers — one dependency graph, three lenses on the same data. A Continuous Indicator can trip a Keystone scenario, a Keystone scenario can raise a Refraction alert, and a Refraction alert can update the vendor-risk register the same hour a headline breaks. The composition is the moat. The individual signals exist everywhere.”

What’s in the release

Allotrope ships with three engines — each an allotropic form of the same underlying data model:

  • Refraction — Dependency-Centric Third-Party Incident Response (DC-TPIR). The forward-looking third-party incident register. Refraction prices vendor exposure in dollars beforethe incident lands, combining dark-web signal, threat-intelligence feeds, and vendor-concentration structure so the exposure number is on the screen the same hour a vendor disclosure hits the news — not two days into a war-room scramble. The methodology of which vendors actually deserve that treatment is covered in “The 5 vendors you should actually worry about”; the underlying framework is in the DC-TPIR executive brief and academic paper.
  • Keystone — Operational Resilience Engine (ORE). Operational resilience, quantified across the whole business — not just vendors. Keystone reads a live dependency graph that connects business functions, processes, systems, people, vendors, and facilities on one map, so a single-point-of-failure surfaces regardless of what type it is: the one person who knows how to run the release, the vendor that quietly became indispensable, the facility whose backup was never tested. The engine identifies which functions fall over first, what the loss looks like at each severity, and who’s downstream — then prices mitigation options against first-year return so resilience spend survives the next budget cycle. Concentration risk shows up across every node type; the vendor sub-case is one lens of many, covered in “Vendor concentration risk: the dimension per-vendor TPRM misses.” Keystone maps directly to DORA Art. 8 (ICT-supported business functions, roles, dependencies), NYDFS §500.16(a)(2) (essential documents, data, facilities, infrastructure, services, personnel), and ISO 22301 §8.2.2 (Business Impact Analysis) — the regulatory frameworks under which mid-market and financial-services buyers already have to author this graph.
  • Continuous Indicators.The KRI engine, derived live from the customer’s own environment rather than typed into a spreadsheet years ago. Four indicator families — conditional (live vendor exposure), structural (concentration drift), behavioral (attack-surface and configuration anomalies), and financial (loss expectancy) — each with real thresholds and triggered response, wired into the rest of the platform. Deeper reading in the Continuous Indicators series and “Why your KRIs stopped predicting anything.”

Why the composition matters

The three engines share one dependency graph and one data model, and Allotrope is the surface where they cross-connect at runtime rather than through a nightly export. A Continuous Indicator can trip a Keystone scenario. A Keystone scenario can raise a Refraction alert. A Refraction alert can update the vendor-risk registerin real time. That composition — not any individual signal — is the difference between backward-looking risk reporting and forward-looking risk intelligence, a distinction covered in “Forward risk vs. backward risk: the board report that shows where you’re headed”. The individual feeds exist elsewhere on the market; the mesh does not.

Availability

Allotrope is generally available today on vCISO Lite, on Business tier and above (Business, Ultra, and Enterprise), with no separate SKU. Existing customers on those tiers see Allotrope in the navigation automatically. Product detail is at vcisolite.com/allotrope, the DC-TPIR executive brief and academic paper are at vcisolite.com/briefs-and-specs, and the accompanying changelog entry covers rollout detail.


About vCISO Lite

vCISO Lite is a compliance and cyber risk platform for growing companies that don’t have a full-time CISO. The platform helps customers close compliance gaps across every framework mapped in the Secure Controls Framework (SOC 2, ISO 27001, PCI DSS, HIPAA, DORA, NYDFS Part 500, GDPR, NIST 800-53 and 800-171, FedRAMP, CMMC, and more), quantify cyber risk in the language their board and deal teams already speak, and — with Allotrope — see forward-looking risk from third-party incidents, operational resilience, and continuous indicators on a single dependency graph. vCISO Lite is headquartered in Atlanta, Georgia. Learn more at vcisolite.com, read related product releases in the changelog, or explore the Continuous Indicators editorial series.

Media Contact

Press & Analyst Inquiries
Yolonda Smith, Founder
press@vcisolite.com

###