Blog
Operating notes on evidence-backed cyber-risk decisions.
The blog index is intentionally focused: proof grammar, financial-risk translation, and the boundary between public positioning and workspace-bound implementation detail.
Request early access
Board reporting / 9 min read
The Board Cyber Brief Template: Dollars, Not a Mostly-Green Heatmap
A section-by-section structure for a board-ready cyber narrative that leads with EBITDA-at-risk, traces every figure to source evidence, and carries decisions and ownership into the next cycle.

CMMC readiness / 8 min read
C3PAO Assessment: What Your Evidence Package Needs
A Level 2 assessment tests 320 objectives against real artifacts. Learn what a C3PAO examines and how to build a defensible evidence package.

CMMC readiness / 8 min read
How Much Does CMMC Level 2 Certification Cost?
CMMC Level 2 has no single sticker price. Scope, remediation, assessment, and sustainment determine the budget; this guide shows what moves each one.

CMMC readiness / 7 min read
CMMC Phase II Timeline: What Changed in July 2026
The government suspended Phase II on July 13 and began a 60-day review. Here is what changed, what Phase I still requires, and what to watch next.

CMMC readiness / 8 min read
CMMC Phase II Is Suspended: Why Contractors Should Not Wait
The government paused Phase II for a 60-day review. Phase I and the underlying security duties remain, so contractors should use the pause to build evidence.

CMMC readiness / 10 min read
POA&M Under CMMC: What's Allowed and the 180-Day Clock
CMMC POA&Ms are narrow: an 88-point floor, limited eligible requirements, and a 180-day closeout clock. Here is what 32 CFR 170.21 allows.

CMMC readiness / 8 min read
CUI Scoping: Drawing the Boundary That Shrinks Your CMMC Assessment
The single biggest lever on the cost and difficulty of a CMMC Level 2 assessment is not a control — it is where you draw the CUI boundary. Here are the five asset categories, the enclave strategy, and the discipline that keeps a tight scope honest.

Risk quantification / 9 min read
FAIR for Security Leaders: Turning Controls Into a Dollar Range
A plain-language guide to Factor Analysis of Information Risk, the Monte Carlo behind a P10/base/P90 loss estimate, and how a CISO uses it to defend a budget without overclaiming.

Risk quantification / 9 min read
From finding to EBITDA with Proof
The full buyer path: a raw security finding mapped to the asset and revenue it exposes, priced as EBITDA-at-risk, ranked by recovery per dollar, funded, and closed with board-ready proof.

CMMC readiness / 10 min read
How to Calculate and Improve Your SPRS Score
The DoD Assessment Methodology turns 110 security requirements into a single number between −203 and 110. Here is exactly how the arithmetic works, what the score does and does not prove, and the highest-leverage way to raise it without gaming it.

Risk quantification / 9 min read
Negotiating Cyber Renewal With Verified Controls, Not a Questionnaire
Self-reported applications leave money on the table; an underwriter-reviewable package of verified control state and a quantified exposure range changes what you are actually negotiating over.

Trust / 6 min read
Why implementation docs are login-bound
Public docs should orient buyers generously. Workspace docs should protect integration details, API scopes, source-adapter behavior, and tenant-specific evidence paths. The split is a posture decision, not an act of withholding.

Operating note / 7 min read
Proof before positioning
Why cyber-risk marketing needs claim state, source coverage, confidence, and publication boundaries next to the strongest copy, and why a product that gates its own outputs should hold its marketing to the same standard.

Risk quantification / 9 min read
CVSS Tells You Severity. It Won't Tell You What to Fix First.
Why a CVSS 9.8 on a forgotten asset can matter less than a CVSS 6 on a revenue-critical path, and how ranking findings by EBITDA recovered per dollar reorders the backlog.

Disclosure and materiality / 9 min read
SEC Cyber-Materiality: Why a Defensible Dollar Beats Adjectives
What Item 1C and the four-day 8-K clock actually require, why "material" is a financial total-mix question, and where a method-stamped quantification helps counsel decide.