March 31, 2026 · Cyber Maturity · Assessment v2

Cyber Maturity Assessment — rebuilt on real Monte Carlo math

Progressive-disclosure UI backed by live FAIR-style Monte Carlo simulation. Loss Exceedance Curves from real percentiles, per-finding ALE and remediation cost derived from BLS + Gartner data, assessment findings that flow into the operating program instead of a shelved report.

What changed

The Cyber Maturity Assessment got rebuilt from the UI down to the math. The previous version showed customers a red/yellow/green rating and a hardcoded cost methodology. The new version is a progressive-disclosure interface backed by real FAIR-style Monte Carlo simulation and per-finding remediation cost derived from live BLS and Gartner data.

Interface
Progressive disclosure. The top-level view is a status bar with domain-level maturity grades. Click a domain for expandable practice rows; click a practice for evidence tiers, narrative context, and a practice-specific roadmap. Same page, different depth, no context switch.
Simulation
Loss Exceedance Curves now use live FAIR-style Monte Carlo percentiles instead of a hardcoded methodology. When business context, threat model, or control coverage changes, the LEC changes on the next simulation run, not on the next quarterly refresh.
Per-finding math
Every finding gets an Annualized Loss Expectancy and a remediation cost line item, both derived from the FAIR model and both decomposed into observable inputs a CFO can question.
Labor rate
Remediation cost per finding is now an hours-per-finding estimate multiplied by a BLS and Gartner blended labor rate. The rate is documented and cited; customers can override it if their actual loaded cost per hour differs.
Program handoff
Findings flow into the platform's task system with owner, priority, and evidence hooks. New customers get the first assessment auto-triggered once business context is in place, with no 'run assessment' button to press.

Why it matters

The compliance industry runs on red/yellow/green ratings that no one can defend to a board and no one can act on operationally. Progressive-disclosure UX plus real quantification math means the assessment now produces two outputs that most maturity tools cannot: a defensible dollar figure a CFO will accept, and a specific set of actions ranked by ALE reduction per remediation dollar — the prioritization the operating team can actually run.

The quantification half of this is the same CRQ discipline we write about for mid-market programs; see Cyber Risk Quantification for Mid-Market for the methodology the assessment output feeds.

Availability

Shipping today to every platform tier. New customers get the first assessment auto-triggered once business context is in place; existing customers see the new interface and the Monte Carlo math on their next assessment run.

No manual migration is required. The Loss Exceedance Curve and per-finding ALE populate from the next simulation run against your current business context, control coverage, and threat model. The BLS and Gartner labor rate is applied by default and can be overridden in assessment settings.

Known limitations

The BLS and Gartner blended labor rate is a cited default. Organizations whose actual loaded cost per hour differs should override it before taking the remediation-cost number into a budget conversation.

The LEC and per-finding ALE recompute on each simulation run; they are not continuously live. Material changes to control coverage or the threat model require a fresh run to be reflected.

The auto-triggered first assessment requires business context (scope, revenue, data categories) to be captured. Until that is complete, the platform will not run the first assessment on the customer's behalf.