What changed
The Cyber Maturity Assessment got rebuilt from the UI down to the math. The previous version showed customers a red/yellow/green rating and a hardcoded cost methodology. The new version is a progressive-disclosure interface backed by real FAIR-style Monte Carlo simulation and per-finding remediation cost derived from live BLS and Gartner data.
Why it matters
The compliance industry runs on red/yellow/green ratings that no one can defend to a board and no one can act on operationally. Progressive-disclosure UX plus real quantification math means the assessment now produces two outputs that most maturity tools cannot: a defensible dollar figure a CFO will accept, and a specific set of actions ranked by ALE reduction per remediation dollar — the prioritization the operating team can actually run.
The quantification half of this is the same CRQ discipline we write about for mid-market programs; see Cyber Risk Quantification for Mid-Market for the methodology the assessment output feeds.
Availability
Shipping today to every platform tier. New customers get the first assessment auto-triggered once business context is in place; existing customers see the new interface and the Monte Carlo math on their next assessment run.
No manual migration is required. The Loss Exceedance Curve and per-finding ALE populate from the next simulation run against your current business context, control coverage, and threat model. The BLS and Gartner labor rate is applied by default and can be overridden in assessment settings.
Known limitations
The BLS and Gartner blended labor rate is a cited default. Organizations whose actual loaded cost per hour differs should override it before taking the remediation-cost number into a budget conversation.
The LEC and per-finding ALE recompute on each simulation run; they are not continuously live. Material changes to control coverage or the threat model require a fresh run to be reflected.
The auto-triggered first assessment requires business context (scope, revenue, data categories) to be captured. Until that is complete, the platform will not run the first assessment on the customer's behalf.