Questions,
answered plainly.
The questions executives ask most about how Core3 works, virtual and fractional CISOs, and cyber risk quantification. Straight answers, no jargon.
Frequently asked questions
-
01
Our security program isn't mature enough for this yet.
This is the most common reason people wait, and it has the logic backwards.
Nothing here requires a mature program. The work measures the one you have, using what you already hold: your last assessment, the tools already deployed, the questionnaires you have already answered. A program with gaps produces a clearer picture than a mature one, because the headroom is larger and the sequence is more obvious.
The harder problem is the one underneath. A program that cannot show progress has only spending to report, and spending is not an outcome. Progress requires a baseline. Waiting two years to mature the program means arriving at that same conversation with two more years of activity and still nothing to show for it.
Start where you are. The first report is a position. Every one after it is a trend.
-
02
We don't need financial modeling. We need things to get done.
Reasonable, and common when the work is being driven from a board or an investor.
The program runs the same either way. Priorities, owners, dates, and every commitment tracked to closure. Reporting can stay entirely on execution: what was committed, what shipped, what is late, and who owns it.
The financial view sits underneath it regardless, because it is what ranks the work in the first place. It is there when it becomes useful, and it usually does, because the question after "did it get done" is "what did it buy us."
-
03
Where do the numbers come from?
This is the question that sinks most attempts at this, and it is worth answering directly.
The numbers are not expert opinion, and they are not a maturity score converted into dollars. Exposure is modeled on commercial actuarial loss data: more than a billion cyber and technology loss events across 21 industries and 18 global regions, of the kind the cyber insurance market prices risk against. Core3 licenses that data and the models built on it rather than producing estimates in-house, so the loss basis is independent of the firm giving you the advice.
Core3 supplies the rest: your organizational profile, current threat data for your sector, and control effectiveness validated against live evidence from the tools you already run rather than a self-reported questionnaire.
Every figure traces back to what produced it, and the model runs the same way every quarter, so movement means something. When a director asks where the number came from, that is the answer.
-
04
What is a Cyber Operating Partner?
Core3's model for cyber leadership. The market calls it a virtual or fractional CISO, but the difference is accountability: Core3 owns the security program, translates risk into financial terms, and reports against its own commitments quarter over quarter, rather than only advising.
-
05
What is a vCISO, and how is it different from a fractional CISO?
Virtual CISO (vCISO) and fractional CISO are two names for the same thing: a senior security leader engaged part-time or on retainer instead of a full-time hire. Core3 delivers this as a Cyber Operating Partner, where the engagement is accountable for the outcome, not just for advice.
-
06
What is cyber risk quantification?
Expressing cyber risk in financial terms, in dollars, rather than a high, medium, or low rating on a heat map. It lets leadership weigh cyber risk like any other business risk and decide where the next dollar of security spending should go.
-
07
How do you measure cyber risk in dollars?
The Core3 Read models the loss a cyber event would be expected to cause, by category, using an actuarial base, your organizational profile, current threat data, and live evidence from the security tools you already run. It produces a dollar figure and a prioritized roadmap for reducing it.
-
08
What does Core3 deliver?
Three layers: Know (establish where you stand and quantify exposure), Own (build and run the program as your Cyber Operating Partner), and Prove (demonstrate it is working with board-ready evidence). One engagement, then a choice. The Core3 Read establishes where you stand, at one of two depths. From there, the program runs at one of three tiers: Advisor, Operator or Partner.
-
09
How is this different from a security assessment or a heat map?
A heat map is subjective and frozen in time, and a standard assessment measures posture without saying what the risk is worth. Core3 puts a defensible dollar figure on the exposure, keeps it current, and stays accountable for reducing it, so the answer holds up when a board, investor, or insurer checks.
-
10
What does it cost?
Pricing follows the scope of the engagement and is shared on request. Every engagement begins with the Core3 Read, which establishes where the program stands and what to do first. At the end of it you either run the plan yourself or Core3 runs it, and Core3 says plainly which it recommends.
-
11
Who is Core3 for?
Any organization accountable for cyber risk to someone who will ask, a board, an investor, an insurer, or an enterprise customer, without an in-house executive who can answer confidently. It also runs across a private equity or holding-company portfolio.
Still have
a question?
If the one keeping you up isn't here, that is a good reason to talk. No pitch on the first call.