Reference · Glossary

Plain language,
no decoder ring.

Cyber and finance both come with their own vocabulary. Here is what Core3 means by the terms you will see across the site, in plain business English.

The products
and the layers.

  • Financial Exposure

    Core3's engagement that measures your cyber risk in dollars: what a cyber event would be expected to cost you, and a ranked plan to reduce it.

  • Cyber Operating Partner (vCISO / Fractional CISO)

    A senior security leader who runs your program on a retained basis. The market calls this a virtual or fractional CISO. The difference with Core3 is that we own the outcome and report against our own commitments.

  • Know · Own · Prove

    Core3's three layers: establish where you stand, build and run the program, and demonstrate that it is working.

  • CISO of record

    Core3 serving as your named, accountable security executive: the name on the SOC 2, and the person auditors, regulators, customers, and the board get answers from.

Measuring
the risk.

  • Cyber Risk Quantification (CRQ)

    Expressing cyber risk in financial terms instead of a high, medium, or low rating, so it can be weighed like any other business risk.

  • Financial Exposure Model

    The model behind the number: expected loss by category, built from your profile and set against your insurance coverage.

  • Annualized (expected) loss

    What you would expect cyber incidents to cost over a year, across the scenarios modeled. A planning figure, not a prediction of any single event.

  • Residual exposure

    The risk that remains after the priority actions are done. What is still on the table once you have acted.

  • Return on Security Investment (RoSI)

    How much risk a given investment removes, set against what it costs, so spending can be ranked by financial benefit rather than fear.

  • Risk tolerance & appetite

    The level of cyber risk leadership decides is acceptable to carry. The line the program is governed against.

  • Reserve recalibration

    As measured exposure falls, the capital a company holds against that risk can be adjusted, freeing money to redeploy.

Controls
and frameworks.

  • NIST CSF 2.0

    A widely used cybersecurity framework. Core3 assesses against it, then crosswalks the results to the other frameworks and questionnaires you get asked about.

  • Control effectiveness / Control validation

    How well a security control actually works, confirmed by independent testing rather than taken on faith.

  • Framework crosswalk

    Answering a control requirement once and mapping that evidence to many frameworks (SOC 2, ISO 27001, HIPAA, PCI, CIS) and customer questionnaires.

  • SOC 2 · ISO 27001

    Common security attestations and certifications that enterprise customers and partners ask you to produce.

Running
the program.

  • Managed GRC

    A retained program that runs governance, risk, and compliance on an ongoing basis, keeping evidence current instead of scrambling at audit time.

  • Third-Party Risk Management (TPRM) / Vendor Relationship Governance

    Governing the risk carried by the vendors and partners you rely on: what they can reach, and what you are on the hook for.

  • Incident Response (IR)

    The plan, playbooks, and roles for handling a security incident, so a bad day runs on preparation rather than improvisation.

  • Tabletop exercise

    A rehearsal that walks leadership through a realistic incident scenario end to end, with an after-action report at the finish.

  • Governed delivery network

    The vetted delivery partners who perform hands-on technical work under Core3's direction, so the party that validates the controls is not the one that installed them.

Still speaking
different languages?

Translating cyber risk into terms your board, your CFO, and your customers all understand is the whole point of Core3. That is where a conversation starts.