Know your risk · The defensible position

Start with an honest read
of where you stand.

Most programs are assessed constantly and understood rarely. The Core3 Read takes the evidence you already hold, your last assessment, the scans, the questionnaires, the tools already running, and turns it into one position you can defend and one plan you can work. The dollar figure is part of it, on whichever page of the readout you want it.

What it takes to start.

Less than most people expect. Most of what Core3 needs is information you already have. Approximate answers are fine, and "we don't track that" is a normal place to begin.

  • The entity or business unit in scope. It does not have to be the whole enterprise.
  • Whatever evidence you already have: past assessments, audit reports, scans, customer questionnaires.
  • The frameworks and customer requirements you are held to.
  • The two or three business processes you cannot afford to lose, and the sensitive data you hold.
  • What security tooling is deployed, and what evidence it can share.
  • A few hours with the people who know the program: security, IT, and vendor management.
  • Who the results are for, and the decision they need to support.

A small amount of input from your team, in exchange for a clear read your leadership can act on. If the answer to something is "we don't track that," that is a finding, not a problem.

Five outputs.
One defensible position.

Know produces evidence, not a report. Each output stands on its own. Together they are what you take into a board meeting, an audit, or a renewal.

Threat context

Which attacker behavior actually applies to your sector, your footprint, and your data. Not a generic threat report with your logo on it.

Control effectiveness

How your controls perform, validated against live evidence from the tools you already run rather than a self-reported questionnaire.

Framework position

Where you stand against the obligations you carry, whether that is SOC 2, ISO 27001, or NIST CSF 2.0.

Consolidated findings

Scans, penetration tests, and assessments already sitting in the business, synthesized into a sequence rather than a backlog.

Financial exposure

What a cyber event would cost, in dollars, by loss category, against what insurance actually transfers. The strongest output, and where the rest of this lands.

The engagement

The Core3 Read.
Where you stand, and what to do about it.

One engagement, at one of two depths. The Read establishes the position. The Model validates it against live evidence and puts the roadmap in dollars. Most companies start with the Read and go deeper when the decision requires it.

You walk away with

  • A defensible position on where the program stands, across the obligations you carry
  • A plan that says what to do first, with an owner and a date on every item
  • With the Model: what your controls are actually doing, validated against live evidence
  • The gaps where reported maturity and real exposure diverge
  • Your financial exposure, in dollars by loss category, when you want that view
  • A straight answer on who should run the plan from here
  1. Depth 01 · The Read

    Weeks, not quarters

    Where you stand, from the evidence you already hold and what your team tells us. A position you can defend, a plan with owners and dates, and a directional dollar figure. Enough to brief a board, an investor, or an enterprise customer.

  2. Depth 02 · The Model

    Deeper, and verified

    Everything in the Read, checked against live evidence from the tools you already run rather than taken on report. The number firms up, and every item in the plan is priced by what it removes against what it costs. Built for the budget decision.

Read and Model together are priced below buying them separately. At the end of either, Core3 says plainly whether you should run the plan yourself or have Core3 run it. See how Core3 runs it →

What the model adds

See your risk
as a number.

Some decisions need more than a red-yellow-green heat map. When they do, Core3 puts a number on it: what a cyber event would cost, broken down by where risk concentrates, and what a prioritized plan removes from it. A color tells you something is wrong. A number tells you how wrong, what fixing it is worth, and whether the fix worked.

Where the number
comes from.

What a cyber event would cost you is measured against losses that actually happened. Seventeen years of cyber and technology loss events, more than a billion of them, across 21 industries and 18 global regions. It is the same loss data the cyber insurance market prices risk against. Core3 licenses that data and the models built on it, so the loss basis is independent of the firm giving the advice.

AI risk, in the
same number.

AI does not get a separate assessment. The Read measures it on the controls it actually lands on, so AI shows up in the same exposure number as everything else. Illustrative: control effectiveness across four AI surfaces, none above 62%.

56.9% / 56.6%

Embedded AI product features

On server and network assets.

Control effectiveness
62.0%

AI-assisted code generation

Compounding vulnerability-management gaps.

Control effectiveness
44.0%

Third-party AI subprocessors

Data extended into supplier environments. The sharpest surface.

Control effectiveness
55.0%

Shadow AI in operations

A detection gap against network monitoring.

Control effectiveness

AI needs no separate control domain or budget line. The sharpest surface is third-party AI subprocessors at 44%, the same supplier-management gap the roadmap already addresses. Scoring it first depends on knowing what is running: see what shadow AI is.

Where you are
paying twice.

Security tools accumulate. They get bought in different years, by different people, against different worries, and the overlap is rarely visible to anyone. Because the model measures what each control area actually removes, it also shows where two of them remove the same thing. That turns consolidation into a decision you can price rather than a hunch.

Overlap, priced

When two controls reduce the same exposure, the overlap appears as its own line instead of being counted twice. That line is also where the budget is buying one outcome more than once.

Consolidation you can defend

Before a tool is replaced, renewed, or cut, you can see what exposure moves and what does not, so the saving is weighed against the risk it changes rather than assumed.

Freed spend, redirected

What consolidation releases can go to the actions ranked highest by the risk they remove, so the exposure number moves without a larger budget.

To pursue this on its own, the Security Stack & Spend Review is the scoped version of the same question.

Scoped work,
added when you need it.

These run on their own or alongside a Read. Buying a Read does not bundle them. Each is fixed-scope and ends in a decision with a documented basis, never a report that sits on a shelf.

Insurance & Risk Transfer Review

The coverage structure read against modeled exposure: what the program transfers, what it silently retains, and where the two do not meet.

Controls & Maturity Assessment

Control maturity scored against NIST CSF 2.0, the honest read on how the program performs rather than how it is described.

Security Stack & Spend Review

Tooling overlap, utilization, and spend, so you can see what you are paying for and what it is actually buying down.

Privacy Risk & Gap Assessment

Privacy posture and policy evaluation, scoped to the obligations that apply to you rather than a generic checklist.

Resilience Assessment

Business impact analysis, backup and recovery validation, and ransomware resilience against a real scenario.

Cyber Due Diligence

Rapid diligence on deal timelines: exposure, integration risk, and the findings that change a valuation or a close.

AI Security & Readiness

AI use-case exposure and governance maturity, assessed before a questionnaire or a regulator does it for you.

Framework Position Assessment

Where you stand against every framework and customer requirement you carry, crosswalked once from the evidence you already hold rather than assessed again for each.

Ongoing framework alignment and compliance is a continuous program, not a one-time assessment, so it lives in Own rather than here.

"Probably fine" is a guess.
The Read tells you.

Whether it confirms you are fine or shows where you are not, you finish knowing where you stand, what to do first, and who should own it.
Start with the Read. Go deeper only if the decision calls for it.