Cyber risk review for CFOs. Your exposure, priced in annual dollars where data permits.
A penetration test tells you what is broken. It does not tell you what a breach would cost, or how much that cost falls if you fix the three things that matter most. This review prices your cyber exposure the way you price any other risk: probability times cost of the event. Then it ranks what to fix first. Built from your contracts and your environment, not a generic calculator. The review is performed by people who did not build or run the controls it examines. It is not an audit or a certification, and Preside may later be engaged to manage remediation. The review works with your CIO or CISO: they provide access and context, and the findings are written so they can take them to the CFO and board.
Who this is for
Four seats that need the same exposure number, in different language
The same underlying exposure gets reported four different ways depending on who is asking. This review produces one set of numbers that answers all four.
IT & Security Leadership
Own the remediation
You are the one who has to decide what gets fixed first with a finite budget and a finite team. The review ranks fixes by how much each one reduces expected loss, not by severity labels alone, so the order of fixes reflects actual priority.
CISO
Needs a documented posture
When the board asks "how exposed are we and what are we doing about it," the answer needs to be a documented figure and a ranked plan, not a general sense that things are improving. This produces the report that carries that conversation.
Compliance & GRC Leads
Own the audit response
Auditors, regulators, and customer security reviews all ask for evidence of controls, not assurances. The review documents what controls exist, what evidence supports them, and where the gaps are, in a form built to be handed to an outside reviewer.
CFO / Board
Need exposure in financial terms
Technical findings do not fit on a board agenda. An expected-loss figure, a likelihood and impact range, and a ranked list of what each fix is worth, do. The output is written for the people who decide the budget, not the people who run the tools.
The core output
Expected loss, not a severity count
A finding marked "critical" does not tell a CFO what it is worth to fix. Expected loss does. It is the probability of an event in a given year, multiplied by what that event would cost the business if it happened. The review builds this figure for each major risk category, using evidence gathered from your actual environment, not a generic list.
Once expected loss is priced, remediation stops being a list and becomes a ranked set of decisions: which fix removes the most dollars of exposure per dollar spent, and in what order.
Example: expected loss
Low
Likely
High
Assume the yearly chance of an incident could reasonably run from 4 to 6 percent, and its cost (lost revenue, response, customer notification, and recovery) from $1.5M to $3M, with 5 percent and $2M the most likely. That gives expected loss of $60,000 (low), $100,000 (likely), and $180,000 (high) per year. A control that cuts the likely chance to 2 percent lowers the likely figure by $60,000 a year.
Why evidence matters
Carriers, auditors, and customers can ask the same question: show the evidence
Cyber insurance applications used to be a yes-or-no form. Insurers can ask for evidence of specific controls at underwriting and renewal, such as MFA coverage, endpoint detection, and backups that have been tested. Requirements vary by carrier and policy. An application answer that turns out not to be fully accurate can become the reason a claim is disputed later. Audits, customer security reviews, and board questions can raise the same evidence gap. Insurance renewal is one reason to build this evidence. It is not the only one.
01
Cyber insurance renewal
Walk into the renewal with documented evidence for each control a carrier asks about, instead of filling out a form from memory. A stronger, evidenced application may help position the organization for terms.
02
Board and audit committee reporting
A documented exposure figure and a ranked list of fixes replace a general assurance that "security is improving," and survives a skeptical director's follow-up question.
03
Regulatory and compliance audits
Where a framework or regulation requires documented control evidence, the review produces the inventory and citations an auditor may request.
04
Customer and vendor security reviews
Enterprise customers often run security questionnaires before signing. Documented evidence can answer these faster than a completed form alone.
| Control area | Earlier form question | Example of a current request |
|---|---|---|
| Multi-factor authentication | "Do you use MFA?" (yes/no) | Which systems, what percentage of accounts, and how it is enforced |
| Endpoint detection | "Do you have endpoint protection?" (yes/no) | What is deployed, where coverage gaps exist, and how alerts are triaged |
| Backups | "Do you back up your data?" (yes/no) | Whether a restore has actually been tested, and how recently |
Example finding
What the review output looks like
An example built to show the format. Each finding includes evidence, a dollar impact range, remediation steps, and an owner.
Multi-factor authentication is not enforced on 22 percent of accounts with administrative access
- Evidence
- Identity provider export shows 31 of 142 accounts holding administrative or privileged roles without MFA enforced, concentrated in service accounts and legacy admin accounts created before the current MFA policy took effect.
- Impact
- These accounts are the highest-value target for credential-based attacks, since a single compromised password grants broad access with no second factor to stop it. Expected-loss range for this finding alone: $40,000 to $120,000 per year, based on an assumed 2 to 6 percent annual likelihood of a credential-based compromise and an assumed $2M cost if one of these accounts is used to reach production systems.
- Why it matters beyond the technical finding
- Cyber insurance applications often ask about this control, and an auditor or customer security review can request the same evidence. A documented gap with a remediation date is a materially different position than an application answer that assumes full coverage.
- Remediation
- Stage 1 (week 1): Enforce MFA on all accounts with administrative or privileged roles; exempt no account without a documented, time-boxed exception. Stage 2 (week 2 to 3): Replace legacy service accounts that cannot support MFA with managed identities or vaulted credentials. Stage 3: Add privileged-account MFA coverage to the quarterly control review.
- Owner / target
- IT Security Lead · target close within one quarter
The review
What the review delivers
Three outputs, built on the expected-loss method Preside uses across its risk work, applied to cyber exposure.
A risk inventory
Every major cyber risk category present in your environment: identity and access, endpoint and detection, backup and recovery, vendor and third-party exposure, and more, documented with evidence rather than assumed.
Low, likely, and high figures
Each risk shown as a low, likely, and high figure where data permits, not a single invented number. The assumptions behind each figure are shown, so you can see what moves it.
A ranked list of what to fix first
Fixes ordered by their effect on expected loss, each with an owner, so the next budget conversation starts from a ranked list and not a severity count. A full roadmap with cost estimates and a board-ready presentation belongs to the Security Posture Initiative.
Before you start
Questions worth answering before you start
Will this get us a lower cyber insurance premium?
No. Preside does not promise a lower premium. The review produces evidence for the controls carriers ask about, which can help position the organization for terms at renewal. The premium is the carrier's decision.
How is this different from a penetration test?
A penetration test tries to break in and reports what it found. This review prices what each category of risk would cost the business in dollars, likelihood and impact, and ranks fixes by how much they move that number. The two are complementary; neither replaces the other.
We already had a security review. Why do this?
Many security reviews stop at a list of findings with severity labels. This review starts there and goes further: it prices each finding's effect on expected loss, so the CFO and the board can see the same priority order the security team sees, in the same unit of measure the business already uses.
What if the number comes back small?
Then that is the finding, and we say so. If the evidence shows the organization's exposure and remediation needs do not justify a larger engagement, the review says that plainly instead of manufacturing urgency.
How does this relate to the Security Posture Initiative?
This is the shorter starting point. The Security Posture Initiative adds a gap analysis against NIST CSF 2.0, a remediation roadmap with effort and risk-reduction estimates, and a board-ready presentation. A review can stand on its own or lead into the Initiative.
Can the review put a dollar figure on every risk?
Where the data supports one. Risks that can be priced are shown as a low, likely, and high figure from your own contracts, costs, and history, with the assumptions listed. Where the data does not support a figure, the review says so and ranks the risk without inventing a number.
Know what your cyber risk would cost before the board, the auditor, or the carrier asks.
A documented view of your cyber exposure, priced in dollars where data permits, with a ranked list of what to fix first. The review takes about a week, a shorter option than the Initiatives. Timing depends on how quickly access and information arrive.