Buyer's checklist

How to evaluate a portfolio cyber risk platform

Every vendor demo looks good. These eight questions show which platform can defend its numbers in front of a board, an LP or a buyer.

Ask every portfolio cyber risk vendor the same eight questions. They cover whose framework is scored, whether answers carry evidence and get checked, whether dollar movement separates earned risk reduction from model changes, how figures and attack paths are labeled, where data and AI run, and who stands behind the vendor.

Eight questions to ask any vendor

Can you score every company against the framework we choose, including one we write?

Why it matters. One framework for every company, usually NIST CSF, forces your standard into someone else's shape. A strong answer. The firm picks the framework, or authors its own, and every company is scored against it the same way. How Testify answers. CIS Controls v8 at the safeguard level, NIST CSF 2.0 with a NIST-to-CIS crosswalk, or a framework you build and publish in the in-app authoring wizard.

Do your assessment questions ask for evidence, or invite a flattering yes?

Why it matters. “Do you have strong MFA?” gets a yes. “When did you last review MFA exceptions, and where is that recorded?” gets evidence. A strong answer. Questions anchored to a recent event and an artifact someone can check. How Testify answers. Testify's CIS Controls v8 questions are behavioral, anchored to a recent event and a record someone can check. Testify recommends questions from your incident history, and its local AI drafts behavioral follow-up questions for the coverage gaps it finds.

What checks an answer before it counts?

Why it matters. An unchecked answer is a claim, and claims are what a board, an LP or a buyer will challenge. A strong answer. Answers are reviewed against what the control requires, and the controls that matter are verified with evidence. How Testify answers. When an assessor asks, an AI coach checks the answer against the control's requirements, flags vague claims and suggests a status. The assessor decides. Verification campaigns grade controls Pass, Partial, Fail or Inconclusive, and failed or partial results open remediation tasks.

When the dollar figure drops, can you show how much came from verified control closes and how much from changing the model?

Why it matters. A figure that moves whenever the model moves cannot prove risk reduction. A strong answer. Earned movement and model re-estimates shown separately, never netted into one number. How Testify answers. The Board's exposure bridge separates risk reduction earned by verified control closes from model re-estimates and portfolio changes, and never merges them.

Does every number say how it was produced, and can we inspect the model?

Why it matters. A board treats every figure as fact unless the figure says otherwise. A strong answer. Each figure states how it was produced, and the model's assumptions are open to the customer. How Testify answers. The exposure bridge is marked Modeled, the risk trajectory keeps Proven, Modeled and Observed readings apart, and the loss model's assumptions are visible to customers inside the platform and theirs to change.

On an attack path, which step was observed and which was inferred?

Why it matters. An inferred chain shown as fact overstates what anyone has seen. A strong answer. The entry and the chain carry separate labels and separate confidence. How Testify answers. Only the external entry can be observed. Every later step through open control gaps is labeled inferred, and entry and chain confidence are shown separately.

Where do our portfolio data and the AI run, and does our data feed anyone's benchmark?

Why it matters. Your portfolio's weaknesses are among the most sensitive data the firm holds. A strong answer. Inside your own deployment, with no pooling across customers. How Testify answers. Testify runs in your cloud or on your premises, and all AI runs on a local model. Connector lookups send only a company's attested domains or IPs, and only with that company's consent. Companies are compared only within your own firm.

Who owns the vendor?

Why it matters. The platform holds every weakness in your portfolio, so it matters whether a sponsor you compete with for deals stands behind the vendor. A strong answer. A plain statement of whether any private-equity firm invests in or owns the vendor. How Testify answers. Cyber Flag has no private-equity investors or owners.

Put Testify through it

Bring these eight questions to a Testify walkthrough. Portfolio Directors and Operating Partners get priority access.

See it on your portfolio

Testify is accepting early customers. Portfolio Directors and Operating Partners get priority access to a guided walkthrough.