A rigorous, defensible basis for the hardest decision in cyber disclosure, ready inside the four-business-day window.
The SEC clock starts the moment you determine a cyber incident is material, and making that determination, then defending it, is exactly the call boards have had no rigorous way to make. That is the real problem, not the filing.
RiskD3M does the analysis and hands your executives a structured, evidence-grounded basis to make the call inside the four-business-day window. The AI does the work. Your executives do what only they can: review, approve, and decide. Item 106 then asks your board to show, each year, how it governs that risk.
Most cyber risk numbers are modeled from other companies' losses and your own questionnaire answers. RiskD3M is built the other way: today, an analysis grounded in your facts and your own thresholds; through our pilot program, dollar exposure computed directly from your environment over read-only telemetry. When a board signs its name to a figure, provenance is everything.
A severity rating cannot be set against a budget line, an insurance limit, or another department's request, because it is not denominated in anything. Cyber risk quantification translates the same technical findings into modeled money: expected annual loss, a tail figure, and a stated range, computed from your own financial anchors and the control efficacy actually observed in your environment.
Every parameter is disclosed and the arithmetic is deterministic, so the same facts always produce the same figure and anyone can check it. Where evidence is missing the range widens, rather than the number quietly filling in. An unobserved control domain is reported as unobserved, never scored as though it passed.
Stated in dollars, exposure stops being a security topic and becomes a governance one. Directors, executives and acquisition authorities can hold it against a stated risk tolerance, weigh it beside every other claim on capital, and ask the obvious next question: what does fixing this buy us.
The analysis answers that directly. Your report ranks each control domain by the expected annual loss it would remove, computed by re-running the same model with that domain brought to passing, so the ranking cannot disagree with the headline figure. A domain we did not measure is listed as unobserved and claims no reduction, because there is no measured posture to improve on. You set each reduction against your own cost. We publish no return-on-investment number, because the cost side is yours and inventing it would make the ratio fiction.
Cyber underwriting still runs on annual questionnaires: self-reported, point-in-time, and impossible to falsify. Both sides know it, so the carrier prices the uncertainty into the premium and the well-run company subsidises the poorly-run one, because neither can prove which they are.
The obstacle is not willingness. It is that proving posture has meant handing over the evidence, and no company is going to ship engineering files, cloud configuration or identity data to a carrier or to a vendor cloud. So RiskD3M does not ask for it.
A read-only server runs inside your network and queries your own telemetry: patching, identity, cloud configuration, endpoint coverage, logging. Nothing in the protocol can change anything: there is no remediation verb.
What crosses outward is a score per control domain, counts, and a SHA-256 digest of the evidence measured. The result type has no field capable of carrying a record, a log line or a file, and a payload bearing one is refused at the boundary.
Each measurement is signed on your premises and chained to the last, so an underwriter can confirm a score corresponds to a specific evidence set, taken at a stated time, unaltered since, while the evidence itself stays with you.
An insurance placement has three sides and standard compliance tooling has one. Here they are separate in the software, not by policy: you own the evidence and the decision to release anything about it. Your broker sees that an attestation exists and how complete it is, and only while a release naming them is live. Your underwriter receives the attestation issued to them, and never your findings.
Release is per carrier, it carries an expiry, and it can be withdrawn, and a withdrawal takes effect on the next request rather than the next cycle. There is no override path and no automatic approval anywhere in it.
The rule that matters most, and the reason this can be written into a policy at all: if a telemetry source is disconnected, that domain is reported unobserved. Never as passing, never as a cached earlier value, and never quietly dropped from the total. An attestation names which domains were dark, so incomplete coverage reads as incomplete rather than as a clean bill.
We supply a measurement and its provenance. The underwriting decision, including any discount, is the carrier's.
Where an AI agent is involved, whether a policy responds turns on how the event is classified. We publish the taxonomy we use openly, under CC BY 4.0, because it is worth more to this market as a shared language than as a private one.
Your team supplies the incident facts in one structured request. The agent takes it from there. No consulting engagement, no workshop calendar.
The engine screens the facts against your own thresholds and the SEC's qualitative factors, computes the deadline, and drafts the board memo for you.
Your executives and board determine materiality and make any filing. RiskD3M produces the analysis and the record; it never makes the determination.
See a sample determination (PDF) Illustrative, from a fictional company. Every factor shown.
Interested in continuous materiality readiness, measured monthly from your own environment? That is our pilot program. Ask about the pilot.