Turn invisible risk into
decisions you can act on.
An AI-and-expert-led
cyber risk governance platform.
You may not be able to hire a full-time CISO, but you can externalize the function. From current-state assessment to risk visualization, board-level explanation, and continuous improvement — all in one place.
AI and experts back the security decisions of listed and growth companies that can't put a CISO in-house.
* The self-assessment plan is free for 14 days (card registration only; cancel during the trial at no charge). Consultation and materials are also free.
The three walls
every company runs into.
From risk visibility to explaining security without a CISO, and keeping it sustained —
challenges shared by listed companies and growth-stage companies alike.
Cyber risk cannot be quantified
You can't see where the risk lies or how big it is, so you can't prioritize what to fix first.
Visualizing cyber risk — see how we solve itNo dedicated CISO — and no way to explain risk to the board
Hiring a full-time CISO is costly and the talent market is tight, so there's no structure to back risk and investment with numbers to the board.
The external CISO function — see how we solve itAssessment is one-off and doesn't continue
Assessments take effort, end up one-shot, and the improvement cycle never starts.
AI-and-expert assessment flow — see how we solve itFor companies that can't put a CISO in-house —
a cyber risk governance platform.
CISOaaS combines AI and human experts to supportyour organization's cyber risk:current-state, visibility, investment decisions, and improvement.
Risk visibility
Quantify where and how much risk you carry, all the way down to mitigation priority. Evidence you can hand straight to the board.
Investment optimization
Turn risk into expected annual loss, then compute ROSI per countermeasure. Spell out 'which control, how much' so leadership can decide where the budget goes.
Continuous governance
Run assessment, analysis, and improvement in a loop. Track how risks shift and how response progresses over time — not deploy-and-done.
Operated by Securebase Inc., a cybersecurity services specialist.
See how it worksAI runs assessment, analysis,
and reporting on its own.
With self-assessment, results come without anyone in the loop.
Expert review is a value-add for higher plans that need explainability to leadership.
- 01ASSESS
AI hearing
Assess your security implementation status through a conversation with AI.
- 02ANALYZE
Risk analysis
Quantify attack-chain risk via the four-phase ACRA model.
- 03OPTIMIZE
Investment optimization
Compute optimal investment allocation and ROI with an economic model.
- 04PLAN
Strategy & roadmap
Build a short-/mid-/long-term initiative plan toward target maturity.
- 05REPORT
Report
Auto-generate executive reports. Up to here without humans in the loop.
Expert review
A security consultant validates and signs off on the AI's assessment, underwriting board-level explainability.
Self-assessment runs all of assessment, analysis, and reporting by AI — start to finish, no humans in the loop.
Expert-review-and-above plans add a security consultant who signs off as the external CISO before finalization, underwriting board-level explainability.
After the assessment, the focus shifts to addressing the findings.
Issues surfaced in the first assessment can be managed as risk items with owner, deadline, status, and comments — progress visualized on the dashboard. From the second assessment onward, just confirm the items that changed since last time — no need to start over. Executive reports can be exported in the latest state at any time.
Respond via CSIRT, then turn the lessons into risks.
If an incident occurs, record and track it under a predefined CSIRT structure and keep a response timeline. The post-mortem then generates preventive risk items that feed back into the next assessment and improvement cycle.
What you get is outcomes — not features.
With CISOaaS, security shifts from "uncontrolled"
to "controlled, with decisions you can defend."
Current-state visibility
Don't know what's missing
Framework-aligned, no blind spots
Risk visualization
Risk is a feeling in someone's head
Quantified along the attack chain, with losses as a probability distribution
Clear improvement priorities
No idea where to start
ROI-ranked priorities
Explanation to the board
Can't explain it, can't get budget
Quantitative board narrative, with worst-case loss attached
Audit readiness
Prepare materials by hand, every time
Assessment history and audit logs ready as evidence at any time
Continuous improvement
One-off assessments that go stale
Improvement cycle progress, visualized over time
Assess against frameworks — nothing slips through.
Aligned with major frameworks like CIS Controls, NIST CSF, and ISO 27001,maturity scores and risk-level distribution quantify your current state.
- Overall score & grade:A 0–100 score and an S/A/B/C/D grade show security maturity at a glance.
- Framework coverage:Visualize attainment per standard — CIS IG1/IG2/IG3, NIST CSF's six functions, and more.
- Risk-level distribution:Detected risks are tallied by severity — Critical / High / Medium / Low — to clarify priority.
See the whole risk picture at a glance.
Assessment results, once scattered, are consolidated on a single dashboard.Executive reporting and field-level improvement start from the same screen.
- Risk at a glance:Score, risk distribution, and framework coverage in one view — intuitively see where you're weakest right now.
- Leadership and the field see the same picture:Jargon-free visuals let leadership, IT, and audit share the same current-state understanding.
- Investment decisions backed by numbers:Expected loss (FAIR probability distribution), recommended investment, and ROI per countermeasure — everything you need to decide, in one place.
- システム停止30%
- 情報漏えい25%
- マルウェア感染20%
- 内部不正15%
- その他10%
- アクセス制御の不備¥320万
- 認証管理の遅れ¥260万
- メールセキュリティ¥180万
- バックアップ体制¥130万
- 従業員の意識向上¥97万
アクセス制御の見直し
認証基盤・メール対策の強化
監視体制の高度化
Decide investment by loss and ROI.
Risk is converted into annual expected loss (a FAIR probability distribution), and return on security investment (ROSI) is calculated per countermeasure — so a limited budget is framed as "which control, how much."
- Expected loss shown as a probability distribution (95% CI, worst case)
- Countermeasures ranked by return on security investment (ROSI)
- Recommended investment ceiling — the numbers for the decision, in one place
| 対策 | ROSI |
|---|---|
| EDR 導入 | +340% |
| MFA 全社展開 | +220% |
| SIEM 構築 | +180% |
Ready to hand straight to leadership.
Assessment results and economic analysis are auto-bundled into a PDF report usable in executive meetings and the board. The time spent crafting reports goes away.
- Score summary (coverage per framework)
- Economic analysis (expected loss, optimal investment, ROI)
- Investment priority (ROSI ranking per countermeasure)
- Strategy & roadmap (target maturity, short/mid/long-term initiatives)
- Risk items and response status
評価報告書
* Illustrative screen. The figures shown are samples — actuals are computed from your usage.
See how these numbers are computedWhy does what used to be a one-off security assessment
turn into continuous governance?
Because the AI runs the core of assessment — assessment, analysis, and reporting — on its own.
Unlike legacy models where cost stacks up by the man-month, a monthly flat fee lets you run assessments continuously.
Automating doesn't mean compromising on objectivity.
CISOaaS assessments are grounded in our own method ACRA (MITRE ATT&CK-aligned), the FAIR model that expresses loss as a probability distribution, and the Gordon-Loeb model from information security economics.
Less manual effort doesn't mean less objectivity or explainability.
* Cost references for legacy assessments and hiring a dedicated CISO are based on general market rates per our research and do not represent any specific company's pricing. See the pricing section for our published plans.
All prices are public.
From AI-driven 'Self-assessment' to expert sign-off with quarterly review,
a dedicated external CISO engagement, up to group-wide Enterprise.
Pick what your structure calls for. Pricing is public and transparent.
Self-assessment
For lean starts, SMB
Do it yourself — visibility with low cost and high speed.
Expert review
For mid-size & IPO-preparation
An expert's sign-off, so you can defend it to leadership.
Dedicated CISO
For listed & large enterprises (single entity)
A dedicated external CISO, with you continuously.
Enterprise
For group enterprises & regulated industries
Group-wide and regulation-fit — designed individually.
Designed individually based on number of group companies and scope
Feature comparison by plan
See exactly what each plan adds — every feature, presence or absence, at a glance.
| Feature comparison by plan | Self-assessment | RecommendedExpert review | Dedicated CISO | Enterprise |
|---|---|---|---|---|
| Risk assessment | Included | Included | Included | Included |
| CIS Controls level | IG1 | IG2 | IG3 | IG3 + custom |
| SCS rating program level | ★3 | ★4 | ★4 | ★4 + custom |
| Framework recommendation | Included | Included | Included | Included |
| AI hearing | Included | Included | Included | Included |
| ACRA risk analysis | Included | Included | Included | Included |
| AI strategy & roadmap drafting | Not included | Included | Included | Included |
| Risk control management | Included | Included | Included | Included |
| Economic analysis (Gordon-Loeb / FAIR / ALE / ROSI) | Included | Included | Included | Included |
| Security initiative management | Included | Included | Included | Included |
| Incident management & CSIRT | Included | Included | Included | Included |
| AI incident assist (auto-classification, post-mortem / preventive-risk generation) | Not included | Included | Included | Included |
| CISO advisor | Included | Included | Included | Included |
| Security dashboard | Included | Included | Included | Included |
| Industry benchmark comparison | Not included | Included | Included | Included |
| PDF report generation | Included | Included | Included | Included |
| Audit log viewing | Included | Included | Included | Included |
| Tamper detection for audit logs (hash chain) | Included | Included | Included | Included |
- IncludedRisk assessment
- IG2IG2CIS Controls level
- ★4★4SCS rating program level
- IncludedFramework recommendation
- IncludedAI hearing
- IncludedACRA risk analysis
- IncludedAI strategy & roadmap drafting
- IncludedRisk control management
- IncludedEconomic analysis (Gordon-Loeb / FAIR / ALE / ROSI)
- IncludedSecurity initiative management
- IncludedIncident management & CSIRT
- IncludedAI incident assist (auto-classification, post-mortem / preventive-risk generation)
- IncludedCISO advisor
- IncludedSecurity dashboard
- IncludedIndustry benchmark comparison
- IncludedPDF report generation
- IncludedAudit log viewing
- IncludedTamper detection for audit logs (hash chain)
Hiring a dedicated CISO is highly competitive and personnel costs are high.
An external CISO function lets you stand up the structure on a monthly fee and keep running it continuously.
Economic analysis estimates risk costs to support security investment decisions (across all plans).
We publish prices to make the difference with opaque legacy pricing clear.
Minimum term, payment terms and other details are shared at contracting.
Inquiries, estimates, and materials are all free.
The self-assessment plan comes with a 14-day free trial (1 assessment, up to 3 users, AI usage cap). Sign-up requires a card, but no charges apply during the trial and cancelling within the period is free. After 14 days, ¥30,000 (¥33,000 incl. tax) per month is charged automatically. Trial data carries over to your paid contract. See the Specified Commercial Transactions Act notice for details.
Frequently asked questions
Questions we often hear from companies evaluating CISOaaS, with answers.
Can we use it without a dedicated CISO or security specialists?
Yes. On the Self-assessment plan, AI drives assessment, analysis, and reporting and produces results without humans in the loop. On Expert-review-and-above plans, our security consultants sign off on the assessment before finalization, so you can operate it as an external CISO function. It also works for organizations where IT runs security as a side duty.
Can we brief leadership even without deep security expertise?
Yes. Assessment results are auto-bundled into a PDF for leadership (score summary, economic analysis, investment priority, improvement roadmap). You can report the state of risk and the basis for investment with quantitative data.
How should we choose a plan?
Pick what your structure calls for. We publish prices on the four plans (Enterprise is custom-quoted): Self-assessment (AI runs end-to-end), Expert-review (expert sign-off + quarterly review), Dedicated CISO (a dedicated specialist as the external CISO), and Enterprise (group-wide and regulation-fit, designed individually). Start with Self-assessment to make the current state visible, and move to a higher plan when you need executive explainability or hands-on accompaniment.
Is there a cap on AI usage in each plan?
Every plan has a monthly cap on AI usage. The specific limits are shared at contract time. Typical usage rarely reaches the cap; if you do approach it, we'll reach out in advance so you can consider moving to a higher plan or arranging additional capacity.
What can I do during the free trial?
You can try the same features as your prospective plan free for 14 days. During the trial, usage is limited to 1 assessment and up to 3 users, with a cap on AI usage; PDF reports include an evaluation watermark. After the trial ends, you keep read-only access for 14 days, and all assessment results and reports carry over when you subscribe.
Can we use the AI's assessment results as-is?
It depends on the plan. On Self-assessment, AI drives from first-pass assessment to finalization on its own — results are immediate. On Expert-review-and-above, before delivery to leadership our security consultants sign off in a two-stage flow; the score, risk analysis, and report are finalized after sign-off.
On Expert-review, does '1 review' mean once per month?
It means 'one review and sign-off per assessment, before finalization' — not a per-month or per-contract count. If you run multiple assessments in the same tenant, each one gets a review before finalization.
How are risk and loss numbers computed?
Risk is quantified along the attack chain via our own method ACRA (MITRE ATT&CK-aligned). Expected loss is computed as a probability distribution using the international standard FAIR (Factor Analysis of Information Risk) plus Monte Carlo simulation — telling you 'the 95% annual loss range' and 'how bad a worst case looks', a more confident basis for investment than a single point estimate. Optimal investment is computed via the Gordon-Loeb model from information security economics.
Can we assess multiple frameworks in parallel?
Yes. The six frameworks — CIS Controls v8.1.2 / NIST Cybersecurity Framework (CSF) 2.0 / ISO 27001:2022 / Supply-chain Security Evaluation Scheme (SCS) / OWASP Top 10 for LLM / AI Governance Maturity Assessment — totaling 628 assessment items can be run in parallel within the same tenant. You can also choose a different IG / ★ level for each assessment.
Can we assess security risks specific to AI systems (generative AI / LLM)?
Yes. We cover OWASP Top 10 for LLM Applications 2025 (with MITRE ATLAS attack-tactic tags), so AI-specific risks like prompt injection, sensitive-data leakage, data/model poisoning, and excessive agency are visualized in the same framework as your existing cyber risk analysis (ACRA) and ROI. Designed for organizations using, building, or providing internal chatbots, RAG, or AI agents.
Can we assess organizational AI governance (structure, policy, risk management, monitoring) for AI use and development?
Yes — via the AI Governance Maturity Assessment (10 management domains, 68 questions), which we built ourselves by referencing NIST AI RMF 1.0 and ISO/IEC 42001:2023. Where OWASP Top 10 for LLM addresses the technical risks of individual AI systems, this framework visualizes the organizational/policy layer — how the organization governs and manages AI — on a 0–5 maturity scale. Available on all plans. It is not the official standard published by NIST or ISO/IEC, and does not guarantee certification.
What is the Attacker-Perspective Simulation?
When each roadmap phase is assumed complete, our proprietary model — applying ideas from security game theory (Stackelberg Security Games; Tambe et al., 2011) — previews how an attacker's likely focus would shift across areas, with AI-generated commentary. It is not a forecast of actual attack probabilities. Available on the Dedicated CISO and Enterprise plans. See 'Attacker-Perspective Simulation: methodology' in Help for the full rationale and references (with DOIs).
Can we aggregate group companies' security status?
Yes. The Expert-review plan supports up to 5 additional tenants and Dedicated CISO up to 15, with larger group structures covered by the Enterprise plan (custom quote). Admins and viewers of the parent tenant can browse and aggregate their scores, risks, and contract status. Data remains fully isolated across tenants.
Where is the data stored?
In the AWS Tokyo region. Data is fully isolated across tenants, and all major operations from sign-in through assessment and report generation are recorded to the audit log (retained for 1 year, exportable in CSV / JSON).
Will the data we enter be used to train the AI?
No. AI (large language models) is used for the AI hearing, risk analysis, and report generation, but data sent through this service is never used to train the AI. Data is stored in the AWS Tokyo region and fully isolated across tenants. See our Privacy Policy for details.
Is the security posture sufficient?
We implement MFA, a strong password policy, browser-side security controls, per-feature rate limiting, audit log retention and export for all major operations, and error monitoring. Data is fully isolated across tenants and cannot be cross-referenced by design.
What are the contract term and termination conditions?
This is a monthly subscription. Please contact us for details such as minimum contract period.
