Turn invisible risk into
decisions you can act on.
An AI-and-expert-led
cyber risk governance platform.
You may not be able to hire a full-time CISO, but you can externalize the function. From current-state assessment to risk visualization, board-level explanation, and continuous improvement — all in one place.
AI and experts back the security decisions of listed and growth companies that can't put a CISO in-house.
* Consultations, quotes and materials are free. Ask us about a trial when you get in touch.
The three walls
every company runs into.
From risk visibility to explaining security without a CISO, and keeping it sustained —
challenges shared by listed companies and growth-stage companies alike.
Cyber risk cannot be quantified
You can't see where the risk lies or how big it is, so you can't prioritize what to fix first.
Visualizing cyber risk — see how we solve itNo dedicated CISO — and no way to explain risk to the board
Hiring a full-time CISO is costly and the talent market is tight, so there's no structure to back risk and investment with numbers to the board.
The external CISO function — see how we solve itAssessment is one-off and doesn't continue
Assessments take effort, end up one-shot, and the improvement cycle never starts.
AI-and-expert assessment flow — see how we solve itFor companies that don't need a dedicated CISO in-house —
a cyber risk governance platform.
CISOaaS combines AI and human experts to supportyour organization's cyber risk:current-state, visibility, investment decisions, and improvement.
Risk visibility
Quantify where and how much risk you carry, all the way down to mitigation priority. Evidence you can hand straight to the board.
Investment optimization
Turn risk into expected annual loss, then compute ROSI per countermeasure. Spell out 'which control, how much' so leadership can decide where the budget goes.
Continuous governance
Run assessment, analysis, and improvement in a loop. Track how risks shift and how response progresses over time — not deploy-and-done.
Operated by Securebase Inc., a cybersecurity services specialist.
See how it worksAI runs assessment, analysis,
and reporting on its own.
With self-assessment, results come without anyone in the loop.
Expert review is an add-on you can attach when you need explainability to leadership.
- 01ASSESS
AI hearing
Assess your security implementation status through a conversation with AI.
PlansAll plans
- 02ANALYZE
Risk analysis
Quantify attack-chain risk via the four-phase ACRA model.
PlansAll plans
- 03OPTIMIZE
Investment optimization
Compute optimal investment allocation and ROI with an economic model.
PlansAct and above (not available on Assess)
- 04PLAN
Strategy & roadmap
Build a short-/mid-/long-term initiative plan toward target maturity.
PlansInitiative management and the execution view, and AI-driven planning and its PDF export, are all available on Act and above
- 05REPORT
Report
Auto-generate executive reports. Up to here without humans in the loop.
PlansAssess and above (the economic analysis chapter requires Act and above)
Expert review
A security consultant validates and signs off on the AI's assessment, underwriting board-level explainability.
PlansWith the Expert Review add-on
Self-assessment runs all of assessment, analysis, and reporting by AI — start to finish, no humans in the loop.
The Expert Review add-on adds a security consultant who signs off as the external CISO before finalization, underwriting board-level explainability.
After the assessment, the focus shifts to addressing the findings.
Issues surfaced in the first assessment can be managed as risk items with owner, deadline, status, and comments — progress visualized on the dashboard. From the second assessment onward, just confirm the items that changed since last time — no need to start over. Executive reports can be exported in the latest state at any time.
Respond via CSIRT, then turn the lessons into risks.
If an incident occurs, record and track it under a predefined CSIRT structure and keep a response timeline. The post-mortem then generates preventive risk items that feed back into the next assessment and improvement cycle.
What you get is outcomes — not features.
With CISOaaS, security shifts from "uncontrolled"
to "controlled, with decisions you can defend."
Figures are samples. Actual values are calculated from your assessment results.
Current-state visibility
Don't know what's missing
Framework-aligned, no blind spots
Risk visualization
Risk is a feeling in someone's head
Quantified along the attack chain, with losses as a probability distribution
Clear improvement priorities
No idea where to start
ROI-ranked priorities
Explanation to the board
Can't explain it, can't get budget
Quantitative board narrative, with a sense of the possible loss range attached
Audit readiness
Prepare materials by hand, every time
Assessment history and audit logs ready as evidence at any time
Continuous improvement
One-off assessments that go stale
Improvement cycle progress, visualized over time
Assess against frameworks — nothing slips through.
Aligned with major frameworks like CIS Controls, NIST CSF, and ISO 27001,maturity scores and risk-level distribution quantify your current state.
- Overall score & grade:A 0–100 score and an S/A/B/C/D grade show security maturity at a glance.
- Framework coverage:Visualize attainment per standard — CIS IG1/IG2/IG3, NIST CSF's six functions, and more.
- Risk-level distribution:Detected risks are tallied by severity — Critical / High / Medium / Low — to clarify priority.
See the whole risk picture at a glance.
Assessment results, once scattered, are consolidated on a single dashboard.Executive reporting and field-level improvement start from the same screen.
- Risk at a glance:Score, risk distribution, and framework coverage in one view — intuitively see where you're weakest right now.
- Leadership and the field see the same picture:Jargon-free visuals let leadership, IT, and audit share the same current-state understanding.
- Investment decisions backed by numbers:Expected loss (FAIR probability distribution), recommended investment, and ROI per countermeasure — everything you need to decide, in one place.
- システム停止30%
- 情報漏えい25%
- マルウェア感染20%
- 内部不正15%
- その他10%
- アクセス制御の不備¥320万
- 認証管理の遅れ¥260万
- メールセキュリティ¥180万
- バックアップ体制¥130万
- 従業員の意識向上¥97万
アクセス制御の見直し
認証基盤・メール対策の強化
監視体制の高度化
Decide investment by loss and ROI.
Risk is converted into annual expected loss (a FAIR probability distribution), and return on security investment (ROSI) is calculated per countermeasure — so a limited budget is framed as "which control, how much."
- Expected loss shown as a probability distribution (prediction range, P95/P99)
- Countermeasures ranked by return on security investment (ROSI)
- Recommended investment ceiling — the numbers for the decision, in one place
| 対策 | ROSI |
|---|---|
| EDR 導入 | +340% |
| MFA 全社展開 | +220% |
| SIEM 構築 | +180% |
Ready to hand straight to leadership.
Assessment results and economic analysis are auto-bundled into a PDF report usable in executive meetings and the board. The time spent crafting reports goes away.
- Score summary (coverage per framework)
- Economic analysis (expected loss, optimal investment, ROI)
- Investment priority (ROSI ranking per countermeasure)
- Strategy & roadmap (target maturity, short/mid/long-term initiatives)
- Risk items and response status
評価報告書
* Illustrative screen. The figures shown are samples — actuals are computed from your usage.
See how these numbers are computedWhy does what used to be a one-off security assessment
turn into continuous governance?
Because the AI runs the core of assessment — assessment, analysis, and reporting — on its own.
Unlike legacy models where cost stacks up by the man-month, a monthly flat fee lets you run assessments continuously.
Automating doesn't mean compromising on objectivity.
CISOaaS assessments are grounded in our own method ACRA (MITRE ATT&CK-aligned), the FAIR model that expresses loss as a probability distribution, and the Gordon-Loeb model from information security economics.
Less manual effort doesn't mean less objectivity or explainability.
* Cost references for legacy assessments and hiring a dedicated CISO are based on general market rates per our research and do not represent any specific company's pricing. See the pricing section for how each plan is priced.
Choose a plan by capability. Add experts when you need them.
From the Assess plan, where AI self-assessment maps your current posture, to the Act and Govern plans that drive remediation and group-wide governance.
Product plans are chosen by capability and scale; expert approval and external CISO support are added as add-ons when needed.
Assess pricing is published. Act and above, and add-ons, are quoted as a fixed monthly fee based on your organization and scope.
Assess
For small and medium businesses
Track improvement with regular reassessment
Act
For mid-sized and pre-IPO companies
Economic analysis and remediation tracking
Fixed monthly fee by team size and scope
Govern
For large companies and groups
Group-wide governance
Fixed monthly fee by team size and scope
Enterprise
For large groups and regulated industries
Custom design and dedicated support
Custom quote by scale and requirements
Add expert support as an add-on
Product plans run without added operational effort on your part. When you need expert sign-off or ongoing support as an external CISO, add it as an add-on.
Expert Review
Can be added to the Act plan and above
- Review & approval of the first-pass AI evaluation
- Review of generated deliverables (ROI, initiatives, report)
- Quarterly review
Dedicated CISO Support
Can be added to the Govern plan and above
- Everything in Expert Review
- Ongoing support from a dedicated external CISO
- Attendance at monthly reviews and management meetings
- Support for ad hoc consultations
| Expert Review / Dedicated CISO Support | Expert Review | Dedicated CISO Support |
|---|---|---|
| Expert review & sign-off of first-pass assessment | Included | Included |
| Review of generated deliverables (ROI, initiatives, report) | Included | Included |
| Quarterly review | Included | Included |
| Dedicated external CISO engagement | Not included | Included |
| Monthly reviews & management meeting attendance | Not included | Included |
| Plans that can add this | Act and above | Govern and above |
Feature comparison by plan
See exactly what each plan adds — every feature, presence or absence, at a glance. What a checkmark cannot show — the consistency of our assessments, the peer set behind the benchmarks, the expert review behind the numbers — we walk you through individually.
| Feature comparison by plan | Assess | RecommendedAct | Govern | Enterprise |
|---|---|---|---|---|
| Security dashboard | Included | Included | Included | Included |
| Risk assessment | Included | Included | Included | Included |
| AI hearing | Included | Included | Included | Included |
| Assessment frequency | Anytime | Anytime | Anytime | Anytime |
| CIS Controls level | IG1 | IG1–2 | IG1–3 | IG1–3 |
| SCS rating program level | ★3 | ★3–4 | ★3–4 | ★3–4 |
| Framework recommendation | Included | Included | Included | Included |
| Evidence Library (bulk policy upload & question matching) | Not included | Included | Included | Included |
| PDF report generation | Included | Included | Included | Included |
| Risk control management | Current-state log only | Included | Included | Included |
| Economic impact analysis (expected loss & return on investment) | Not included | Included | Included | Included |
| AI strategy & roadmap drafting | Not included | Included | Included | Included |
| Security initiative management | Not included | Included | Included | Included |
| Annual plan (fiscal-year task management & 3-year roadmap) | Not included | Included | Included | Included |
| Industry benchmark comparison | Not included | Included | Included | Included |
| Security check sheet response support | Not included | Included | Included | Included |
| CISO advisor | Not included | Included | Included | Included |
| Incident management & CSIRT | Not included | Included | Included | Included |
| AI incident assist (auto-classification, post-mortem / preventive-risk generation) | Not included | Not included | Included | Included |
| SAML SSO | Not included | Included | Included | Included |
| Audit log viewing | Included | Included | Included | Included |
| Audit log export (CSV / JSON) | Not included | Included | Included | Included |
| Users | 3 | 10 | 25 | Custom quote |
| Manageable tenants | 0 | 0 | 15 | Custom quote |
| Parent-child tenants | Not included | Not included | Included | Included |
| Additional users | Available | Available | Available | Custom |
| Additional tenants | — | — | Available | Custom |
| Attacker-perspective simulation | Not included | Not included | Included | Included |
| Risk appetite policy | Not included | Not included | Included | Included |
| Custom framework ingestion※ | Not included | Not included | Not included | Included |
| Priority support※ | Not included | Not included | Not included | Included |
| Custom design & onboarding※ | Not included | Not included | Not included | Included |
- IncludedSecurity dashboard
- IncludedRisk assessment
- IncludedAI hearing
- AnytimeAnytimeAssessment frequency
- IG1–2IG1–2CIS Controls level
- ★3–4★3–4SCS rating program level
- IncludedFramework recommendation
- IncludedEvidence Library (bulk policy upload & question matching)
- IncludedPDF report generation
- IncludedRisk control management
- IncludedEconomic impact analysis (expected loss & return on investment)
- IncludedAI strategy & roadmap drafting
- IncludedSecurity initiative management
- IncludedAnnual plan (fiscal-year task management & 3-year roadmap)
- IncludedIndustry benchmark comparison
- IncludedSecurity check sheet response support
- IncludedCISO advisor
- IncludedIncident management & CSIRT
- nonoAI incident assist (auto-classification, post-mortem / preventive-risk generation)
- IncludedSAML SSO
- IncludedAudit log viewing
- IncludedAudit log export (CSV / JSON)
- 1010Users
- 00Manageable tenants
- nonoParent-child tenants
- AvailableAvailableAdditional users
- ——Additional tenants
※ Provided under individual contract
Economic analysis estimates risk costs to support security investment decisions (Act plan and above; not available on the Assess plan).
- All pricing is a flat monthly fee, to make the difference with man-month billing clear.
- Pricing for Act and above is shared when you contact us, based on your structure and scope. Minimum term and payment terms are shared at contracting.
- Accounts for every plan are issued after you contact us and we confirm your requirements; we no longer offer online self-registration. Ask us about a trial when you get in touch. See the Specified Commercial Transactions Act notice for payment and cancellation terms.
- Responses may be statistically aggregated in a form that cannot identify you or your organization, and used to build industry benchmarks and similar indicators. See the Privacy Policy for details.
Frequently asked questions
Questions we often hear from companies evaluating CISOaaS, with answers.
Can we use it without a dedicated CISO or security specialists?
Yes. Across every product plan, AI drives assessment, analysis, and report generation on its own, with results delivered without added staff effort. If you need a security consultant's sign-off or ongoing support as an external CISO, you can add it as an add-on (Expert Review = Act and above, Dedicated CISO Support = Govern and above). It also works for teams where IT handles security as a side responsibility.
Can we brief leadership even without deep security expertise?
Yes. Assessment results are auto-bundled into a PDF for leadership. On Assess this covers the score summary and risk list; the economic analysis chapter and the improvement roadmap chapter are available on Act and above. You can report the state of risk and the basis for investment with quantitative data.
How should we choose a plan?
Choose based on the features and scale you need. Assess lets you reassess anytime and delivers watermark-free PDF reports. Act adds economic analysis, initiative management, and incident response. Govern is built for group governance, with up to 15 parent-child tenants, SSO, and audit log export. Enterprise is designed individually for cross-group and regulatory needs. If you need human sign-off on the first-pass evaluation, quarterly reviews, or ongoing support from a dedicated security consultant as an external CISO, you can add these as add-ons (Expert Review / Dedicated CISO Support).
Is there a cap on AI usage in each plan?
Each plan has a monthly cap on AI usage. As a rough guide, using one standard assessment at CIS Controls IG1 as the unit, the Assess plan corresponds to roughly 4-6 assessments per month, Act to roughly 15-25, and Govern and Enterprise to roughly 40-60. Usage is counted per calendar month (Japan time) and resets on the first day of each month; unused allowance does not carry over. These are estimates only: frameworks with more questions, CIS Controls IG2 / IG3 assessments, and AI features such as ROI estimation, report generation, roadmap generation, and the CISO Advisor draw from the same allowance, so actual counts vary with usage. We show an in-app notice once you reach 80% of the cap, and also notify you by email once you reach 100%. After reaching the cap, contact us about moving to a higher plan or arranging additional capacity.
What can I do during a trial?
We issue trials individually to customers who contact us — no card is required and nothing is charged automatically. You can try the same features as your prospective plan for a set period (14 days as of this writing). During the trial, usage is limited to 1 assessment (cumulative) and up to 3 users, with a cap on AI usage; PDF reports include an evaluation watermark. If you do not move to a paid contract when the trial ends, you have read-only access for 14 days starting the day after the end date, after which sign-in is no longer possible. If you do move to a paid contract, assessment results and reports carry over. See the Specified Commercial Transactions Act notice below for details.
See trial details (Specified Commercial Transactions Act notice)Do security experts check the AI's assessment results?
By default, AI runs from the first-pass assessment to the final results without an expert check. If you want expert verification, the Expert Review add-on (Act plan and above) adds a sign-off step in which our security consultant approves the content before finalization; the score, risk analysis, and report are finalized after that approval.
Can we use it to answer the security checklists our partners send us?
Yes. Based on your approved assessment results, AI automatically extracts the questions from a received Excel checklist and drafts answers with compliance status, confidence, and evidence. A person finalizes the answers (with the Expert Review add-on). Check-sheet response support is available on the Act plan and above.
See Security Checklist Response Support detailsCan we put our internal policies and procedure manuals to work in assessments?
Yes. Bulk-upload policies and procedure manuals (PDF, Word, Excel, PowerPoint) into the Evidence Library, and AI matches them against assessment questions and surfaces them as per-question reference information during AI hearings. Answers and scores are never auto-filled — people answer. The Evidence Library is available on the Act plan and above at no extra cost.
See Evidence Library detailsOn the Expert Review add-on, does 'one review' mean once a month?
It means one first-pass sign-off per assessment, before finalization — not a per-month or per-contract count. The Expert Review add-on also includes review of generated deliverables (return-on-investment estimates, initiatives, report), a quarterly review, and expert verification needed for third-party rating programs. If you run multiple assessments in the same tenant, each one gets a review before finalization.
How are risk and loss numbers computed?
Risk is quantified along the attack chain via our own method ACRA (MITRE ATT&CK-aligned). Expected loss is computed as a probability distribution using the international standard FAIR (Factor Analysis of Information Risk) plus Monte Carlo simulation — telling you 'the 95% prediction range for annual loss' and 'the P95/P99 benchmark (roughly 1-in-20 and 1-in-100-year events)', a more confident basis for investment than a single point estimate. For investment, the Gordon-Loeb model from information security economics gives a recommended ceiling relative to the expected annual loss — a ceiling to reason against, not a guarantee that spending up to it is sufficient. This economic analysis is available on Act and above (not on Assess).
Can we assess multiple frameworks in parallel?
Yes. The six frameworks — CIS Controls v8.1.2 / NIST Cybersecurity Framework (CSF) 2.0 / ISO 27001:2022 / Supply-chain Security Evaluation Scheme (SCS) / OWASP Top 10 for LLM / AI Governance Maturity Assessment — totaling 628 assessment items can be run in parallel within the same tenant. You can also choose a different IG / ★ level for each assessment.
Can we assess security risks specific to AI systems (generative AI / LLM)?
Yes. We cover OWASP Top 10 for LLM Applications 2025 (with MITRE ATLAS attack-tactic tags), so AI-specific risks like prompt injection, sensitive-data leakage, data/model poisoning, and excessive agency are visualized in the same framework as your existing cyber risk analysis (ACRA) and ROI. ROI analysis is available on Act and above. Designed for organizations using, building, or providing internal chatbots, RAG, or AI agents.
Can we assess organizational AI governance (structure, policy, risk management, monitoring) for AI use and development?
Yes — via the AI Governance Maturity Assessment (10 management domains, 68 questions), which we built ourselves by referencing NIST AI RMF 1.0 and ISO/IEC 42001:2023. Where OWASP Top 10 for LLM addresses the technical risks of individual AI systems, this framework visualizes the organizational/policy layer — how the organization governs and manages AI — on a 0–5 maturity scale. Available on all plans. It is not the official standard published by NIST or ISO/IEC, and does not guarantee certification.
What is the Attacker-Perspective Simulation?
When each roadmap phase is assumed complete, our proprietary model — applying ideas from security game theory (Stackelberg Security Games; Tambe et al., 2011) — previews how an attacker's likely focus would shift across areas, with AI-generated commentary. It is not a forecast of actual attack probabilities. Available on the Govern and Enterprise plans. See 'Attacker-Perspective Simulation: methodology' in Help for the full rationale and references (with DOIs).
Can we aggregate group companies' security status?
Yes. The Act plan has no parent-child tenant mechanic and is limited to a single tenant. The Govern plan supports up to 15 group companies as standard, and larger group structures are handled by the Enterprise plan under an individual contract. Admins and viewers of the parent tenant can browse and aggregate scores, risks, and contract status across tenants, with data fully isolated between them.
Where is the data stored?
In the AWS Tokyo region. Data is fully isolated across tenants, and all major operations from sign-in through assessment and report generation are recorded to the audit log (retained for 1 year). Viewing the audit log and tamper detection are available on every plan; exporting to CSV / JSON requires Act and above.
Will the data we enter be used to train the AI?
No. AI (large language models) is used for the AI hearing, risk analysis, and report generation, but data sent through this service is never used to train the AI. Data is stored in the AWS Tokyo region and fully isolated across tenants. See our Privacy Policy for details.
Is the security posture sufficient?
We implement MFA, a strong password policy, browser-side security controls, per-feature rate limiting, audit log retention with tamper detection for all major operations (CSV / JSON export requires Act and above), and error monitoring. Data is fully isolated across tenants and cannot be cross-referenced by design.
Do you support the SCS Evaluation Scheme (METI/IPA)?
Yes. In CISOaaS you can select the SCS Evaluation Scheme's ★3 and ★4 criteria as an assessment framework and use them to visualize your current state and plan improvements against those criteria. The SCS Evaluation Scheme is a voluntary program; participation and applying for evaluation are decisions you make yourself. CISOaaS supports preparation against the criteria and does not guarantee that a ★ rating will be granted.
See SCS Evaluation Scheme readiness detailsWhat are the contract term and termination conditions?
Every plan is governed by an individual contract with us, entered into after you get in touch; it sets the contract term, minimum period, and cancellation conditions. Please contact us for details. If you already hold an Assess monthly subscription paid by card, it continues to renew month to month; you can cancel at any time from the "Manage billing" screen after signing in, and you keep access until the end of the current billing cycle (no prorated refunds).
