Cyber Risk Governance

Turn invisible risk into
decisions you can act on.

An AI-and-expert-led
cyber risk governance platform.

You may not be able to hire a full-time CISO, but you can externalize the function. From current-state assessment to risk visualization, board-level explanation, and continuous improvement — all in one place.

* Consultations, quotes and materials are free. Ask us about a trial when you get in touch.

  1. 1
    Answer

    Just answer the AI's questions on screen.

    Do you take regular backups of your data?

    Daily, automatedSome systems onlyNot yet
  2. 2
    See the numbers

    Risks are scored and converted into expected annual loss.

    Sample
    Risk score
    2.1/ 5.0
    Expected annual loss
    ¥12.47M
    System outage1.6 / 5.0¥3.74M
    Data breach2.0 / 5.0¥3.12M
    Other2.7 / 5.0¥5.61M
  3. 3
    Act in order

    Actions are ranked from the most critical risks by return on security investment.

    1. 1CriticalFix access control−¥3.2M
    2. 2HighStrengthen authentication−¥2.6M
    3. 3MediumHarden email security−¥1.8M
    ROI +125%
We support readiness for the SCS Evaluation Scheme (★3/★4, expected to launch around March 2027)Learn more
Issues

The three walls
every company runs into.

From risk visibility to explaining security without a CISO, and keeping it sustained —challenges shared by listed companies and growth-stage companies alike.

01

Cyber risk cannot be quantified

You can't see where the risk lies or how big it is, so you can't prioritize what to fix first.

Visualizing cyber risk — see how we solve it
02

No dedicated CISO — and no way to explain risk to the board

Hiring a full-time CISO is costly and the talent market is tight, so there's no structure to back risk and investment with numbers to the board.

The external CISO function — see how we solve it
03

Assessment is one-off and doesn't continue

Assessments take effort, end up one-shot, and the improvement cycle never starts.

AI-and-expert assessment flow — see how we solve it
WHAT IS CISOaaS

For companies that don't need a dedicated CISO in-house —
a cyber risk governance platform.

CISOaaS combines AI and human experts to supportyour organization's cyber risk:current-state, visibility, investment decisions, and improvement.

VISUALIZE

Risk visibility

Quantify where and how much risk you carry, all the way down to mitigation priority. Evidence you can hand straight to the board.

OPTIMIZE

Investment optimization

Turn risk into expected annual loss, then compute ROSI per countermeasure. Spell out 'which control, how much' so leadership can decide where the budget goes.

GOVERN

Continuous governance

Run assessment, analysis, and improvement in a loop. Track how risks shift and how response progresses over time — not deploy-and-done.

Operated by Securebase Inc., a cybersecurity services specialist.

See how it works
How it works

AI runs assessment, analysis,
and reporting on its own.

With self-assessment, results come without anyone in the loop.
Expert review is an add-on you can attach when you need explainability to leadership.

AIAI runs this entire track
  1. 01
    ASSESS

    AI hearing

    Assess your security implementation status through a conversation with AI.

    PlansAll plans

  2. 02
    ANALYZE

    Risk analysis

    Quantify attack-chain risk via the four-phase ACRA model.

    PlansAll plans

  3. 03
    OPTIMIZE

    Investment optimization

    Compute optimal investment allocation and ROI with an economic model.

    PlansAct and above (not available on Assess)

  4. 04
    PLAN

    Strategy & roadmap

    Build a short-/mid-/long-term initiative plan toward target maturity.

    PlansInitiative management and the execution view, and AI-driven planning and its PDF export, are all available on Act and above

  5. 05
    REPORT

    Report

    Auto-generate executive reports. Up to here without humans in the loop.

    PlansAssess and above (the economic analysis chapter requires Act and above)

Expert (add-on)06

Expert review

A security consultant validates and signs off on the AI's assessment, underwriting board-level explainability.

PlansWith the Expert Review add-on

Self-assessment runs all of assessment, analysis, and reporting by AI — start to finish, no humans in the loop.
The Expert Review add-on adds a security consultant who signs off as the external CISO before finalization, underwriting board-level explainability.

See the AI hearing experience
After onboarding

After the assessment, the focus shifts to addressing the findings.

Issues surfaced in the first assessment can be managed as risk items with owner, deadline, status, and comments — progress visualized on the dashboard. From the second assessment onward, just confirm the items that changed since last time — no need to start over. Executive reports can be exported in the latest state at any time.

Incident response

Respond via CSIRT, then turn the lessons into risks.

If an incident occurs, record and track it under a predefined CSIRT structure and keep a response timeline. The post-mortem then generates preventive risk items that feed back into the next assessment and improvement cycle.

Outcomes

What you get is outcomes — not features.

With CISOaaS, security shifts from "uncontrolled"
to "controlled, with decisions you can defend."

Sample
Expected annual loss
¥12.47M
After improvement
¥4.18M
Maturity score
2.1
After
3.8/ 5.0

Figures are samples. Actual values are calculated from your assessment results.

Current-state visibility

Don't know what's missing

Framework-aligned, no blind spots

Risk visualization

Risk is a feeling in someone's head

Quantified along the attack chain, with losses as a probability distribution

Clear improvement priorities

No idea where to start

ROI-ranked priorities

Explanation to the board

Can't explain it, can't get budget

Quantitative board narrative, with a sense of the possible loss range attached

Audit readiness

Prepare materials by hand, every time

Assessment history and audit logs ready as evidence at any time

Continuous improvement

One-off assessments that go stale

Improvement cycle progress, visualized over time

Security Assessment

Assess against frameworks — nothing slips through.

Aligned with major frameworks like CIS Controls, NIST CSF, and ISO 27001,maturity scores and risk-level distribution quantify your current state.

  • Overall score & grade:A 0–100 score and an S/A/B/C/D grade show security maturity at a glance.
  • Framework coverage:Visualize attainment per standard — CIS IG1/IG2/IG3, NIST CSF's six functions, and more.
  • Risk-level distribution:Detected risks are tallied by severity — Critical / High / Medium / Low — to clarify priority.
See all supported frameworks
Fig. 01— Security AssessmentSample
ES
Executive Summary
A
72.5
/ 100 SCORE
+5.2
CIS Controls coverage
IG1
91%
IG2
78%
IG3
65%
Risk distribution
2
Critical
5
High
8
Medium
3
Low
NIST CSF coverage
ID
PR
DE
RS
RC
GV
Ransomware coverage
2 phases need work
68%
20/29 in place
Entry
Lateral
Execution
Detection
Mitigation
Recovery
Dashboard

See the whole risk picture at a glance.

Assessment results, once scattered, are consolidated on a single dashboard.Executive reporting and field-level improvement start from the same screen.

  • Risk at a glance:Score, risk distribution, and framework coverage in one view — intuitively see where you're weakest right now.
  • Leadership and the field see the same picture:Jargon-free visuals let leadership, IT, and audit share the same current-state understanding.
  • Investment decisions backed by numbers:Expected loss (FAIR probability distribution), recommended investment, and ROI per countermeasure — everything you need to decide, in one place.
Fig. 02— Risk DashboardSample
リスクサマリーSample
¥1,247万
年間想定損失額
¥418万
改善後の想定損失額
+125%
投資対効果(ROI)
リスク内訳
¥1,247万想定損失
  • システム停止30%
  • 情報漏えい25%
  • マルウェア感染20%
  • 内部不正15%
  • その他10%
優先対応リスク TOP5
  • アクセス制御の不備¥320万
  • 認証管理の遅れ¥260万
  • メールセキュリティ¥180万
  • バックアップ体制¥130万
  • 従業員の意識向上¥97万
改善ロードマップ(例)
今すぐ0–3ヶ月

アクセス制御の見直し

短期3–6ヶ月

認証基盤・メール対策の強化

中期6–12ヶ月

監視体制の高度化

Economics

Decide investment by loss and ROI.

Risk is converted into annual expected loss (a FAIR probability distribution), and return on security investment (ROSI) is calculated per countermeasure — so a limited budget is framed as "which control, how much."

  • Expected loss shown as a probability distribution (prediction range, P95/P99)
  • Countermeasures ranked by return on security investment (ROSI)
  • Recommended investment ceiling — the numbers for the decision, in one place
Fig. 03— ROI AnalysisSample
ROI
ROI Analysis
¥1,247万
年間予想損失額
¥459万
推奨投資上限
+125%
投資対効果
7件
未対応リスク
損失額の確率分布(FAIR)
SAMPLE
95% CI: ¥800万〜¥1,600万最悪 ¥5,000万超
損失内訳
ランサムウェア
¥374万
情報漏洩
¥312万
不正アクセス
¥249万
その他
¥312万
投資優先度 TOP3
対策ROSI
EDR 導入+340%
MFA 全社展開+220%
SIEM 構築+180%
Report

Ready to hand straight to leadership.

Assessment results and economic analysis are auto-bundled into a PDF report usable in executive meetings and the board. The time spent crafting reports goes away.

  • Score summary (coverage per framework)
  • Economic analysis (expected loss, optimal investment, ROI)
  • Investment priority (ROSI ranking per countermeasure)
  • Strategy & roadmap (target maturity, short/mid/long-term initiatives)
  • Risk items and response status
Fig. 04— Report (PDF)Sample
CISOaaS Report
セキュリティ
評価報告書
A72.5

* Illustrative screen. The figures shown are samples — actuals are computed from your usage.

See how these numbers are computed
Why it works

Why does what used to be a one-off security assessment
turn into continuous governance?

Because the AI runs the core of assessment — assessment, analysis, and reporting — on its own.
Unlike legacy models where cost stacks up by the man-month, a monthly flat fee lets you run assessments continuously.

Cost structure
Legacy
Man-months — cost grows linearly
CISOaaS
AI-driven — cost does not grow linearly
Pricing model
Legacy
One-off, custom quote per engagement
CISOaaS
Monthly flat fee, continuous subscription
Standing up the function
Legacy
Hiring a dedicated CISO is hard and slow
CISOaaS
Start the external CISO function immediately
Delivery speed
Legacy
Weeks to months
CISOaaS
Results right after answering
How risk is shown
Legacy
Mostly qualitative (high/medium/low)
CISOaaS
Financially quantified as a probability distribution via FAIR
Attacker-perspective in planning
Legacy
Advice during occasional reviews (timing & granularity depend on the individual)
CISOaaS
Roadmap auto-annotated with how attacker focus shifts (Govern and above)
Continuity of assessment
Legacy
One-off, prone to going stale
CISOaaS
Improvement loop, continuously
Consistency of assessment
Legacy
Depends on the individual consultant; the bar moves when the person changes
CISOaaS
We continuously verify that the same criteria yield the same assessment

Automating doesn't mean compromising on objectivity.

CISOaaS assessments are grounded in our own method ACRA (MITRE ATT&CK-aligned), the FAIR model that expresses loss as a probability distribution, and the Gordon-Loeb model from information security economics.
Less manual effort doesn't mean less objectivity or explainability.

See the methodology

* Cost references for legacy assessments and hiring a dedicated CISO are based on general market rates per our research and do not represent any specific company's pricing. See the pricing section for how each plan is priced.

Pricing

Choose a plan by capability. Add experts when you need them.

From the Assess plan, where AI self-assessment maps your current posture, to the Act and Govern plans that drive remediation and group-wide governance.
Product plans are chosen by capability and scale; expert approval and external CISO support are added as add-ons when needed.
Assess pricing is published. Act and above, and add-ons, are quoted as a fixed monthly fee based on your organization and scope.

ASSESS

Assess

For small and medium businesses

Track improvement with regular reassessment

¥30,000/ month
(¥33,000 incl. tax)
¥300,000 / year (¥330,000 incl. tax, 2 months free)
Contact us for annual billing
ACTRecommended

Act

For mid-sized and pre-IPO companies

Economic analysis and remediation tracking

Contact us

Fixed monthly fee by team size and scope

GOVERN

Govern

For large companies and groups

Group-wide governance

Contact us

Fixed monthly fee by team size and scope

ENTERPRISE

Enterprise

For large groups and regulated industries

Custom design and dedicated support

Contact us

Custom quote by scale and requirements

Add-ons

Add expert support as an add-on

Product plans run without added operational effort on your part. When you need expert sign-off or ongoing support as an external CISO, add it as an add-on.

Add-ons

Expert Review

Can be added to the Act plan and above

  • Review & approval of the first-pass AI evaluation
  • Review of generated deliverables (ROI, initiatives, report)
  • Quarterly review
Add-ons

Dedicated CISO Support

Can be added to the Govern plan and above

  • Everything in Expert Review
  • Ongoing support from a dedicated external CISO
  • Attendance at monthly reviews and management meetings
  • Support for ad hoc consultations
Expert Review / Dedicated CISO Support
Expert Review / Dedicated CISO SupportExpert ReviewDedicated CISO Support
Expert review & sign-off of first-pass assessmentIncludedIncluded
Review of generated deliverables (ROI, initiatives, report)IncludedIncluded
Quarterly reviewIncludedIncluded
Dedicated external CISO engagementNot includedIncluded
Monthly reviews & management meeting attendanceNot includedIncluded
Plans that can add thisAct and aboveGovern and above
Compare

Feature comparison by plan

See exactly what each plan adds — every feature, presence or absence, at a glance. What a checkmark cannot show — the consistency of our assessments, the peer set behind the benchmarks, the expert review behind the numbers — we walk you through individually.

  • IncludedSecurity dashboard
  • IncludedRisk assessment
  • IncludedAI hearing
  • AnytimeAnytimeAssessment frequency
  • IG1–2IG1–2CIS Controls level
  • ★3–4★3–4SCS rating program level
  • IncludedFramework recommendation
  • IncludedEvidence Library (bulk policy upload & question matching)
  • IncludedPDF report generation

※ Provided under individual contract

Decision basis

Economic analysis estimates risk costs to support security investment decisions (Act plan and above; not available on the Assess plan).

How it's measured
  • All pricing is a flat monthly fee, to make the difference with man-month billing clear.
  • Pricing for Act and above is shared when you contact us, based on your structure and scope. Minimum term and payment terms are shared at contracting.
  • Accounts for every plan are issued after you contact us and we confirm your requirements; we no longer offer online self-registration. Ask us about a trial when you get in touch. See the Specified Commercial Transactions Act notice for payment and cancellation terms.
  • Responses may be statistically aggregated in a form that cannot identify you or your organization, and used to build industry benchmarks and similar indicators. See the Privacy Policy for details.
FAQ

Frequently asked questions

Questions we often hear from companies evaluating CISOaaS, with answers.

Can we use it without a dedicated CISO or security specialists?

Yes. Across every product plan, AI drives assessment, analysis, and report generation on its own, with results delivered without added staff effort. If you need a security consultant's sign-off or ongoing support as an external CISO, you can add it as an add-on (Expert Review = Act and above, Dedicated CISO Support = Govern and above). It also works for teams where IT handles security as a side responsibility.

Can we brief leadership even without deep security expertise?

Yes. Assessment results are auto-bundled into a PDF for leadership. On Assess this covers the score summary and risk list; the economic analysis chapter and the improvement roadmap chapter are available on Act and above. You can report the state of risk and the basis for investment with quantitative data.

How should we choose a plan?

Choose based on the features and scale you need. Assess lets you reassess anytime and delivers watermark-free PDF reports. Act adds economic analysis, initiative management, and incident response. Govern is built for group governance, with up to 15 parent-child tenants, SSO, and audit log export. Enterprise is designed individually for cross-group and regulatory needs. If you need human sign-off on the first-pass evaluation, quarterly reviews, or ongoing support from a dedicated security consultant as an external CISO, you can add these as add-ons (Expert Review / Dedicated CISO Support).

Is there a cap on AI usage in each plan?

Each plan has a monthly cap on AI usage. As a rough guide, using one standard assessment at CIS Controls IG1 as the unit, the Assess plan corresponds to roughly 4-6 assessments per month, Act to roughly 15-25, and Govern and Enterprise to roughly 40-60. Usage is counted per calendar month (Japan time) and resets on the first day of each month; unused allowance does not carry over. These are estimates only: frameworks with more questions, CIS Controls IG2 / IG3 assessments, and AI features such as ROI estimation, report generation, roadmap generation, and the CISO Advisor draw from the same allowance, so actual counts vary with usage. We show an in-app notice once you reach 80% of the cap, and also notify you by email once you reach 100%. After reaching the cap, contact us about moving to a higher plan or arranging additional capacity.

What can I do during a trial?

We issue trials individually to customers who contact us — no card is required and nothing is charged automatically. You can try the same features as your prospective plan for a set period (14 days as of this writing). During the trial, usage is limited to 1 assessment (cumulative) and up to 3 users, with a cap on AI usage; PDF reports include an evaluation watermark. If you do not move to a paid contract when the trial ends, you have read-only access for 14 days starting the day after the end date, after which sign-in is no longer possible. If you do move to a paid contract, assessment results and reports carry over. See the Specified Commercial Transactions Act notice below for details.

See trial details (Specified Commercial Transactions Act notice)

Do security experts check the AI's assessment results?

By default, AI runs from the first-pass assessment to the final results without an expert check. If you want expert verification, the Expert Review add-on (Act plan and above) adds a sign-off step in which our security consultant approves the content before finalization; the score, risk analysis, and report are finalized after that approval.

Can we use it to answer the security checklists our partners send us?

Yes. Based on your approved assessment results, AI automatically extracts the questions from a received Excel checklist and drafts answers with compliance status, confidence, and evidence. A person finalizes the answers (with the Expert Review add-on). Check-sheet response support is available on the Act plan and above.

See Security Checklist Response Support details

Can we put our internal policies and procedure manuals to work in assessments?

Yes. Bulk-upload policies and procedure manuals (PDF, Word, Excel, PowerPoint) into the Evidence Library, and AI matches them against assessment questions and surfaces them as per-question reference information during AI hearings. Answers and scores are never auto-filled — people answer. The Evidence Library is available on the Act plan and above at no extra cost.

See Evidence Library details

On the Expert Review add-on, does 'one review' mean once a month?

It means one first-pass sign-off per assessment, before finalization — not a per-month or per-contract count. The Expert Review add-on also includes review of generated deliverables (return-on-investment estimates, initiatives, report), a quarterly review, and expert verification needed for third-party rating programs. If you run multiple assessments in the same tenant, each one gets a review before finalization.

How are risk and loss numbers computed?

Risk is quantified along the attack chain via our own method ACRA (MITRE ATT&CK-aligned). Expected loss is computed as a probability distribution using the international standard FAIR (Factor Analysis of Information Risk) plus Monte Carlo simulation — telling you 'the 95% prediction range for annual loss' and 'the P95/P99 benchmark (roughly 1-in-20 and 1-in-100-year events)', a more confident basis for investment than a single point estimate. For investment, the Gordon-Loeb model from information security economics gives a recommended ceiling relative to the expected annual loss — a ceiling to reason against, not a guarantee that spending up to it is sufficient. This economic analysis is available on Act and above (not on Assess).

Can we assess multiple frameworks in parallel?

Yes. The six frameworks — CIS Controls v8.1.2 / NIST Cybersecurity Framework (CSF) 2.0 / ISO 27001:2022 / Supply-chain Security Evaluation Scheme (SCS) / OWASP Top 10 for LLM / AI Governance Maturity Assessment — totaling 628 assessment items can be run in parallel within the same tenant. You can also choose a different IG / ★ level for each assessment.

Can we assess security risks specific to AI systems (generative AI / LLM)?

Yes. We cover OWASP Top 10 for LLM Applications 2025 (with MITRE ATLAS attack-tactic tags), so AI-specific risks like prompt injection, sensitive-data leakage, data/model poisoning, and excessive agency are visualized in the same framework as your existing cyber risk analysis (ACRA) and ROI. ROI analysis is available on Act and above. Designed for organizations using, building, or providing internal chatbots, RAG, or AI agents.

Can we assess organizational AI governance (structure, policy, risk management, monitoring) for AI use and development?

Yes — via the AI Governance Maturity Assessment (10 management domains, 68 questions), which we built ourselves by referencing NIST AI RMF 1.0 and ISO/IEC 42001:2023. Where OWASP Top 10 for LLM addresses the technical risks of individual AI systems, this framework visualizes the organizational/policy layer — how the organization governs and manages AI — on a 0–5 maturity scale. Available on all plans. It is not the official standard published by NIST or ISO/IEC, and does not guarantee certification.

What is the Attacker-Perspective Simulation?

When each roadmap phase is assumed complete, our proprietary model — applying ideas from security game theory (Stackelberg Security Games; Tambe et al., 2011) — previews how an attacker's likely focus would shift across areas, with AI-generated commentary. It is not a forecast of actual attack probabilities. Available on the Govern and Enterprise plans. See 'Attacker-Perspective Simulation: methodology' in Help for the full rationale and references (with DOIs).

Can we aggregate group companies' security status?

Yes. The Act plan has no parent-child tenant mechanic and is limited to a single tenant. The Govern plan supports up to 15 group companies as standard, and larger group structures are handled by the Enterprise plan under an individual contract. Admins and viewers of the parent tenant can browse and aggregate scores, risks, and contract status across tenants, with data fully isolated between them.

Where is the data stored?

In the AWS Tokyo region. Data is fully isolated across tenants, and all major operations from sign-in through assessment and report generation are recorded to the audit log (retained for 1 year). Viewing the audit log and tamper detection are available on every plan; exporting to CSV / JSON requires Act and above.

Will the data we enter be used to train the AI?

No. AI (large language models) is used for the AI hearing, risk analysis, and report generation, but data sent through this service is never used to train the AI. Data is stored in the AWS Tokyo region and fully isolated across tenants. See our Privacy Policy for details.

Is the security posture sufficient?

We implement MFA, a strong password policy, browser-side security controls, per-feature rate limiting, audit log retention with tamper detection for all major operations (CSV / JSON export requires Act and above), and error monitoring. Data is fully isolated across tenants and cannot be cross-referenced by design.

Do you support the SCS Evaluation Scheme (METI/IPA)?

Yes. In CISOaaS you can select the SCS Evaluation Scheme's ★3 and ★4 criteria as an assessment framework and use them to visualize your current state and plan improvements against those criteria. The SCS Evaluation Scheme is a voluntary program; participation and applying for evaluation are decisions you make yourself. CISOaaS supports preparation against the criteria and does not guarantee that a ★ rating will be granted.

See SCS Evaluation Scheme readiness details

What are the contract term and termination conditions?

Every plan is governed by an individual contract with us, entered into after you get in touch; it sets the contract term, minimum period, and cancellation conditions. Please contact us for details. If you already hold an Assess monthly subscription paid by card, it continues to renew month to month; you can cancel at any time from the "Manage billing" screen after signing in, and you keep access until the end of the current billing cycle (no prorated refunds).