仕組み

導入後、何が起きるのか。

このページで分かること
  • AIヒアリングで評価が進む様子(ツール連携は不要)
  • AIが自走し、専門家レビューが品質を担保する流れ
  • 分析を短期・中期・長期の実行ロードマップに落とす過程
How it works

AI runs assessment, analysis,
and reporting on its own.

With self-assessment, results come without anyone in the loop.
Expert review is a value-add for higher plans that need explainability to leadership.

AIAI runs this entire track
  1. 01
    ASSESS

    AI hearing

    Assess your security implementation status through a conversation with AI.

  2. 02
    ANALYZE

    Risk analysis

    Quantify attack-chain risk via the four-phase ACRA model.

  3. 03
    OPTIMIZE

    Investment optimization

    Compute optimal investment allocation and ROI with an economic model.

  4. 04
    PLAN

    Strategy & roadmap

    Build a short-/mid-/long-term initiative plan toward target maturity.

  5. 05
    REPORT

    Report

    Auto-generate executive reports. Up to here without humans in the loop.

Expert (higher plans)06

Expert review

A security consultant validates and signs off on the AI's assessment, underwriting board-level explainability.

Self-assessment runs all of assessment, analysis, and reporting by AI — start to finish, no humans in the loop.
Expert-review-and-above plans add a security consultant who signs off as the external CISO before finalization, underwriting board-level explainability.

See the AI hearing experience
After onboarding

After the assessment, the focus shifts to addressing the findings.

Issues surfaced in the first assessment can be managed as risk items with owner, deadline, status, and comments — progress visualized on the dashboard. From the second assessment onward, just confirm the items that changed since last time — no need to start over. Executive reports can be exported in the latest state at any time.

Incident response

Respond via CSIRT, then turn the lessons into risks.

If an incident occurs, record and track it under a predefined CSIRT structure and keep a response timeline. The post-mortem then generates preventive risk items that feed back into the next assessment and improvement cycle.

AI Hearing

Only answer the items that apply to you —
here's why you don't need to answer everything.

You don't need to answer every item one by one.
The AI asks only what matters, in a conversation, and breaks down the jargon.
No tool integrations to set up.

IG1 hearing progress12 / 56 items done (21%)
C11Data recovery

Official definition (standard text)

Do you regularly back up critical data and maintain a state where it can be recovered when needed?

If data were lost to ransomware or a server failure, do you regularly back it up so it can be restored? And do you keep a copy somewhere separate from production (cloud or a different site)?

Concrete measures (select all that apply)

Critical data is auto-backed-up every day
Backups are also kept in a separate location (cloud / off-site)
We regularly test that we can actually restore
Backups themselves are protected with access controls
We auto-back-up to the cloud every day. But we've never actually tried restoring.
Got it. You're covered on backups and off-site copies. Since the recovery test (verifying you can actually restore) hasn't been done, I'll record this item as 'partially implemented.' Verifying you can reliably restore in an incident is your next improvement.
Got it. How often should we run the recovery test?
A quarterly test against a subset of data is already useful. I'll save it as an improvement note for next review.
I don't knowNot applicable

* Illustrative screen. Actual hearing content depends on the framework you use.

  • We don't ask everything

    Questions are narrowed to items relevant to the level you chose.

  • Only what's changed

    From the second assessment onward, we focus on items that changed since last time.

  • Answer once, reuse

    Answers from one framework carry over — we don't ask the same thing twice across frameworks.

  • Click rather than type

    Most answers are clicks from a list. Attach internal documents and the AI reads and reflects them.

No integration

No tool integration required.

No API setup to connect cloud platforms (AWS, etc.) or XDR/SIEM. Just answer the AI in conversation, and your current state is assessed. Start right away, with no IT overhead.

In the conversation the AI digs deeper, confirming operational frequency and coverage. Attach internal documents and the AI reads them as evidence and reflects them in the assessment.

On expert-review-and-above plans, a security consultant additionally validates the assessment before finalization to underwrite accuracy.

Your data

Your input is not used to train the AI.

AI is used to power the AI hearing and risk analysis, but your input is never used to train the AI.

See our Privacy Policy for details.

Who uses it

You don't have to be a security expert.

Solo IT / IT-and-everything-else staffHead of corporate / GA (no dedicated security)Corporate strategy / IPO preparationParent-company IT / group IT leadSubsidiary IT and administrationDX / generative-AI initiative leadsInternal audit / internal controls

Even without knowing the security jargon, you can move the assessment forward just by answering the AI.

Strategy & Roadmap

Turn analysis into a plan you can execute.

From assessment findings and ROI investment priorities,
the AI proposes a short-/mid-/long-term initiative roadmap toward your target maturity.

* Manual initiative management and the execution view (track and manage state by severity × ROSI) are included in all plans.
AI-driven strategy proposal and PDF export are in expert-review-and-above plans.

Plan backed out from a goal

Set a target maturity (0–5) and break the gap from current state into short-, mid-, and long-term initiatives.

AI proposes, you finalize

The AI proposes the strategy and roadmap in narrative form. You finalize it as your official security strategy.

Consistent with ROI, included in the report

Numbers and ROSI come straight from the ROI analysis. Once finalized, it's exported as a chapter in the executive PDF report.

Product imageSample
Target maturity gap
Lv2
Current
Lv024 months to targetLv5
Lv4
Target
Short term0–6 months
Deploy EDR / XDRROSI +340%
Roll out MFA company-wideROSI +220%
Stand up incident response capabilities
Mid term6–12 months
Build SIEM / log monitoringROSI +180%
Phased rollout of Zero Trust (ZTNA)
Embed company-wide security training & drills
Long term12+ months
Strengthen supply-chain risk management
Roll out governance group-wide
Sustain continuous maturity assessment and improvement

* Illustrative screen. Initiatives and figures are samples — actuals come from your assessment and ROI analysis.

Before the assessment

Load your policies before the hearing.

Put your policies and procedure manuals into the Evidence Library, and the AI conducts the hearing with the related documents in view. Related documents appear for each question, so you stop digging out the same policy every time (every plan, no extra cost).

See Evidence Library details
Where your results go next

An assessment isn't over when you finish answering.

Your approved assessment results can be reused as draft answers to the security checklists your partners send you. AI extracts the questions from a received Excel file and drafts answers matched against your results — a person finalizes them (Expert Review plan and above).

See Security Checklist Response Support details

自社での進め方を、具体的に相談する。

想定担当者・期間・体制まで、貴社の状況に合わせてご案内します。

お問い合わせ