Open any security assessment from any vendor and look at the first page. The headline number is almost always a posture score, a maturity rating, or a compliance percentage. Some color-coded gauge that goes from red to green.
Now ask: what does that number actually mean to a CISO trying to get budget approved?
The honest answer is, not much. A 67/100 posture score doesn't translate to anything a CFO understands. A "Tier 2" maturity rating doesn't justify a purchase order. A compliance percentage doesn't move a board.
What moves a board, what justifies a purchase order, and what unlocks a budget conversation is a single number: the dollar value of expected loss if the company does nothing.
That number is buried or absent in almost every commercial security report. We made it the headline. This post is about why.
The standard report assumes you've already decided to act
Every security tool I've used in the last decade is built on a buried assumption: that the customer has already decided to spend money on security. The tool's job is to help them decide what to spend it on.
That assumption is wrong about half the time.
The other half of the time, the customer is having a much more fundamental conversation. The CFO is asking why security spend is going up year over year. The board is comparing security to revenue-generating investments. The CEO is wondering whether the security team's request can be deferred to next year.
In those conversations, "you should buy a SIEM that costs $95,000" is not a useful piece of information. The CISO already knows that. The conversation is happening one level higher: should we be making this kind of investment at all?
The "Do Nothing" scenario is the answer to that question. It's the projected annualized loss if the company makes no changes to its current security posture. It's a dollar figure, not a percentage. It's specific to the company's industry, size, current controls, and threat exposure. And it's the only number that actually matches the CFO's mental model.
How we calculate it
The Do Nothing scenario in CyberTwin is built from three inputs:
Records at risk. Based on the company's industry, sector, and operating model, the engine estimates how many sensitive records are exposed to a successful breach. For a fintech, that's customer payment records and PII. For a healthtech, it's PHI. For a SaaS company, it's customer data and source code. The estimates are conservative; we err on the low side.
Per-record breach cost. Drawn from IBM's Cost of a Data Breach 2025 report as a per-record cost by data class — customer PII around $160 per record, more for PHI, less for names-only — applied through the sublinear law below rather than multiplied flat. Publicly sourced and refreshed when IBM publishes.
Industry-adjusted breach probability. Based on Verizon's Data Breach Investigations Report and similar industry data, the engine estimates the probability of a successful breach within the next 12 months given the company's current security posture. A fintech with full Microsoft + CrowdStrike + Okta + Wiz might have a 4-6% annual breach probability; the same fintech with no EDR and no SIEM might have a 22-28% probability.
The Do Nothing ALE (Annualized Loss Expectancy) is the mean of a seeded Monte-Carlo over these inputs: each iteration draws a breach size and prices it with a sublinear cost law — a breach 10× larger is not 10× the loss, because per-record cost cannot be extrapolated straight past ~113k records (IBM's own caveat) — then multiplies by the adjusted probability. We read the P10/P50/P90 off the resulting distribution rather than multiplying the factors' percentiles.
For a 240-person Saudi fintech with their existing controls, the engine produces something like:
- Expected annualized loss with no changes: $3.8M (P50). Range: $1.6M (P10) to $7.2M (P90).
- With Lean stack: $2.1M. Saves $1.7M/year for $43,000 spend. ROI multiple: 39×.
- With Balanced stack: $720K. Saves $3.1M/year for $128,000 spend. ROI multiple: 24×.
- With Advanced stack: $290K. Saves $3.5M/year for $310,000 spend. ROI multiple: 11×.
That's the headline a CFO understands.
If the Lean stack delivers a 39× ROI multiple and the Advanced stack delivers 11×, the marginal dollar of security spend has dramatically diminishing returns.
Why this is uncomfortable for the security industry
You don't see numbers like this in commercial security reports because they make the value proposition uncomfortably explicit. If the Lean stack delivers a 39× ROI multiple and the Advanced stack delivers 11×, then the marginal dollar of security spend has dramatically diminishing returns above a certain point.
That's a true fact. It's also a fact that most security vendors don't want their customers to internalize, because their business model depends on customers buying more.
CyberTwin's recommendation engine is deterministic and our incentive is to help customers make defensible decisions, not to sell them a specific product. So we publish the math.
The Lean tier is genuinely the right answer for some companies. The Balanced tier is the right answer for most. The Advanced tier is the right answer when regulatory exposure or threat profile justifies the marginal spend, and not when it doesn't.
A platform that's selling you tools has to push you toward more tools. A platform that's selling you decisions has to be honest about when fewer tools is the better answer.
The objections, addressed honestly
The most common objection to the Do Nothing model is that the breach probability numbers are squishy. Different sources cite different figures; the variance year over year is significant; and the company's specific threat profile may differ from the industry baseline.
That's all true. It's why we present the number as a P10/P50/P90 range rather than a single value, and why we explicitly mark our peer-benchmark data as estimated until we have enough customer data to ground it in real outcomes.
The objection that the model is squishy is also less damning than it sounds. Every alternative is squishier. "67 out of 100 posture score" is a number with no underlying ground truth. "Tier 2 maturity" is even more abstract. The Do Nothing dollar figure is at least anchored to something measurable: per-record breach costs that are publicly reported and breach probabilities that are publicly studied.
The other common objection is that publishing these numbers gives ammunition to competitors. If a CFO sees that the Lean stack has a 39× ROI multiple, they might decide that's good enough and reject the Balanced proposal.
That's true. It's also fine. The CFO making that decision with full information is a better outcome than the CFO making it with no information. Companies that buy the Lean tier when Balanced is genuinely necessary will eventually pay for that choice, and they'll know the trade they made. Companies that buy Balanced when Lean would have been sufficient will spend more than they needed to, and they'll know that too.
Honest information leads to better decisions, even when the decision is to spend less.
Why this should be the headline
Every security report should lead with the dollar number a CFO can act on. Posture scores, maturity ratings, and compliance percentages are useful supporting context, but they're not the headline.
The headline of a CyberTwin assessment is always the same shape:
Your current setup carries an expected annualized loss of $X. Lean takes you to $Y for $Z spend. Balanced takes you to $A for $B spend. Advanced takes you to $C for $D spend. Here's the math.
That's a number a CISO can walk into a board meeting with. It's a number that justifies a purchase order. It's a number that wins the budget conversation.
The reason most security reports don't lead with it is that the math is uncomfortable for the industry. It makes the value proposition concrete and the diminishing returns visible.
We think that's a feature.