The Institute establishes the first continuous, real-time standard for quantifying supply chain risk. We operationalize data from the SBoM to the Boardroom.
Global frameworks have shifted. Point-in-time assessments are no longer sufficient. The law now requires ongoing visibility.
Requires contractors to "Monitor security controls on an ongoing basis to ensure continued effectiveness."
Mandates "measures to manage the risks concerning the relationships between each entity and its direct suppliers."
Introduces the "Continuous ATO" (Authority to Operate), requiring real-time dashboard visibility.
Financial entities must "manage ICT third-party risk as an integral component... and regularly review strategy."
We don't just scan IP addresses. The Institute ingests the Bill of Materials (SBoM/HBoM) and internal compliance data to create a normalized, quantified risk score.
Leveraging IEEE/UL 2933 for risk quantification and the Secure Controls Framework (SCF) for normalization.
We enable dynamic risk pricing for cyber insurance and contract liability.
Built by the architects of CMMC, SBOM, and the Secure Controls Framework.
Executive Director
Co-Author of CMMC v1. Compliance & Risk veteran. Faculty at IANS. Former organizer of BSides Delaware.
Former CSO, Oracle
Ret. after 40 years securing Oracle's global infrastructure. A legend in software assurance.
"Father of SBOM"
Formerly CISA/NTIA. Led the global charge for Software Bill of Materials transparency.
Founder, SCF
Creator of the Secure Controls Framework (SCF), the gold standard for control normalization.
CISO, Indiana Univ. Health
Co-Vice Chair of IEEE/UL 2933. Expert in Clinical IoT security.
CEO, Cyturus
30+ years navigating complex regulatory landscapes and supply chain risk.
Senior Analyst, LLNL
SANS Instructor and Senior Cyber Analyst at Lawrence Livermore National Labs.
Researcher, Eclypsium
Founder of Security Weekly. Expert in firmware security and supply chain vulnerabilities.
UN Transparency Protocol
Leading Digital Product Passports (DPP) and sustainability traceability for the UN.