Know where the cyber decision will stall before the exposure outruns you.
A 40-criterion assessment of the friction between recognition, consequence, authority, evidence, funding, execution, notification and reconsideration.
Know where a consequential cyber decision will stall before the exposure outruns you.
The Index still measures decision friction. The update recognises that AI can compress the clock in new places: machine-generated signals, human/AI authority boundaries, supplier/model changes, funding decisions and the trigger to reopen a previously accepted position.
How long before the signal is treated as material?
Tests signal quality, materiality threshold, autonomous/agent alerts, ownership and first escalation.
How long before technical exposure becomes business consequence?
Tests service impact, customer/regulatory consequence, scenario framing, uncertainty and decision ask.
How long before the issue reaches someone who can decide?
Tests delegated authority, human/AI decision boundary, stop rights, escalation and conflict resolution.
How long before leaders have enough evidence to choose?
Tests evidence availability, supplier proof, technical validation, assumptions and evidence confidence.
How long before the choice receives resources?
Tests investment authority, emergency funding, cost-of-delay logic, procurement and exception routes.
How long before the decision changes the operating position?
Tests handoffs, control implementation, supplier action, rollback/fallback and accountable completion.
How long before external notification decisions are made?
Tests materiality, regulatory/customer routes, legal coordination, evidence preservation and clock ownership.
How long before changed conditions force reconsideration?
Tests provider/model change, drift, incidents, new intelligence, residual exposure and review triggers.
Are our cyber decisions getting faster at the same rate that AI is accelerating the threat, the change and the number of actors capable of taking action?
Measure the decision path, not just the incident process.
Use the Index when security can see the exposure but leadership action still depends on translation, authority, evidence, funding or a governance route that may be slower than the threat.