Back to Blog

What changes for a 35-person company when risk posture updates hourly

A two-person security function at a Series B SaaS company. Until this year, board risk reporting was a spreadsheet the lead updated the weekend before the meeting. Now the Risk Posture Index moves overnight, the team responds in hours, and the board meeting takes 20 minutes to prep. The operating model, in detail.

Quick Answer

A two-person security function at a Series B SaaS company. Until this year, board risk reporting was a spreadsheet the lead updated the weekend before the meeting. Now the Risk Posture Index moves overnight, the team responds in hours, and the board meeting takes 20 minutes to prep. The operating model, in detail.

The customer in this example is a 35-person B2B SaaS company in their Series B year. The security team is one person, with a half-time engineering manager who handles compliance. The CTO owns risk in the CFO’s eye. The customer carries SOC 2 plus a state privacy framework. They support enterprise sales with security questionnaires. They have a board meeting once a quarter.

Until this year, board risk reporting at this company looked like every other Series B board pack: a slide with red/amber/ green indicators rolled up from a spreadsheet the security lead updated the weekend before the board meeting. The indicators were all backward-looking. The thresholds were all guesses. The board accepted the slide because they did not have a better option to ask for.

Then Continuous Indicators turned on inside their vCISO Lite Reporting view, and the operating model of the program changed.

What the working day looks like now

8:30 AM. The security lead opens the dashboard. The Risk Posture Index has moved overnight — from 64 to 58. The trend pill reads “attack surface accelerating.”

The lead drills in. The behavioral indicator on AWS attack surface is flagged: 18 internet-exposed resources, up from 4 six days ago. The accelerating trend started 36 hours ago. Two of the exposed resources match exploit campaigns currently active in the threat-intel feed.

At 8:45 AM the lead sends a Slack message to the engineering manager: here is the indicator, here are the two specific resources matching active campaigns, here is the action. Containment is in progress by 9:30 AM. Three of the eighteen resources are closed. The indicator updates by 9:45 AM. The Risk Posture Index ticks back up to 61.

The feedback loop that did not exist before

Containment used to be its own separate workstream that hit the board report a quarter later, as “incidents closed.” Now the team sees their containment work move the Risk Posture Index in real time, which produces a tighter feedback loop and a different psychology around the work. The same engineer who used to feel like they were closing tickets now feels like they are moving a number that the board sees.

What the board meeting looks like now

The board pack still has a security slide. It is structurally different.

Element
Before Continuous Indicators
After Continuous Indicators
Headline metric
Coverage % (e.g., 87% of controls implemented)
Risk Posture Index + trend arrow (58, ↓ from 76 over 2 quarters)
Color of the slide
Mostly green — the lagging metrics look fine
Honest. Mixed. The slide reflects reality, not the desired narrative
Forward-looking content
None directly. Roadmap commitments serve as proxy
The Risk Posture Index trend is the forward-looking content
What the board asks the CISO
"Are we compliant?" "Did we have any incidents?"
"Where is the index heading?" "What is the largest concentration point?"
How long the slide takes to prepare
Four hours, the weekend before the board meeting
Twenty minutes — the slide is generated from the current dashboard state
Drift from the actual program state
Two to six weeks (depending on when the spreadsheet was last updated)
Minutes — the indicators were derived live the morning of the meeting

What the security lead spends time on now

The biggest change at this team size is what falls off the weekly schedule, not what gets added.

Off the schedule: the quarterly spreadsheet update marathon. The annual KRI-review committee meeting (there is no committee; the indicators update themselves). The recurring “refresh our threshold thinking” calendar item (the thresholds calibrate against outcomes; the team accepts the recommendations or overrides them with a documented reason).

On the schedule: a 20-minute spot-check every morning of the top three Risk Posture Index movers from overnight. A weekly drift-detection review with the engineering manager (looking at the trend, not at individual indicators). Quarterly conversations with the CFO about whether the appetite thresholds — the dollar limits on conditional exposure before the system escalates — still match the company’s risk tolerance as the business grows.

Net effect: the security lead spends meaningfully less time on the meta-work of running the program (defining indicators, adjusting thresholds, preparing reports) and meaningfully more time on responding to what the program is actually surfacing. That is the work that should have been the job all along; the meta-work was overhead the previous toolchain forced into existence.

The headcount conversation, plainly

The standard pitch for this kind of capability claims it eliminates the need for headcount. That is not the right framing at a 35-person company. The security lead does not have anyone to eliminate; they have themselves. The right framing is that the lead now has the time and the data to act like the company has a full risk team, without actually having one. The board sees the difference in the board pack. The CFO sees the difference in the questionnaire-response speed. The lead sees the difference in their own working hours.

What the CFO and the board now ask differently

Three new conversations have appeared at this customer’s board meetings that did not happen before:

Insurance renewal math. The Risk Posture Index trend has become the headline number the customer takes into the cyber insurance renewal conversation. The carrier’s underwriter asks for trend, not snapshot. Having a trend is the difference between being able to renegotiate the policy downward versus accepting whatever the carrier offers.

Vendor concentration triage. The structural indicator on Okta concentration surfaces every board meeting now. The board has started asking the CTO when the backup IDP will be in place. It used to be a roadmap item that drifted; it is now a board-asked question, which moves the timeline.

Conditional exposure during active incidents. When a third-party vendor disclosure hits the news, the CFO now opens the dashboard before forwarding the article to the CTO, because the conditional indicator will already be computing the customer’s exposure to that specific incident in real time. The CFO has stopped sending the “are we affected by this?” email. The answer is on the dashboard before the question forms.

The honest limitations at this team size

Three things this kind of indicator framework does not solve for a 35-person company:

It does not eliminate the security lead role. It changes what the lead does. The lead still has to interpret the indicators, prioritize the responses, and make the calls that the system flags but does not decide.

It does not eliminate the need for incident response. When a vendor breach actually hits and the conditional indicator surfaces a real exposure, the response is still humans making decisions at human speed. The indicator gives the team the exposure number and the reasoning trail; the response decides what to do.

It does not auto-fix the underlying issues the indicators surface. An indicator showing accelerating attack-surface drift does not close the exposed buckets. The engineering team still has to do the closing. The system surfaces what to close, in priority order, with the dollar impact attached — which is most of the operational lift, but not all of it.

The next article in this series gets specific about the underlying calibration discipline that makes the indicators actually predictive over time — the Brier scoring, the prediction tracking, the automatic threshold recommendations. Without that discipline, this whole approach is just another risk dashboard with prettier graphs.

Where this matters next

Share this article:

Ready to build your security program?

See how easy it can be.