The customer in this example is a 35-person B2B SaaS company in their Series B year. The security team is one person, with a half-time engineering manager who handles compliance. The CTO owns risk in the CFO’s eye. The customer carries SOC 2 plus a state privacy framework. They support enterprise sales with security questionnaires. They have a board meeting once a quarter.
Until this year, board risk reporting at this company looked like every other Series B board pack: a slide with red/amber/ green indicators rolled up from a spreadsheet the security lead updated the weekend before the board meeting. The indicators were all backward-looking. The thresholds were all guesses. The board accepted the slide because they did not have a better option to ask for.
Then Continuous Indicators turned on inside their vCISO Lite Reporting view, and the operating model of the program changed.
What the working day looks like now
8:30 AM. The security lead opens the dashboard. The Risk Posture Index has moved overnight — from 64 to 58. The trend pill reads “attack surface accelerating.”
The lead drills in. The behavioral indicator on AWS attack surface is flagged: 18 internet-exposed resources, up from 4 six days ago. The accelerating trend started 36 hours ago. Two of the exposed resources match exploit campaigns currently active in the threat-intel feed.
At 8:45 AM the lead sends a Slack message to the engineering manager: here is the indicator, here are the two specific resources matching active campaigns, here is the action. Containment is in progress by 9:30 AM. Three of the eighteen resources are closed. The indicator updates by 9:45 AM. The Risk Posture Index ticks back up to 61.
Containment used to be its own separate workstream that hit the board report a quarter later, as “incidents closed.” Now the team sees their containment work move the Risk Posture Index in real time, which produces a tighter feedback loop and a different psychology around the work. The same engineer who used to feel like they were closing tickets now feels like they are moving a number that the board sees.
What the board meeting looks like now
The board pack still has a security slide. It is structurally different.
What the security lead spends time on now
The biggest change at this team size is what falls off the weekly schedule, not what gets added.
Off the schedule: the quarterly spreadsheet update marathon. The annual KRI-review committee meeting (there is no committee; the indicators update themselves). The recurring “refresh our threshold thinking” calendar item (the thresholds calibrate against outcomes; the team accepts the recommendations or overrides them with a documented reason).
On the schedule: a 20-minute spot-check every morning of the top three Risk Posture Index movers from overnight. A weekly drift-detection review with the engineering manager (looking at the trend, not at individual indicators). Quarterly conversations with the CFO about whether the appetite thresholds — the dollar limits on conditional exposure before the system escalates — still match the company’s risk tolerance as the business grows.
Net effect: the security lead spends meaningfully less time on the meta-work of running the program (defining indicators, adjusting thresholds, preparing reports) and meaningfully more time on responding to what the program is actually surfacing. That is the work that should have been the job all along; the meta-work was overhead the previous toolchain forced into existence.
The standard pitch for this kind of capability claims it eliminates the need for headcount. That is not the right framing at a 35-person company. The security lead does not have anyone to eliminate; they have themselves. The right framing is that the lead now has the time and the data to act like the company has a full risk team, without actually having one. The board sees the difference in the board pack. The CFO sees the difference in the questionnaire-response speed. The lead sees the difference in their own working hours.
What the CFO and the board now ask differently
Three new conversations have appeared at this customer’s board meetings that did not happen before:
Insurance renewal math. The Risk Posture Index trend has become the headline number the customer takes into the cyber insurance renewal conversation. The carrier’s underwriter asks for trend, not snapshot. Having a trend is the difference between being able to renegotiate the policy downward versus accepting whatever the carrier offers.
Vendor concentration triage. The structural indicator on Okta concentration surfaces every board meeting now. The board has started asking the CTO when the backup IDP will be in place. It used to be a roadmap item that drifted; it is now a board-asked question, which moves the timeline.
Conditional exposure during active incidents. When a third-party vendor disclosure hits the news, the CFO now opens the dashboard before forwarding the article to the CTO, because the conditional indicator will already be computing the customer’s exposure to that specific incident in real time. The CFO has stopped sending the “are we affected by this?” email. The answer is on the dashboard before the question forms.
The honest limitations at this team size
Three things this kind of indicator framework does not solve for a 35-person company:
It does not eliminate the security lead role. It changes what the lead does. The lead still has to interpret the indicators, prioritize the responses, and make the calls that the system flags but does not decide.
It does not eliminate the need for incident response. When a vendor breach actually hits and the conditional indicator surfaces a real exposure, the response is still humans making decisions at human speed. The indicator gives the team the exposure number and the reasoning trail; the response decides what to do.
It does not auto-fix the underlying issues the indicators surface. An indicator showing accelerating attack-surface drift does not close the exposed buckets. The engineering team still has to do the closing. The system surfaces what to close, in priority order, with the dollar impact attached — which is most of the operational lift, but not all of it.
The next article in this series gets specific about the underlying calibration discipline that makes the indicators actually predictive over time — the Brier scoring, the prediction tracking, the automatic threshold recommendations. Without that discipline, this whole approach is just another risk dashboard with prettier graphs.
