Technical evaluation

vCISO Lite versus Kovrr

Kovrr is a Tel-Aviv-founded cyber-risk-quantification specialist with a published Monte Carlo methodology and insurance-actuarial partnerships (MAPFRE RE, Aon). vCISO Lite runs cyber risk quantification inside a broader vCISO + GRC + services platform from $299/mo — with a productized M&A cyber diligence service, an externally-anchored evidence chain, and risk operations your own AI agents can call.

Prepared
Method
Capability walk against Kovrr’s published product surface (kovrr.com, kovrr.com/cyber-risk-quantification, kovrr.com/ai-risk-quantification, kovrr.com/trust/monte-carlo-cyber-event-simulation) and vCISO Lite’s live platform.
Sources
kovrr.com, kovrr.com/cyber-risk-quantification, kovrr.com/ai-risk-quantification, kovrr.com/trust/monte-carlo-cyber-event-simulation, MAPFRE RE + Aon partnership press releases, vcisolite.com/pricing, vcisolite.com/diligence, vcisolite.com/evidence-graph, vcisolite.com/briefs-and-specs. See §10.
Corrections
Both vendors invited to review. Send corrections to /contact; the “Prepared” date above is bumped on any material update.
On this page · 10 sections

TL;DR

Findings§1

Where Kovrr leads

  • Insurance-actuarial data pedigree. MAPFRE RE reinsurance partnership (2021), Aon partnership (2020) for cyber-risk modeling, Deutsche Rück + MS&AD on the customer roster, Hetul Patel (Chief Actuary Officer, Liberty Mutual Re) on the advisor bench.[4] Loss corpus blends Advisen (Kovrr’s documented cut through Feb 2022), proprietary insurance-claims data, and Hudson Rock infostealer intel. Strongest publicly-visible carrier-actuarial signal in this tranche.
  • 25,000-trial Monte Carlo, methodology published. Trial count is on kovrr.com/trust/monte-carlo-cyber-event-simulation. Output: Average Annual Loss, 1:100 tail exposure at the 99th percentile, Loss Exceedance Curve, ALE.[1] Real transparency signal — vCISO Lite’s trial count is engineered but not publicly published.
  • AI Risk Quantification (AIRQ) as productized SKU. Kovrr shipped a dedicated AI-risk-in-dollars module Oct 2025. AI Interaction Data Fabric (Sep 2026) correlates AI activity across browser, endpoint, agent, cloud, LLM, identity, DLP sources. Kovrr is aggressively pivoting into AI-security while their CRQ category commoditizes.
  • Portfolio Analysis + Decision Simulator. Dedicated modules for scenario-comparison and portfolio-level rollup. vCISO Lite ships portfolio analysis via QCD Pillar 2 but frames it as HHI concentration, not scenario-comparison — distinct primitives.
  • Bespoke Event Catalog — proprietary synthetic-events methodology, distributions calibrated from the three data sources above. vCISO Lite doesn’t publish an equivalent event corpus.
  • DORA + SEC materiality positioning as dedicated marketing surfaces (kovrr.com/cyber-regulations-and-materiality-analysis). Not a distinct DORA dashboard, but purpose-built positioning for the regulatory intersection.

Where vCISO Lite leads

  • Per-control what-if — the FAIR-CAM primitive, shipped. vCISO Lite lets you quantify how a specific control’s frequency reduction and magnitude reduction shift ALE for a specific loss event, re-run through the same 10,000-iteration seed-deterministic Monte Carlo engine. Output: ALE reduction in dollars, Loss Exceedance Curve delta, NPV, payback (10% discount, 3-year). Callable from any MCP-speaking agent through APRI. This is FAIR-CAM’s core mechanic. Kovrr surfaces scenario-level what-if via the Decision Simulator, but per-control quantification is not a distinct primitive.[3]
  • QCD 5-pillar CCOD — productized M&A cyber diligence. 72-hour deliverable, defensible at the IC, methodology codified in Yolonda’s 2026 book Someone Else’s Debt. Attack Surface + Third-Party & Vendor Concentration + Data Sensitivity + Program Maturity + Integration & Post-Close Risk = one dollar figure. Kovrr has no comparable M&A diligence surface.[6]
  • QCD Pillar 2 — portfolio HHI concentration. Tells your CFO, as a dollar figure, how much you’re on the hook for if your most-concentrated vendor exposure turns bad. HHI penalty bands (0 / 0.10 / 0.25) feed the CCOD directly.[5]
  • Evidence Graph — externally-anchored, SDK-licensable. Every CRQ artifact Ed25519-signed and anchored to an external RFC-3161 timestamp authority. A SOC 2 auditor, cyber-insurance carrier, or M&A diligence reviewer can prove the chain wasn’t tampered with, without trusting vCISO Lite. Kovrr’s audit trail is platform-internal.[7]
  • Risk operations callable from your own AI agent stack. APRI at mcp.vcisolite.com exposes per-control what-if, top-risk retrieval, scenario simulation, and Loss Exceedance Curve retrieval to any MCP-speaking client. Kovrr’s AIRQ + AI Data Fabric stay inside the Kovrr UI.[8]
  • Published pricing from $299/mo at /pricing. Kovrr is sales-led with no public floor.[10]
  • Own security posture published. SOC 2 Type II + ISO 27001 posture visible on /about. Kovrr’s /trust page returns HTTP 404.[9]
  • Trustworthy Autonomy. Public beta since 2026-07-07; Level 1 agent governance proven in production 2026-08-17. Published evaluation harness grades the agent by task category before purchase.
  • Founder-direct. [email protected] reaches the founder, not an SDR queue.

Scope & evaluation criteria

Boundaries§2

In scope

Buyer profile
CISOs, CROs, and CFOs comparing dedicated CRQ specialists (Kovrr) against CRQ inside a broader vCISO + GRC + services program (vCISO Lite). Especially useful for buyers who need a defensible dollar-figure CRQ output AND a productized M&A cyber diligence surface, or who want CRQ operations callable from their own Claude / Cursor / agent stack.
Evaluation frame
Ten capability categories the CRQ buyer typically weighs — Monte Carlo engine mechanics, per-control what-if (FAIR-CAM primitive), Loss Exceedance Curve output, insurance-actuarial data pedigree, portfolio-concentration primitive, M&A diligence surface, evidence integrity, MCP callability, own trust posture, published pricing. Not: everything each vendor does.
Comparison basis
Kovrr’s published product surface (kovrr.com/cyber-risk-quantification, kovrr.com/ai-risk-quantification, kovrr.com/trust/monte-carlo-cyber-event-simulation) + press-release history (MAPFRE RE, Aon partnerships). vCISO Lite’s live platform. Not: NDA material, unreleased roadmap, or third-party analyst reports behind paywalls.

Out of scope

Insurance-carrier-side underwriting
Kovrr’s partnerships with MAPFRE RE and Aon are structured around reinsurance underwriting + cyber-risk modeling for insurance clients. If the buyer is an insurance carrier building an underwriting workflow, that’s Kovrr’s home turf. vCISO Lite’s CRQ serves the enterprise / mid-market buyer, not the insurance-carrier-side workflow.
AI Security & Governance suite (Kovrr’s 2025–2026 pivot)
Kovrr’s AI Interaction Data Fabric (Sep 2026), AI Compliance Readiness, and AI Third-Party Risk Management are their newer expansion surface. This page compares CRQ shape, not the crowded AI-security-posture category (Wiz, Prompt Security, Lakera, HiddenLayer).
FAIR Institute badge status
Safe Security holds the FAIR-CAM analyst-cite via Forrester Q2 2025; neither Kovrr nor vCISO Lite currently holds it. vCISO Lite ships the underlying FAIR-CAM mechanic (per-control frequency reduction × magnitude reduction Monte Carlo); the analyst-positioning work is on the roadmap. Kovrr’s FAIR positioning is “FAIR-aligned,” not FAIR-Institute-certified.

Capability coverage

Ten capabilities§3

Amber = Kovrr ships / has it. Teal = vCISO Lite ships it. Split = both. Hover a hex for the mechanism detail.

Capability deep-dives

How each side implements it§4

Five capabilities, one spec-card per side. Framework decomposition lives in §5.

EXTERNAL DATA SOURCESAdvisen loss data~90k events · Kovrr’s cut through Feb ‘22Insurance claimsMAPFRE RE + Aon partnersHudson Rockinfostealer / credential intel+ customer telemetrycalibrateKOVRR SAASBespoke Event Catalogsynthetic events · freq + severity distributionsdraw eventsMonte Carlo engine25,000 trials per quantificationFAIR-aligned (not FAIR-Institute certified)×25kOutputs: AAL · 1:100 tail · LEC · ALEAI Security & Governance (2025+)AIRQ · AI Data Fabric · ComplianceCyber Risk Register · PortfolioScenario Intelligence · Decision SimulatorExecutive / co-branded partner-channel exec reports (out to customer)kovrr.com/trust returns 404
Three external datasets calibrate a synthetic-event catalog, which the Monte Carlo engine iterates 25,000 times per quantification to produce AAL, 1:100 tail exposure, LEC, and ALE.
§4.1

Monte Carlo CRQ engine

Head-to-head on the core mechanic. Kovrr publishes 25,000 trials on their own site; vCISO Lite ships 10,000-iteration seed-deterministic Monte Carlo in production.

Kovrr

25,000 Monte Carlo trials per quantification, methodology published on kovrr.com/trust. Frequency + severity distributions calibrated from Advisen loss data, proprietary insurance-claims corpora, and Hudson Rock infostealer intel.

Inputs
Scenario definition · frequency + severity distribution parameters from Bespoke Event Catalog · organizational context.
Outputs
Average Annual Loss (AAL); 1:100 tail exposure at the 99th percentile; Loss Exceedance Curve; ALE via the AIRQ module.
Evidence
Trial count and methodology published at kovrr.com/trust/monte-carlo-cyber-event-simulation — real transparency signal.
Fails when
Buyer needs per-control what-if quantification (FAIR-CAM primitive) that ties a specific control to a specific loss-event frequency + magnitude reduction. Kovrr's Decision Simulator surfaces scenario-vs-scenario, not per-control impact.
vCISO Lite CRQ engine

10,000-iteration seed-deterministic Monte Carlo. Every simulation is reproducible for audit — identical inputs produce identical outputs.

Inputs
Scenario definition drawn from the risk register; frequency low/high; magnitude low/high; control effectiveness; optional what-if control frequency and magnitude reductions.
Outputs
Baseline and projected ALE with percentile bands, full Loss Exceedance Curve, ALE reduction in dollars and percent, ROI (NPV, payback years, 10% discount, 3-year model).
Evidence
Trial count engineered for sub-30-second per-org runtime across the risk register. Every simulation is Ed25519-signed to the Evidence Graph.
Fails when
Buyer specifically requires FAIR Institute badging or an insurance-carrier-grade actuarial dataset. That's Kovrr's ceded ground (see §4.3); analyst-positioning is on the roadmap.
§4.2

Per-control what-if — the FAIR-CAM primitive

vCISO Lite ships FAIR-CAM's core mechanic in production. Kovrr's what-if is scenario-level, not per-control.

Kovrr

Decision Simulator surfaces scenario-vs-scenario comparisons and portfolio-level what-if. Per-control quantification — how a specific control shifts ALE for a specific loss event — is not surfaced as a distinct primitive.

Inputs
Scenario definitions to compare.
Outputs
Comparative scenario dollar figures + narrative.
Evidence
Kovrr product page describes Decision Simulator as scenario-level; per-control quantification is not surfaced.
Fails when
Buyer needs to answer 'what does IAM at maturity Z do to my ALE?' as a per-control decomposition. That's FAIR-CAM's core question; not Kovrr's shape.
vCISO Lite

Per-control frequency reduction and magnitude reduction re-run the target scenario through the same 10,000-iteration Monte Carlo engine. Callable from any MCP-speaking agent through APRI.

Inputs
Target scenario or risk name; the control's frequency reduction and magnitude reduction (0–1 fractions); optional implementation cost and annual cost for ROI computation.
Outputs
Baseline and projected numbers side-by-side: Expected (ALE), BestCase, Severe, Worst, and full Loss Exceedance Curve. Plus ALE reduction in dollars and percent, and ROI (NPV, payback years, 10% discount, 3-year model).
Evidence
Every invocation Ed25519-signed to the Evidence Graph. This is FAIR-CAM's definitional statement: quantify how a specific control impacts loss event frequency and loss magnitude.
Fails when
Buyer requires the FAIR Institute badge specifically today; the analyst-positioning work is on the roadmap.
§4.3

Insurance-actuarial data pedigree

Kovrr wins. MAPFRE RE + Aon partnerships; Liberty Mutual Re Chief Actuary on the advisor bench.

Kovrr

MAPFRE RE reinsurance partnership (2021) and Aon partnership (2020) for cyber-risk modeling. Hetul Patel (CAO, Liberty Mutual Re) on the advisor bench — the strongest publicly-visible actuarial signal.

Inputs
Advisen historicals (Kovrr's cut through Feb 2022) + proprietary insurance-claims data (specific carriers not publicly named) + Hudson Rock infostealer intel.
Outputs
Frequency + severity distributions calibrated from the above; Monte Carlo trials produce dollarized loss estimates carriers can defend.
Evidence
Named partnerships in press releases (helpnetsecurity + businesswire + theinsurer.com). Customer roster on kovrr.com/about includes reinsurers (Deutsche Rück) and insurance holdcos (MS&AD).
Fails when
Kovrr does not publicly name the specific carriers whose claims data feed the corpus. If the buyer needs audit-grade provenance, push for named sources.
vCISO Lite

Loss estimates are QCD-methodology-grounded against customer-engagement data. Not sourced from licensed insurance-carrier claims corpora.

Inputs
Per-engagement customer data + industry benchmarks published in Someone Else's Debt.
Outputs
CCOD dollar figure defensible at the IC. Not marketed as carrier-actuarial-grade.
Evidence
Someone Else's Debt (Yolonda Smith, 2026) is the codified methodology.
Fails when
Buyer's procurement filter includes 'must source from licensed insurance-carrier claims data.' That's Kovrr's ceded ground and vCISO Lite doesn't compete on that axis today.
§4.4

M&A cyber diligence as productized SKU

Kovrr has no M&A cyber diligence surface. vCISO Lite ships QCD 5-pillar CCOD as a 72-hour productized service.

Kovrr

Enterprise CRQ + AI Security & Governance is Kovrr's platform. M&A cyber diligence as a productized deliverable is not a Kovrr surface.

Inputs
N/A — no diligence product on public surface.
Outputs
N/A.
Evidence
Public product surface has no /diligence, /qcd, or M&A-diligence-branded page.
Fails when
Buyer is deal-team-side (PE, M&A) needing pre-close cyber-diligence deliverable in days, not weeks, defensible at Investment Committee.
vCISO Lite QCD

Quantitative Cyber Diligence — 5-pillar CCOD (Attack Surface, Third-Party Concentration, Data Sensitivity, Program Maturity, Integration) productized at /diligence. 72 hours from kickoff to a deliverable defensible at the Investment Committee.

Inputs
Target company scope + engagement letter · public attack surface data · contracts and vendor list where accessible · framework attestations.
Outputs
Single-figure CCOD (Cyber Cost of Deal) with per-pillar decomposition · defensible narrative for the IC · portable format (ephemeral by design).
Evidence
Codified from Someone Else's Debt (Yolonda Smith, 2026). Published pillar-by-pillar on /diligence.
Fails when
N/A on the diligence axis — Kovrr has no comparable productized diligence surface.
§4.5

CRQ operations callable from your own agent stack

Kovrr's AI runs inside the Kovrr UI. APRI exposes CRQ operations to any MCP-speaking client so your Claude, Cursor, or custom LLM can invoke them directly.

Kovrr

AIRQ and AI Interaction Data Fabric run inside the Kovrr platform UI. External Claude / Cursor / partner agents cannot invoke CRQ operations without dashboard scraping.

Inputs
User interactions inside the Kovrr UI or a user-configured Kovrr integration.
Outputs
Displayed inside the Kovrr platform; exportable to PDF or dashboard embed.
Evidence
Kovrr product surface describes AIRQ and AI Interaction Data Fabric as platform capabilities. Nothing on the public surface describes an external-agent-callable interface.
Fails when
Buyer's team lives in Claude / Cursor / their own LLM and wants CRQ work to happen there. Or a partner (M&A diligence firm, insurance carrier) wants to wire CRQ outputs into their own agent stack. Or an autonomous agent needs to invoke controls-what-if continuously.
vCISO Lite APRI

APRI at mcp.vcisolite.com exposes CRQ operations as callable MCP tools. Any Claude, Cursor, custom LLM, or autonomous loop can invoke per-control what-if, top-risk retrieval, scenario simulation, and Loss Exceedance Curve retrieval directly.

Inputs
Whatever context the invoking agent has — scenario ID, control candidate, risk threshold, workflow step from another MCP server.
Outputs
Same projection, delta, and ROI response the platform returns. Every invocation Ed25519-signed to the Evidence Graph regardless of which agent called it.
Evidence
Three architectural guarantees make composability safe: caller-entitlement scoped (invoking user's entitlements, not a service account), complete tool-call audit trail (Ed25519 on the Evidence Graph), observe-first (writes go through a confirmation gate).
Fails when
Buyer's primary constraint is 'we need CRQ but our agents don't need to invoke it' — Kovrr's inside-the-UI AI is fine for that shape.

Framework & control coverage

Framework depth§5

Kovrr crosswalks against NIST CSF 2.0, DORA, NYDFS 500, SEC cyber disclosure, PCI DSS, NIS2, CIS Controls, ISO 27001, EU AI Act, NIST AI RMF, ISO 42001, MITRE ATLAS from their marketing surface. vCISO Lite ships 250+ SCF-cross-mapped frameworks (1,468 universal controls)— every SCF-mapped control unlocks the frameworks that share it.

Kovrr[6]

NIST CSF 2.0
DORA
NYDFS 500
SEC cyber
PCI DSS
NIS 2
CIS Controls
ISO 27001
EU AI Act
NIST AI RMF
ISO 42001
MITRE ATLAS

vCISO Lite

SOC 2
ISO 27001
HIPAA
PCI DSS
NIST CSF 2.0
CMMC L1
CMMC L2
CMMC L3
800-171r3
NIST 800-53
FedRAMP
NIST RMF
NIST AI RMF
SEC cyber
CIS Controls
GDPR
DORA
NYDFS 500
HITRUST
CJIS
NIS 2
EU AI Act
ISO 42001
ISO 27002
ISO 27701
ISO 22301
SOC 1
SOC 3
CCPA / CPRA
GLBA
StateRAMP
TX-RAMP
CIS Benchmarks
MITRE ATT&CK
NIST 800-63
NIST 800-172
FFIEC CAT
SWIFT CSCF
LGPD
PIPEDA
COPPA
FERPA
CIPA
CSA CCM

Pricing & delivery model

Direct-buy floor vs enterprise implementation§6

Kovrr is sales-led with no dollar figure surfaced without a scoping call (free-trial entry available on some tiers). vCISO Lite starts at $299/mo Starter (5 vendors + 5 vendor questionnaires answered), with additional tiers on /pricing. And vCISO Lite ships productized TPRM services on top of the platform — Kovrr ships the platform only.

Kovrr

Enterprise SaaS

Contact-sales · free-trial entry on some tiers · no public dollar figure[9]

Sold to
Security-team buyers at mid-market to enterprise scale — fintechs, retailers with big vendor tails, security-conscious SaaS
Published tiers
None — contact-sales for pricing
Free-trial entry
“Start Free Trial” / “Get Started Free” on entry tiers
Delivery model
Sales-led · demo-gated · enterprise implementation
Sales cycle
Request-a-demo → scoping call → contract
vCISO Lite

From $299/mo

Direct-buy from Starter · every tier on /pricing

Starter
$299/mo — 5 vendors + 5 vendor questionnaires answered per month. Additional tiers on /pricing.
Platform + services
vCISO Lite ships the platform and productized TPRM services (managed CAIQ / SIG completion, analyst-driven vendor assessments) on /services. Kovrr ships the platform only.
Sales cycle
Direct-buy end-customer · Enterprise: one call, flat MSRP on file · no scoping-call gate to see a price

Integration surface

Native connectors§7

Kovrr lists integrations on the platform surface but does not enumerate a public catalog. vCISO Lite’s full catalog is on /features/integrations.

IntegrationKovrrvCISO Lite
AWSNative
AzureNative
GCPNative
SnowflakeNative
GitHubNative
GitLabNative
Google WorkspaceNative
Microsoft 365Native
OktaNative
JiraNative
SlackNative
ServiceNowNative
MCP (Model Context Protocol)Native
External scanner (attack-surface)Native
Threat-intelligence feedsNative
Integration catalog published?Referenced, not enumeratedFull catalog on /features/integrations

Deployment, data, extensibility

Platform architecture§8
AttributeKovrrvCISO Lite
Service modelSaaS multi-tenant · CRQ specialist · Monte Carlo engine + insurance-actuarial data pipelineSaaS multitenant · end-customer tenancy · Enterprise-tier isolated deployment on request
CRQ engine25,000-trial Monte Carlo · published methodology at kovrr.com/trust/monte-carlo-cyber-event-simulation10,000-iteration seed-deterministic Monte Carlo · reproducible for audit · every simulation Ed25519-signed to the Evidence Graph
Per-control what-if (FAIR-CAM primitive)Scenario-level Decision Simulator · per-control quantification not a distinct primitivePer-control frequency reduction × magnitude reduction re-run through the same engine · ALE reduction in dollars + NPV + LEC delta · callable from any MCP-speaking agent through APRI
Loss dataset provenanceAdvisen (Zywave-licensed · Kovrr’s cut through Feb 2022) + proprietary insurance-claims data (carriers unnamed) + Hudson Rock infostealer intelQCD proprietary methodology (Someone Else’s Debt, 2026) · customer-engagement-grounded, not carrier-actuarial
M&A cyber diligence surfaceNot on public product surfaceQCD 5-pillar CCOD productized at /diligence · 72-hour deliverable · defensible at the IC
Portfolio-concentration primitivePortfolio Analysis + Decision Simulator (scenario-level rollup)QCD Pillar 2 HHI concentration · penalty bands 0 / 0.10 / 0.25 · feeds CCOD dollar figure
Audit-trail modelPlatform-internal store · no external anchor / per-event signing / transparency log disclosedEvidence Graph · per-event Ed25519 signing · RFC 3161 external timestamp anchor · SDK-licensable
Where the AI actually runsInside the Kovrr UI · AIRQ + AI Data Fabric · external agents cannot invokeCallable from any MCP-speaking client via APRI at mcp.vcisolite.com · every invocation Ed25519-signed to Evidence Graph
Insurance-actuarial pedigreeMAPFRE RE + Aon partnerships · Liberty Mutual Re CAO on advisor benchNot competing on this axis
Own compliance posturekovrr.com/trust returns 404 · no visible SOC 2 badge or ISO 27001 certificateSOC 2 Type II · ISO 27001 · posture published on /about

Business-case briefing

For a budget request§9

Personalized briefing

Make the case for vCISO Lite alongside Kovrr

A PDF business case, personalized to your company, that lays out the three options — no CRQ platform, Kovrr, or direct-buy vCISO Lite — with the cost math and honest tradeoffs. Written to be credible with a buyer who's already seen Kovrr's insurance-actuarial pedigree (MAPFRE RE + Aon + Advisen loss corpus) and needs to see what the integrated vCISO + GRC + services + QCD alternative actually delivers on a separate axis — with the FAIR-CAM primitive shipped, MCP-callable, and Ed25519-signed to an externally-anchored evidence chain.

View pricing

Notes & sources

Provenance§10
  1. [1] Kovrr 25,000-trial Monte Carlo methodology from kovrr.com/trust/monte-carlo-cyber-event-simulation (accessed 2026-09-16). vCISO Lite ships a 10,000-iteration seed-deterministic Monte Carlo engine (default trial count; identical inputs produce identical outputs).
  2. [2] Loss Exceedance Curve output for both vendors. Kovrr AAL + 1:100 tail exposure + LEC + ALE from published methodology page. vCISO Lite ships LEC alongside Expected (ALE), BestCase, Severe, and Worst percentile bands on every scenario and every per-control what-if.
  3. [3] Per-control what-if (FAIR-CAM primitive). vCISO Lite ships per-control frequency reduction × magnitude reduction re-run through the same Monte Carlo engine, returning ALE reduction in dollars, NPV, payback, and Loss Exceedance Curve delta. Callable from any MCP-speaking agent through APRI. Analyst-positioning work on the FAIR-CAM alignment is on the roadmap.
  4. [4] Kovrr insurance-actuarial pedigree: MAPFRE RE reinsurance partnership (2021) from mapfrere.com. Aon partnership (2020) from theinsurer.com. Hetul Patel (Chief Actuary Officer, Liberty Mutual Re) advisor from kovrr.com/about.
  5. [5] QCD Pillar 2 (Third-Party & Vendor Concentration) Herfindahl-Hirschman Index concentration penalty at portfolio level, combined with Max Single-Vendor Loss for Expected Annual Cost + P90, codified from Yolonda’s 2026 book Someone Else’s Debt. Kovrr Portfolio Analysis + Decision Simulator (scenario-level) from kovrr.com/cyber-risk-quantification.
  6. [6] QCD 5-pillar CCOD (Cyber Cost of Deal) productized as M&A cyber diligence service from vcisolite.com/diligence. Methodology codified in Yolonda Smith’s 2026 book Someone Else’s Debt. Framework coverage (250+ SCF-cross-mapped frameworks + 1,468 universal controls) verified against live vcisolite.com/features/compliance.
  7. [7] vCISO Lite Evidence Graph (per-event Ed25519 signing shipped 2026-08-16 + RFC-3161 external timestamp anchor + transparency log live in production 2026-08-20; SDK-licensable since 2026-08-15) from vcisolite.com/evidence-graph. Kovrr audit-trail characteristics from kovrr.com (no external anchor / per-event signing / transparency log surfaced).
  8. [8] vCISO Lite APRI (MCP tool graph exposing per-control what-if, top-risk retrieval, scenario simulation, and Loss Exceedance Curve retrieval; live at mcp.vcisolite.com) verified against vcisolite.com/titanium. Kovrr AIRQ + AI Interaction Data Fabric (inside the Kovrr UI; no public MCP endpoint) from kovrr.com/ai-risk-quantification.
  9. [9] Kovrr own trust posture: kovrr.com/trust returns HTTP 404 as of 2026-09-16; no visible SOC 2 badge or ISO 27001 certificate on public pages. vCISO Lite SOC 2 Type II + ISO 27001 posture published on vcisolite.com/about.
  10. [10] Kovrr pricing (sales-led; kovrr.com/pricing-crq directs to demo form, not to prices; Microsoft Azure Marketplace private-offer model) from kovrr.com/pricing-crq. vCISO Lite platform tiers ($299/mo Starter through $8,500/mo Enterprise MSRP) from vcisolite.com/pricing.
  11. All product capability claims for both platforms are current as of the “Prepared” date at the top of this page. If Kovrr publishes a per-control what-if primitive or an externally-anchored evidence chain since publication, corrections at /contact.
  12. This page compares Kovrr (CRQ specialist) against vCISO Lite (CRQ inside a broader vCISO + GRC + services SKU). It does not compare against other CRQ specialists on their own merits — the buyer evaluating dedicated CRQ platforms should also see /vs/cybersaint and /vs/safe-security. Enterprise IRM alternatives at /vs/riskonnect and /vs/servicenow-irm.