Technical evaluation

vCISO Lite versus Riskonnect

Riskonnect is a PE-owned (TA Associates + Thoma Bravo) enterprise integrated-risk-management platform — 2,700+ customers, ~24 modules across GRC, insurable risk, business continuity, and AI governance, Salesforce-native at the core. vCISO Lite runs cyber risk quantification and TPRM inside a broader vCISO + GRC + services platform from $299/mo— with a shipped Monte Carlo CRQ engine, a productized M&A cyber diligence service, an externally-anchored evidence chain, and risk operations your own AI agents can call.

Prepared
Method
Capability walk against Riskonnect’s published product surface (riskonnect.com, riskonnect.com/products, riskonnect.com/solutions) and vCISO Lite’s live platform.
Sources
riskonnect.com, riskonnect.com/products/it-risk-management, riskonnect.com/products/third-party-risk-management, riskonnect.com/products/ai-governance, Feb 3 2026 Intelligent Risk Framework on Agentforce 360 press release, Argos Risk partnership press (Jul-Aug 2026), Redhand Advisors 2026 RMIS Report, vcisolite.com/pricing, vcisolite.com/diligence, vcisolite.com/evidence-graph, vcisolite.com/briefs-and-specs. See §10.
Corrections
Both vendors invited to review. Send corrections to /contact; the “Prepared” date above is bumped on any material update.
On this page · 10 sections

TL;DR

Findings§1

Where Riskonnect leads

  • Enterprise scale. ~$231M ARR, ~990-1,000 employees, 2,700+ customers including Arrow Electronics, RELX, Kohler, Wendy’s, Boston Scientific, Pure Storage, Southwest Airlines, Kaiser Permanente, Schlumberger, US Army. Multi-billion-dollar procurement footprint vCISO Lite doesn’t touch.
  • Multi-domain risk platform. Four solution families (GRC, Insurable Risk, Business Continuity & Resilience, AI Governance) across ~24 modules including ERM, Compliance, Policy, ESG, Internal Audit, IT Risk, TPRM, Health & Safety, Claims Management, RMIS (Ventiv acquisition), BCM (Castellan acquisition), Crisis Management, Threat Intelligence, Active Risk Manager (Sword acquisition). Buyers looking for one platform for cyber + ops + ESG + HR + claims can get it here.[9]
  • Redhand RMIS Leader nine years running. Insurance-industry analyst placement vCISO Lite doesn’t hold. (Origami Risk beat them for #1 in the 2026 report; still a Leader placement.)
  • Intelligent Risk Framework on Agentforce 360. Announced Feb 3, 2026 — biggest platform play of the year. Salesforce enterprise-AI integration for buyers already deep in the Agentforce environment.
  • Continuous vendor intelligence via Argos Risk. Partnership formalized Aug 5, 2026 — OEMed rather than natively built, but a real capability inside Riskonnect’s TPRM surface.[6]
  • Salesforce-native core. ERM / GRC / Compliance / Policy / TPRM / AI-Gov modules run on Force.com; buyers already standardized on Salesforce get platform-consistent tooling and identity, workflow, and data-model reuse.

Where vCISO Lite leads

  • Native CRQ engine, shipped. Riskonnect’s IT Risk Management page names FAIR + NIST 800-53 + NIST CSF + ISO 27001 + COBIT as framework support — no Monte Carlo, no ALE, no Loss Exceedance Curves in the product surface. vCISO Lite ships a 10,000-iteration seed-deterministic Monte Carlo CRQ engine with per-control what-if (the FAIR-CAM primitive), ALE, LEC, and NPV output on every scenario.[1][2]
  • Productized M&A cyber diligence. QCD 5-pillar CCOD (Attack Surface, Third-Party Concentration, Data Sensitivity, Program Maturity, Integration) as a 72-hour deliverable defensible at the Investment Committee. Codified from Someone Else’s Debt (Yolonda Smith, 2026). Riskonnect has no M&A diligence surface.[3]
  • Risk operations callable from your own AI agent stack. APRI at mcp.vcisolite.com exposes per-control what-if, top-risk retrieval, scenario simulation, and Loss Exceedance Curve retrieval to any MCP-speaking client. Riskonnect’s Intelligent Risk Framework runs inside Salesforce’s Agentforce 360 — external Claude / Cursor / custom LLMs work through the Salesforce environment, not the risk platform directly.[4]
  • Externally-anchored evidence chain. Every risk artifact Ed25519-signed and anchored to an external RFC-3161 timestamp authority. A SOC 2 auditor, cyber-insurance carrier, or M&A diligence reviewer can prove the chain wasn’t tampered with, without trusting vCISO Lite. Riskonnect’s audit trail sits inside the Salesforce data layer. SDK-licensable since 2026-08-15.[5]
  • Own security posture published. SOC 2 Type II + ISO 27001 posture visible on /about. Riskonnect’s public trust story is a 2016 SOC 2 Type II completion press release plus inherited Salesforce compliance — no public trust portal at trust.riskonnect.com, no ISO 27001 or ISO 27701 surfaced on public pages.[7]
  • 250+ frameworks named — including everything Riskonnect leaves off. Riskonnect’s public pages name DORA, SOX, APRA CPS 230, NIST 800-53, NIST CSF, ISO 27001, COBIT, FAIR. Not named: NYDFS Part 500, PCI DSS, HIPAA, GDPR, GLBA, Basel, MAS TRM, OSFI B-13. vCISO Lite’s 250+ SCF-cross-mapped frameworks include every one of those.[8]
  • Published pricing from $299/mo at /pricing. Riskonnect is enterprise-sales-led with third-party estimates of $150K-$500K+ Year 1 for TPRM-only mid-market, or ~$400K first-year TCO all-in.[10]
  • Trustworthy Autonomy proven in production. Public beta since 2026-07-07; Level 1 agent governance proven in production 2026-08-17. Riskonnect’s Intelligent Risk Framework on Agentforce 360 is thought-leadership plus platform integration; no published evaluation harness grading the agent by task category before purchase.
  • Founder-direct. [email protected] reaches the founder, not a sales-development queue.

Scope & evaluation criteria

Boundaries§2

In scope

Buyer profile
CISOs, CROs, and CFOs comparing an enterprise multi-domain IRM platform (Riskonnect) against cyber + GRC + services on a narrower SKU (vCISO Lite). Especially useful for buyers who need a shipped Monte Carlo CRQ engine (not just FAIR-name-checked framework support), risk operations callable from their own agent stack (not from Agentforce 360), or a productized M&A cyber diligence deliverable.
Evaluation frame
Ten capability categories the enterprise risk buyer typically weighs — native CRQ engine, per-control what-if primitive, M&A cyber diligence, agent-callable risk operations, evidence integrity foundation, native vendor scanning, own trust posture, named framework breadth, multi-domain risk breadth, published pricing. Not: everything each vendor does.
Comparison basis
Riskonnect’s published product surface (riskonnect.com/products), Feb 3 2026 Intelligent Risk Framework on Agentforce 360 press release, Argos Risk partnership press (Jul-Aug 2026), Redhand Advisors 2026 RMIS Report. vCISO Lite’s live platform. Not: NDA material, unreleased roadmap, or third-party analyst reports behind paywalls.

Out of scope

Insurable Risk / RMIS / Claims
Riskonnect’s Insurable Risk family (5 modules including Claims Management and RMIS from the Jan 2024 Ventiv acquisition) targets insurance carriers and self-insured enterprises. vCISO Lite doesn’t compete in this category. If the buyer needs unified GRC + Claims + RMIS on one platform, Riskonnect is the right choice.
Business Continuity & Resilience (Castellan)
Riskonnect’s BCM family (5 modules including Castellan-origin BCM, Operational Resilience, Crisis Management, Threat Intelligence, Emergency Notification) is a distinct product category. vCISO Lite doesn’t compete in BCM as a standalone; buyers needing dedicated BCM alongside cyber should evaluate Castellan-inside-Riskonnect or Fusion Risk Management.
Enterprise Salesforce standardization
Riskonnect’s GRC / TPRM / Compliance / Policy / AI-Gov core is Salesforce-native. Buyers already deep in Salesforce (Force.com, Agentforce 360, Data Cloud) get platform-consistent identity, workflow, and data-model reuse. vCISO Lite runs multi-tenant SaaS outside the Salesforce environment — different foundation assumption.

Capability coverage

Ten capabilities§3

Amber = Riskonnect ships / has it. Teal = vCISO Lite ships it. Split = both. Hover a hex for the mechanism detail.

Capability deep-dives

How each side implements it§4

Five capabilities, one spec-card per side. Framework decomposition lives in §5.

FOUR SOLUTION FAMILIESGRC (11 modules)ERM · TPRM · IT Risk · AI GovInsurable Risk (5)Claims · RMIS (Ventiv)BCM & Resilience (5)Castellan-origin BCMAI Governance(new module 2026)ride onSUBSTRATE STACKSSalesforce-native core (Force.com)GRC · TPRM · Compliance · Policy · IT Risk · AI GovSwordActive Risk MgrVentivRMIS / ClaimsCastellanBCM stackIntelligent Risk Framework on Agentforce 360announced Feb 3, 2026 — agentic surface (inside Salesforce)Argos Risk (OEM)continuous vendor intelligence · formalized Aug 5, 2026ERM Dashboard · heat maps · bowtie visualizations · role-based viewsno shipped Monte Carlo · no ALE / LEC output · no auto-narrated board reportEnterprise board readouts · 2,700+ customers (Kaiser, Kohler, US Army, Southwest, Boston Scientific)public trust posture: 2016 SOC 2 releaseno trust.riskonnect.com portal
Four solution families ride on a Salesforce-native core plus acquired acquired stacks (Sword, Ventiv, Castellan), with the Intelligent Risk Framework agentic layer running on Agentforce 360.
§4.1

Native CRQ engine (Monte Carlo)

Riskonnect names FAIR as framework support. vCISO Lite ships the Monte Carlo engine in production.

Riskonnect

The IT Risk Management module names FAIR + NIST 800-53 + NIST CSF + ISO 27001 + COBIT as supported frameworks. No shipped Monte Carlo engine, no ALE / SLE terminology, no Loss Exceedance Curves on the public product surface.

Inputs
Risk scenarios, control assessments, and framework mappings inside the ERM / IT Risk modules.
Outputs
Heat maps, bowties, role-based ERM dashboards, PDF/CSV exports. No dollar-figure ALE, no LEC curves.
Evidence
riskonnect.com/products/it-risk-management names FAIR; no Monte Carlo or LEC on the surface.
Fails when
Buyer needs a defensible dollar-figure ALE, LEC curve for board reporting, or Monte-Carlo-driven quantification for cyber-insurance underwriting conversations. Enterprises typically pair Riskonnect with a CRQ specialist (Safe Security, Kovrr, or the former RiskLens) for real quantification.
vCISO Lite

10,000-iteration seed-deterministic Monte Carlo engine. Every simulation is reproducible for audit — identical inputs produce identical outputs.

Inputs
Scenario definition from the risk register; frequency low/high; magnitude low/high; control effectiveness; optional per-control what-if frequency and magnitude reductions.
Outputs
Baseline and projected ALE with percentile bands, full Loss Exceedance Curve, ALE reduction in dollars and percent, ROI (NPV, payback years, 10% discount, 3-year model).
Evidence
Trial count engineered for sub-30-second per-org runtime across the risk register. Every simulation Ed25519-signed to the Evidence Graph.
Fails when
Buyer's procurement requirement is a Forrester Wave CRQ Leader analyst cite specifically. Neither Riskonnect nor vCISO Lite currently holds that placement (Safe Security is the Q2 2025 Wave Leader).
§4.2

Per-control what-if (FAIR-CAM primitive)

Riskonnect names FAIR but doesn't ship the per-control quantification mechanic. vCISO Lite ships it in production and exposes it to external agents through APRI.

Riskonnect

Per-control quantification — how a specific control's frequency reduction and magnitude reduction shift ALE for a specific loss event — is not surfaced as a distinct primitive on any public product page.

Inputs
Control assessments and framework mappings inside the IT Risk Management module.
Outputs
Heat-map placement, control-effectiveness ratings, framework coverage rollups.
Evidence
riskonnect.com/products/it-risk-management describes FAIR as framework support without a per-control what-if primitive.
Fails when
Buyer needs to answer 'what does this control at maturity Z do to my ALE for this specific loss event?' as a dollar figure. That's FAIR-CAM's definitional question; not Riskonnect's shape today.
vCISO Lite

Per-control frequency reduction × magnitude reduction re-runs the target scenario through the same 10,000-iteration Monte Carlo engine. Callable from any MCP-speaking agent through APRI.

Inputs
Target scenario or risk name; the control's frequency reduction and magnitude reduction (0–1 fractions); optional implementation cost and annual cost for ROI computation.
Outputs
Baseline and projected numbers side-by-side: Expected (ALE), BestCase, Severe, Worst, and full Loss Exceedance Curve. Plus ALE reduction in dollars and percent, and ROI (NPV, payback years, 10% discount, 3-year model).
Evidence
Every invocation Ed25519-signed to the Evidence Graph. This is FAIR-CAM's definitional statement: quantify how a specific control impacts loss event frequency and loss magnitude.
Fails when
Buyer's requirement is the Forrester Wave FAIR-CAM analyst cite specifically today. Safe Security holds that; the analyst-positioning work is on the roadmap.
§4.3

M&A cyber diligence as productized SKU

Riskonnect has no M&A cyber diligence surface. vCISO Lite ships QCD 5-pillar CCOD as a 72-hour productized service.

Riskonnect

Enterprise IRM across GRC + Insurable Risk + BCM + AI Governance is Riskonnect's platform. M&A cyber diligence as a productized deliverable is not a Riskonnect surface. Deal-side buyers doing PE/M&A cyber diligence engage big-four services or specialist boutiques.

Inputs
N/A — no diligence product on public surface.
Outputs
N/A.
Evidence
Public product surface has no /diligence, /qcd, or M&A-diligence-branded page.
Fails when
Buyer is deal-team-side (PE, M&A) needing pre-close cyber diligence delivered in days, not weeks, defensible at Investment Committee.
vCISO Lite QCD

Quantitative Cyber Diligence — 5-pillar CCOD (Attack Surface, Third-Party Concentration, Data Sensitivity, Program Maturity, Integration) productized at /diligence. 72 hours from kickoff to a deliverable defensible at the Investment Committee.

Inputs
Target company scope + engagement letter · public attack-surface data · contracts and vendor list where accessible · framework attestations.
Outputs
Single-figure CCOD (Cyber Cost of Deal) with per-pillar decomposition · defensible narrative for the IC · portable format (ephemeral by design).
Evidence
Codified from Someone Else's Debt (Yolonda Smith, 2026). Published pillar-by-pillar on /diligence.
Fails when
N/A on the diligence axis — Riskonnect has no comparable productized diligence surface.
§4.4

Risk operations callable from your own agent stack

Riskonnect's Intelligent Risk Framework runs inside Salesforce Agentforce 360. vCISO Lite exposes risk operations as MCP tools any external agent can invoke directly.

Riskonnect

Intelligent Risk Framework on Agentforce 360 (announced Feb 3, 2026) is Riskonnect's biggest platform play. It runs inside Salesforce's agent runtime. External Claude / Cursor / partner agents work through the Salesforce environment, not against Riskonnect operations directly.

Inputs
User interactions and agent flows inside the Agentforce 360 / Salesforce environment.
Outputs
Displayed inside the Riskonnect + Salesforce platform; exportable through Salesforce.
Evidence
Feb 3 2026 press release names Agentforce 360 as the agentic layer.
Fails when
Buyer's team lives in Claude / Cursor / a custom LLM outside the Salesforce environment and wants CRQ or vendor operations to happen there. Or an autonomous agent needs to invoke controls-what-if continuously without a Salesforce round-trip.
vCISO Lite APRI

APRI at mcp.vcisolite.com exposes CRQ operations as callable MCP tools. Any Claude, Cursor, custom LLM, or autonomous loop can invoke per-control what-if, top-risk retrieval, scenario simulation, and Loss Exceedance Curve retrieval directly.

Inputs
Whatever context the invoking agent has — scenario ID, control candidate, risk threshold, workflow step from another MCP server.
Outputs
Same projection, delta, and ROI response the platform returns. Every invocation Ed25519-signed to the Evidence Graph regardless of which agent called it.
Evidence
Three architectural guarantees make composability safe: caller-entitlement scoped (invoking user's entitlements, not a service account), complete tool-call audit trail (Ed25519 on the Evidence Graph), observe-first (writes go through a confirmation gate). Published foundation-model choice (Anthropic Claude family).
Fails when
Buyer is already fully standardized on Salesforce Agentforce 360 and prefers all agent work to flow through the Salesforce environment. That's Riskonnect's foundation strength.
§4.5

Named framework breadth

Riskonnect's public pages name a narrow set. vCISO Lite names 250+ frameworks — including everything Riskonnect leaves off.

Riskonnect

IT Risk Management page names NIST 800-53, NIST CSF, ISO 27001, COBIT, FAIR. Financial services page names DORA, SOX, APRA CPS 230, Bank of England. Compliance story is generic ("built-in compliance tracking") rather than named-framework-specific.

Inputs
Framework mappings inside each module.
Outputs
Framework coverage rollups per module, ERM dashboard rollup.
Evidence
riskonnect.com/products pages surveyed. NOT explicitly named on public pages: NYDFS Part 500, PCI DSS, HIPAA, GDPR, GLBA, Basel, MAS TRM, OSFI B-13.
Fails when
Buyer needs explicit coverage of a framework Riskonnect's public pages don't name (NYDFS 500, PCI DSS, HIPAA, GDPR, etc.). Would require scoping-call confirmation and likely a customization implementation.
vCISO Lite

250+ SCF-cross-mapped frameworks (1,468 universal controls) — every SCF-mapped control unlocks the frameworks that share it.

Inputs
SCF (Secure Controls Framework) crosswalk applied to every control in the corpus.
Outputs
Framework coverage per control, gap analyses, cross-framework harmonization for shared controls.
Evidence
Full framework list on /features/compliance. Includes NYDFS 500, PCI DSS, HIPAA, GDPR, CCPA/CPRA, GLBA, NIS 2, EU AI Act, ISO 42001, NIST AI RMF, CMMC L1-L3, FedRAMP, StateRAMP, TX-RAMP — every framework Riskonnect's public pages leave unmentioned.
Fails when
Buyer needs a specific niche insurance-industry framework (RIMS-CRO Standard, etc.) that Riskonnect's Insurable Risk family covers via Ventiv's RMIS lineage. That's Riskonnect's ceded ground.

Framework & control coverage

Framework depth§5

Riskonnect names DORA, SOX, APRA CPS 230, NIST 800-53, NIST CSF, ISO 27001, COBIT, FAIR across its IT Risk Management + Financial Services pages. Not named on public pages: NYDFS 500, PCI DSS, HIPAA, GDPR, GLBA, Basel, MAS TRM, OSFI B-13. vCISO Lite ships 250+ SCF-cross-mapped frameworks (1,468 universal controls) — every SCF-mapped control unlocks the frameworks that share it.

Riskonnect[8]

NIST CSF
NIST 800-53
ISO 27001
COBIT
FAIR
DORA
SOX
APRA CPS 230

vCISO Lite

SOC 2
ISO 27001
HIPAA
PCI DSS
NIST CSF 2.0
CMMC L1
CMMC L2
CMMC L3
800-171r3
NIST 800-53
FedRAMP
NIST RMF
NIST AI RMF
SEC cyber
CIS Controls
GDPR
DORA
NYDFS 500
HITRUST
CJIS
NIS 2
EU AI Act
ISO 42001
ISO 27002
ISO 27701
ISO 22301
SOC 1
SOC 3
CCPA / CPRA
GLBA
StateRAMP
TX-RAMP
CIS Benchmarks
MITRE ATT&CK
NIST 800-63
NIST 800-172
FFIEC CAT
SWIFT CSCF
LGPD
PIPEDA
COPPA
FERPA
CIPA
CSA CCM

Pricing & delivery model

Enterprise sales-led vs published direct-buy§6

Riskonnect is 100% enterprise-sales-led with no public pricing. Third-party estimates land first-year TCO at ~$400K all-in and mid-market TPRM-only Year 1 at $150K-$500K+. vCISO Lite starts at $299/mo Starter, with every tier price on /pricing.

Riskonnect

Enterprise SaaS

Contact-sales · no public dollar figure[10]

Sold to
Fortune 500 / large-enterprise CROs, CFOs, CIOs — Arrow Electronics, RELX, Kohler, Kaiser Permanente, US Army, Southwest Airlines
Published tiers
None — contact-sales for pricing
Free-trial entry
No
Delivery model
Sales-led · demo-gated · enterprise implementation with services (~$258K services + ~$142K internal ~= ~$400K first-year TCO all-in per third-party estimates)
Sales cycle
Request-a-demo → scoping call → implementation SOW → contract
vCISO Lite

From $299/mo

Direct-buy from Starter · every tier on /pricing

Starter
$299/mo — 5 vendors + 5 vendor questionnaires answered per month + CRQ scenario runs. Additional tiers on /pricing.
Platform + services
vCISO Lite ships the platform and productized services (QCD M&A cyber diligence, managed TPRM assessments) on /services.
Sales cycle
Direct-buy end-customer · Enterprise: one call, flat MSRP on file · no scoping-call gate to see a price

Integration surface

Native connectors§7

Riskonnect’s Salesforce-native core gets everything Salesforce does — AppExchange breadth, Mulesoft, Data Cloud, Slack. vCISO Lite runs its own connector catalog outside the Salesforce environment. Full catalog on /features/integrations.

IntegrationRiskonnectvCISO Lite
AWSNative
AzureNative
GCPNative
SnowflakeNative
GitHubNative
GitLabNative
Google WorkspaceNative
Microsoft 365Native
OktaNative
JiraNative
SlackNativeNative
MCP (Model Context Protocol)Native
Salesforce / Force.comNative
Salesforce Agentforce 360Native
MulesoftNative
Argos Risk (vendor intelligence, OEM)Native
Integration catalog published?AppExchange (Salesforce), not Riskonnect-enumeratedFull catalog on /features/integrations

Deployment, data, extensibility

Platform architecture§8
AttributeRiskonnectvCISO Lite
Service modelSaaS multi-tenant · Salesforce-native core (GRC/TPRM/Compliance/Policy/IT Risk/AI-Gov) · Sword / Ventiv / Castellan on their own acquired stacksSaaS multitenant · end-customer tenancy · Enterprise-tier isolated deployment on request
Native CRQ engineNames FAIR + NIST 800-53 as framework support; no shipped Monte Carlo, ALE, or LEC10,000-iteration seed-deterministic Monte Carlo · reproducible for audit · every simulation Ed25519-signed to the Evidence Graph
Per-control what-if (FAIR-CAM primitive)Not surfaced on public product pagesPer-control frequency reduction × magnitude reduction re-run through the same engine · ALE reduction in dollars + NPV + LEC delta · callable from any MCP-speaking agent through APRI
M&A cyber diligence surfaceNot on public product surfaceQCD 5-pillar CCOD productized at /diligence · 72-hour deliverable · defensible at the IC
Audit-trail modelSalesforce-native data layer (core modules) · Sword / Ventiv / Castellan on their own stacks · no external anchor / per-event signing / transparency log disclosedEvidence Graph · per-event Ed25519 signing · RFC 3161 external timestamp anchor · SDK-licensable
Where the AI actually runsIntelligent Risk Framework on Salesforce Agentforce 360 · inside the Salesforce environmentCallable from any MCP-speaking client via APRI at mcp.vcisolite.com · every invocation Ed25519-signed to Evidence Graph
Vendor intelligence (continuous)Argos Risk OEM partnership (formalized Aug 5, 2026)Engagement-driven (red-team / QCD / DC-TPIR), not always-on rating engine
Multi-domain risk breadth~24 modules across GRC + Insurable Risk + BCM + AI GovCyber + GRC + TPRM + DC-TPIR + M&A diligence — narrower
Analyst pedigreeRedhand Advisors 2026 RMIS Report Leader (9th consecutive year)No CRQ-category or IRM-category analyst-cite today
Own compliance posture2016 SOC 2 Type II press release · no public trust portal at trust.riskonnect.com · inherits underlying Salesforce compliance stackSOC 2 Type II · ISO 27001 · posture published on /about

Business-case briefing

For a budget request§9

Personalized briefing

Make the case for vCISO Lite alongside Riskonnect

A PDF business case, personalized to your company, that lays out the three options — no integrated risk platform, Riskonnect, or direct-buy vCISO Lite — with the cost math and honest tradeoffs. Written to be credible with a buyer who's already seen Riskonnect's enterprise IRM breadth and needs to see what the shipped Monte Carlo CRQ + productized M&A cyber diligence + externally-anchored evidence chain + published pricing alternative actually delivers on a separate axis.

View pricing

Notes & sources

Provenance§10
  1. [1] Riskonnect IT Risk Management module framework support (FAIR, NIST 800-53, NIST CSF, ISO 27001, COBIT) from riskonnect.com/products/it-risk-management (accessed 2026-09-16). No Monte Carlo, ALE, or Loss Exceedance Curve terminology on the product surface. vCISO Lite ships a 10,000-iteration seed-deterministic Monte Carlo engine with ALE, percentile bands, and LEC output on every scenario.
  2. [2] Per-control what-if (FAIR-CAM primitive). Not surfaced on Riskonnect’s public product pages. vCISO Lite ships per-control frequency reduction × magnitude reduction re-run through the same Monte Carlo engine, returning ALE reduction in dollars, NPV, payback, and Loss Exceedance Curve delta. Callable from any MCP-speaking agent through APRI.
  3. [3] QCD 5-pillar CCOD (Cyber Cost of Deal) productized as M&A cyber diligence service from vcisolite.com/diligence. Methodology codified in Yolonda Smith’s 2026 book Someone Else’s Debt.
  4. [4] Riskonnect Intelligent Risk Framework on Agentforce 360 announced Feb 3, 2026 (Riskonnect press release). vCISO Lite APRI (MCP tool graph exposing per-control what-if, top-risk retrieval, scenario simulation, and Loss Exceedance Curve retrieval; live at mcp.vcisolite.com) verified against vcisolite.com/titanium.
  5. [5] vCISO Lite Evidence Graph (per-event Ed25519 signing shipped 2026-08-16 + RFC-3161 external timestamp anchor + transparency log live in production 2026-08-20; SDK-licensable since 2026-08-15) from vcisolite.com/evidence-graph. Riskonnect audit-trail characteristics from riskonnect.com product pages (Salesforce-native data layer for core; Sword / Ventiv / Castellan on their own stacks; no external anchor / per-event signing / transparency log disclosed).
  6. [6] Riskonnect Argos Risk partnership announced Jul 21, 2026; formalized Aug 5, 2026 (Riskonnect press releases). Continuous vendor intelligence is OEMed rather than natively built.
  7. [7] Riskonnect own trust posture: 2016 SOC 2 Type II completion press release; no public trust portal at trust.riskonnect.com; no ISO 27001, HITRUST, or ISO 27701 surfaced on public pages as of 2026-09-16. Underlying Salesforce compliance stack (FedRAMP, SOC 1/2, ISO 27001) is Salesforce’s program, not Riskonnect’s own. vCISO Lite SOC 2 Type II + ISO 27001 posture published on vcisolite.com/about.
  8. [8] Riskonnect explicitly-named frameworks: NIST 800-53, NIST CSF, ISO 27001, COBIT, FAIR (IT Risk Management); DORA, SOX, APRA CPS 230, Bank of England (Financial Services). NOT named on public pages: NYDFS Part 500, PCI DSS, HIPAA, GDPR, GLBA, Basel, MAS TRM, OSFI B-13. vCISO Lite framework coverage (250+ SCF-cross-mapped, 1,468 universal controls) verified against vcisolite.com/features/compliance.
  9. [9] Riskonnect four solution families and ~24 modules from riskonnect.com/products. Acquisitions: Sword GRC (Feb-Apr 2022), Castellan (Jul 2022), Ventiv Technology (Jan 11, 2024). Revenue ~$231M ARR and 2,700+ customers per third-party aggregators (PitchBook / ZoomInfo) and Riskonnect public statements.
  10. [10] Riskonnect pricing (100% sales-led; no public dollar figure; third-party estimates place entry-level single module at $35K-$140K/yr and first-year TCO at ~$400K all-in) from third-party aggregator data. vCISO Lite platform tiers ($299/mo Starter through $8,500/mo Enterprise MSRP) from vcisolite.com/pricing.
  11. All product capability claims for both platforms are current as of the “Prepared” date at the top of this page. If Riskonnect publishes a native Monte Carlo CRQ engine, a public MCP endpoint, or an externally-anchored evidence chain since publication, corrections at /contact.
  12. This page compares Riskonnect (enterprise multi-domain IRM) against vCISO Lite (CRQ + GRC + services on a narrower SKU). It does not compare against other IRM platforms on their own merits — the buyer evaluating enterprise IRM should also see /vs/servicenow-irm. Dedicated CRQ specialists at /vs/safe-security, /vs/kovrr, and /vs/cybersaint.