Executive Overview

Sample Organization · Sample data · as of

Get your score

Value at Stake

measured + modeled, kept separate
$55K–$135K

one-time cost to fix · measured

$85K–$225K/yr

annual risk exposure · modeled (estimate)

  • Ready$25K–$60K
  • Safeest.$85K–$225K/yr
  • Efficient$30K–$75K
How this is calculated

The dollars your technology posture puts in play, in two parts we keep strictly separate — a one-time cost to fix, and an annual risk exposure:

  • Measured — facts derived from real signals (e.g. the engineering cost to pay down the technical debt we detected: effort × your loaded engineering cost). A one-time cost to remediate.
  • Modeled — risk-adjusted expected loss = modeled annual probability × impact. A weaker score raises the modeled probability. These are estimates from tunable assumptions, never guaranteed losses.
IT-modernization remediationmeasured$25K–$60K

From your IT Modernization score. Estimated one-time engineering cost to close the measured IT-modernization gaps (IaC, paved-road, cloud, automation, containers) to a healthy bar: effort × loaded engineering cost. A measured cost, not a guaranteed spend.

Technical-debt remediationmeasured$30K–$75K

From your Technical Debt score. Estimated remediation exposure of $30K–$75K (2–5 engineer-months) to bring technical debt to a healthy bar, measured across 5 of 6 dimensions. Confidence: high. Primary drivers: Architecture Debt, Legacy Code, Dependency Debt. This is an estimated exposure, not a guaranteed cost.

Breach expected-lossmodeled$55K–$150K

From your Security Readiness score. Modeled annual breach expected-loss at a 50/100 security posture (~19% modeled annual probability × $500,000 impact). Estimate, not a measured loss.

EOL incident expected-lossmodeled$30K–$75K

From your Lifecycle Risk score. Modeled annual EOL/lifecycle incident expected-loss at a 60/100 lifecycle posture (~19% modeled annual probability × $250,000 impact). Estimate, not a measured loss.

Assumptions (breach/incident impact, annual probabilities, loaded engineering cost) are coarse, defensible defaults shown in each line above and are tunable per organization — they are starting points, never presented as measured truth.

Measured is a one-time cost to fix (e.g. debt remediation effort); modeled is an annual risk estimate from tunable assumptions, not a guaranteed loss. The two are never added together.

ShipReady Score

CDeveloping+2

The ShipReady Score is 68/100 (Developing) — a weighted composite of AI readiness, ROI, agents, debt, modernization, lifecycle, security, delivery, and cloud health.

Target 75 (Strong) · 7 to close

Priorities

Ranked · owner · highest impact
  • criticalBring down the most serious known security flawsCISO

    The count of serious known security flaws is high for the size of your technology estate. Fix the most serious ones on customer-facing and business-critical systems first.

    could add about 25 points
  • criticalReplace unsupported system: Windows Server 2012 R2CIO

    Windows Server 2012 R2 (Infrastructure) no longer receives any support or security fixes from its maker, leaving it exposed to known attacks and likely to fail an audit. Upgrade to Windows Server 2022, or replace it or buy extended support.

    could add about 8 points
  • criticalReplace aging core systemsCIO

    Some of the servers and core systems the business runs on are at or past the point where their vendors stop providing fixes and security updates. Plan replacements or paid extended support before one fails an audit or causes an outage. At risk now: Windows Server 2012 R2 (all vendor support ended Oct 2025) — upgrade to Windows Server 2022, Ubuntu 18.04 LTS (standard support ended May 2025) — upgrade to Ubuntu 24.04 LTS. Support dates come from a curated industry catalog; the dated inventory lists each one.

    could add about 4 points
  • criticalMove software onto supported versionsCIO

    Some of the underlying technology the company's software is built on has reached, or is nearing, the point where its maker stops issuing security fixes — anything found after that stays open. Move to versions the maker still supports. At risk now: Node.js 18 (standard support ended Apr 2026) — upgrade to Node.js 22, Python 3.8 (standard support ended Oct 2025) — upgrade to Python 3.12, .NET 6 (standard support ends Nov 2026). Support dates come from a curated industry catalog; the dated inventory lists each one.

    could add about 3 points
  • highModernize the oldest parts of the systemCTO

    A large share of the software is aging code that no one actively owns, which makes every change slower and riskier. Focus modernization on the parts that change most often.

    could add about 4 points

What moved

Delivery Health improved the most (+6) and Security Readiness slipped the most (-3) since the last run.

Improved

  • Delivery Health+684/100
  • Technical Debt+563/100
  • AI Readiness+468/100

Declined

  • Security Readiness-350/100
  • AI ROI-282/100
  • IT Modernization-165/100

Domain scores

Each 0–100 score is a weighted, explainable composite — the same computation a real tenant gets from its connected data sources.

AI Readiness

CDeveloping+4

Material gaps must close before the organization can adopt AI safely at scale — AI Readiness is developing at 68/100. Fix the weakest areas first.

AI ROI

BStrong-2

Every dollar on AI tooling is returning an estimated 10x+ in engineering time — the clearest read on whether the AI budget is paying for itself. 82/100 on $21,100/mo of AI spend. Refine the inputs to sharpen the estimate.

Agent Health

BStrong+3

Reliable, mostly hands-off agents are shipping work end-to-end and adding delivery capacity. 85% success and 70% autonomous completion across 8,450 runs. Widen agent access to compound the gain.

Technical Debt

CDeveloping+5

Rising technical debt is starting to slow delivery and push up maintenance cost. Debt health 63/100. Pay down the heaviest debt first.

IT Modernization

CDeveloping-1

A modernization gap slows delivery, drives up cloud cost, and leaves operational risk in aging platforms. 65/100 overall, developing. Close the biggest modernization gaps first.

Lifecycle Risk

CDeveloping+2

Running unsupported, end-of-life tech is a live security and audit exposure — an unpatched system can fail a customer or compliance review and turn into an outage. 5 asset groups past end-of-life/support. Grade held at C because Windows Server 2012 R2 (high-criticality) is past end-of-life — a critical/high end-of-life is not averaged away by supported assets. Upgrade or replace those first.

Security Readiness

DAt Risk-3

6 critical exposures could stall an enterprise deal, fail a customer security review, or become an incident. 6 critical / 38 high / 142 medium — 186 distinct vulnerabilities and 71% compliance posture. Clear the criticals first. Score capped at 50 while a critical vulnerability remains open — it cannot rise above 50 until the criticals are resolved.

Delivery Health

BStrong+6

How fast and reliably you ship sets your time-to-market and how quickly you recover when something breaks. Delivery Health is strong at 84/100 on release speed and reliability (DORA) from your connected sources. No dimension is below target.

Cloud Health

CDeveloping+1

Your cloud estate drives monthly spend, uptime, and breach exposure — it's developing at 69/100 across cost, security, reliability, and architecture. Shore up the weakest of those first.

This is sample data. Yours would be real.

Connect your cloud, DevOps, security, and AI tooling to turn scattered signals into one executive view — scored the same way, from your own data.

Get started