Resources

The method, written down and versioned.

Thirty-two original IO documents. Every one carries its status and document version, so pre-normative specifications and open questions can never read as settled guidance.

The library

Search it, or filter by collection.

Specifications and working notes are marked. Templates are written to be used, not admired.

32 documents

IO domain and topic

Collections group documents by kind. Topics and IO domains are what a document speaks to, they are not the same axis.

Specificationsv3.4

IO Maturity Model, Specification

This is the canonical maturity definition for the current IO product. It supersedes the earlier staged formulation that used different level names and a 0–6 progression. That earlier structure must not be mixed with the levels below in product…

Pre-normative working specification · 9 min

Specificationsv3.3

IO Risk Rating, Specification

Conventional risk registers commonly treat residual risk as a judgement. Someone asserts that the controls are working and re-scores the risk in a workshop. The number moves because a person decided it should.

Pre-normative working specification · 8 min

Methodv3.3

The Verification Method

Most security programmes can tell you what they did last quarter. Very few can tell you whether it worked. This document describes the mechanism that answers the second question, and, more importantly, the constraints that stop it answering it…

Current method · 6 min

Standards & Referencesv3.4

C2M2 Reference Map

The Cybersecurity Capability Maturity Model Version 2.1 was published by the US Department of Energy in June 2022 and is publicly available. It was built for operators of industrial and operational technology environments. Three properties…

Domain-level reference map · 3 min

Standards & Referencesv3.3

NIST AI RMF and ISO/IEC 42001 Reference Map

The NIST AI 600-1 Generative AI Profile (July 2024) is a companion to AI RMF 1.0, not a replacement. It adds GenAI-specific risk considerations and actions. IO uses it when a finding concerns models, prompts, agents, plugins, training or…

Function- and clause-level reference map · 4 min

Templatesv3.2

IO Reporting™ Board Risk Update Skeleton

A board risk update that reports only what is comfortable is worse than none, because it manufactures confidence that the register does not support. This skeleton enforces the three figures that must appear together and puts the uncomfortable one…

Ready to use · 4 min

Templatesv3.2

Verification Measure Definition Sheet

Complete this before the work starts. A measure defined after the fact is not a measure; it is a description of what happened, chosen once the outcome was known.

Ready to use · 3 min

Templatesv3.2

Exception Record

An exception is a decision to accept a known deviation for a stated period. It is not an absence of a control and it is not a backlog item. Recorded properly it is a sign of a governed programme; recorded loosely it is how an organisation grants…

Ready to use; platform gap disclosed · 3 min

Technical & Demov3.4

Signal Taxonomy Reference

Every signal IO ingests, by source system, with what it can inform. Useful for scoping a deployment before any connector is authorised, you can see in advance which domain dimensions will have evidence and which will read not yet assessable.

Demo-tenant scope · 4 min

Technical & Demov3.4

Demo Dataset Manifest

Atlas Industrial Technologies does not exist. Every person, incident, supplier and measurement in the demonstration tenant was generated. Nothing in it derives from a customer, and no figure in it should be cited as a benchmark or an industry…

Synthetic dataset disclosure · 4 min

Technical & Demov3.4

IO Domain Registry Schema

Machine-readable structure for the eight IO domains, their dimensions, and, most importantly, how a dimension with no evidence is represented so that it cannot band, score, or contribute.

Pre-normative technical reference · 3 min

Articlesv3.1

Absence of Evidence Is Not a Measurement

Ten separate defects in one product build had the same shape. A failed query, a blocking policy, or a truncating limit rendered as a plausible empty state or a confident number. Every one of them passed code review. Every one surfaced only by…

Publishable article · 4 min

Methodv3.1

Residual Risk Is a Judgment Everywhere Except Here

The title is deliberate shorthand, not a claim that IO removes judgement from risk. Judgement remains in scope, likelihood and impact definitions, appetite, measure design, noise thresholds and treatment decisions. What IO removes is a specific…

Public method overview · 4 min

Articlesv3.1

Why We Publish the Ones That Didn’t Work

In one demonstration tenant, 183 interventions are recorded as regressed. The measure they were meant to improve moved the wrong way, and the record says so, permanently, attributed to the playbook that produced it.

Publishable article · 4 min

Working Methodv3.1

Threshold Calibration, Open Question

The maturity gates, 90% ownership at Level 1, 80% cadence adherence at Level 2, 70% verification coverage at Level 4, and the rest, are working values. They were set by judgement about what ought to constitute a repeatable practice, not derived…

Open; blocks normative release · 3 min

Working Methodv3.1

Continuity, and Whether It Separates

This is a real distinction and a consequential one. A reactive organisation can produce enormous volumes of completed work, all of it in the fortnight after an incident, none of it in the eleven weeks either side. Volume cannot tell those two…

Experimental; dimension may be removed · 3 min

Working Methodv3.1

Evidence Decay

A residual risk score resting on a verification from two hundred days ago is weaker than the same score resting on one from last week. The environment moved. The population changed. The control may have drifted. Nothing in the record says so, and…

Open decision · 3 min

Methodv3.2

What the Maturity Model Does Not Cover

A model claiming to cover everything is not credible. This page names the exclusions, and it is intended to be read before the model rather than after it.

Current boundary note · 2 min

Methodv3.1

What Verification Does Not Establish

The verification loop is the strongest claim this product makes. This page is about its limits, and it exists because the gap between what the mechanism shows and what a reader might assume it shows is where a credible product becomes an…

Current boundary note · 3 min

Methodv3.2

What a Playbook Actually Contains

A playbook is encoded method, not a document attached to a task. It defines when an intervention applies, what must already be true, how the work is performed and how the result will be judged. The execution record is created later, when a named…

Current product reference · 2 min

Methodv3.2

Maturity You Can’t Self-Assess

Someone arrives with a questionnaire. A team answers it. The answers are scored, banded, and rendered as a level. The organization is told it is a 3.

Public method overview · 12 min

Standards & Referencesv3.4

IO Industry Methodology and Standards Map

IO is not a replacement for a cybersecurity framework, management-system standard, risk method, control catalog or assurance engagement. It is an evidence operating layer: it connects observed conditions to accountable work, then tests whether…

Cross-framework positioning reference · 3 min

Articlesv3.1

Automation Is Not Assurance

Automation can make security and compliance work faster. It can also make an unsupported conclusion appear faster, cleaner and more authoritative.

Publishable article · 2 min

Guidesv3.1

AI Security Governance: From Tool Inventory to Verified Operation

Most AI governance begins with an inventory and ends with a policy. Both are necessary. Neither shows whether the organisation's controls are operating.

Operating guide · 2 min

Articlesv3.1

Third-Party Risk Is Negotiated Before It Is Measured

Vendor-risk programmes often present the rating as if risk existed as a clean, objective fact before the assessment. In practice, technical, operational, procurement, legal and business teams first negotiate what the risk means, what evidence…

Research-informed article · 2 min

Articlesv3.1

Threat Speed Does Not Remove the Need for Evidence

When adversaries move faster, security teams need faster detection, decisions and response. They do not need lower standards for claiming success.

Threat-informed article · 2 min

Templatesv3.2

Binding Constraint Worksheet

A maturity level tells you where a practice currently stands. The binding constraint tells you why it cannot advance and what evidence would change the answer.

Ready to use · 3 min

Guidesv3.2

Inside the IO Command Center™

The IO Command Center™ is the operating view of IO™. It is designed to answer three questions without making the user reconstruct the programme from separate dashboards:

Product guide · 3 min

Guidesv3.2

Publishing an IO Reporting™ Board Update

Publishing turns live programme data into a governed record. The objective is not to make the current position look complete; it is to let a decision-maker understand the material exposure, evidence limits, movement and decision required at a…

Operational guide · 3 min

Guidesv3.2

First Ninety Days on IO

The first ninety days should establish a trustworthy operating baseline, not manufacture a maturity improvement story. Some practices will not have enough elapsed history to assess by day ninety. Reporting that limitation correctly is part of a…

Deployment guide · 3 min

Guidesv3.2

Writing a Measure You Can Defend

A defensible measure is not the most sophisticated number available. It is a number another person can recompute, challenge and use for the decision it was designed to support.

Operational guide · 3 min

Guidesv3.2

Turning Policy Into Execution

Most organisations do not have a policy shortage. They have a translation problem: principles are approved in documents, but the operating systems do not know when a rule applies, who must act, what evidence closes the work or whether the…

Operational guide · 4 min

The Executive Briefing

A written briefing, when there is something worth saying.

No cadence promises and no drip sequence. The briefing goes out when a verification result, a pattern across deployments, or a change in the threat picture is worth an executive's ten minutes.

In production

Sign up below; the first issue has not shipped yet.

Withheld

One document, Connection Readiness Checklist, is written but not published; its source is incomplete and it will go up when it is repaired.

Next step

See it before you talk to anyone.

Two quarters of recorded activity across sixteen seats. One click, no install.