For investors, vCSOs & the boards they answer to

Cyber risk, priced in dollars.

Theodolite deploys a scanner inside the environment you're invited into — a portfolio company, a client — and turns verified cloud evidence into a dollar-denominated exposure estimate, a prioritized fix plan, and a board-ready report. FAIR methodology, CIS Controls v8, every finding backed by live cloud evidence.

30-minute call. No slides. Real numbers from a real scan.

Scroll

Frameworks & standards we map against

FAIREPSSCIS Controls v8MITRE ATT&CKCISA KEVCVSSPCI DSSHIPAACMMCGDPR

Cloud Evidence

AzureAWSEntra ID

Risk Frameworks

FAIREPSSCIS Controls v8

Data Discovery

SharePointBoxBlob & S3

CIS v8 Compliance

ControlsEvidenceAudit

Theodolite

>

Illustrative example

In 30 minutes, Theodolite helps you answer the most important question

“How much could we lose?”

A different approach to cyber risk.

Traditional

  • Siloed scans with no business context
  • CVSS scores that mean nothing to the board
  • Weeks to compile a risk report

With Theodolite

RISK$4.2M
CIS v8: 91%
Findings: 847
Actions: 12
  • Total cyber exposure quantified in dollars
  • Board-ready risk reports in days, not weeks
  • One cyber risk balance sheet for your CFO

The Story Behind Theodolite

“I built Theodolite because no tool gave me what I needed in that boardroom: a single number, in dollars, that told the truth about our risk posture.”

Nick Shevelyov, Founder

Founder, Theodolite & vCSO

15 years CSO, SVB

Author, “Cyber War…and Peace” — on translating cyber risk for boards

Cyber Risk Balance Sheet

Every finding in dollars.

Access Intelligence

See who can reach the value at risk. Over-permissioned identities, external access, and blast radius — mapped from live cloud permissions and graded by access and data reach.

See who can reach your value at risk
Access by Risk ($)
1,847 identities
svc-backup-prodAdmin
$2.1M
Resources reachable: 34
MFA: No
External: No
Action: Scope service principal to a single resource group
j.doe@partner.comExternal
$1.4M
Resources reachable: 8
MFA: Yes
External: Yes
Action: Review guest access to the finance site
ops-shared-adminShared
$890K
Resources reachable: 23
MFA: No
External: No
Action: Split shared account into named identities
ci-deploy-tokenToken
$340K
Resources reachable: 5
MFA: No
External: No
Action: Rotate long-lived deploy credentials
intern-2024Stale
$120K
Resources reachable: 2
MFA: Yes
External: No
Action: Disable dormant account (no sign-in 180d)
Value reachable by risky identities$4.87M
CIS v8 Readiness
91%READY
Access Control95%
Change Mgmt88%
Risk Assessment92%
Monitoring85%
198
Answered
11
Pending
18
Controls

Compliance Automation

209 assessment questions — 153 CIS Controls v8 and 56 cyber due-diligence — auto-answered from live cloud evidence.

Run it on your own environment

Data Discovery

Scan Azure, AWS, SharePoint, and Box for PII, PHI, and exposed credentials — inside the customer environment, never stored on our servers.

See what a scan surfaces
Sensitive Data Found
3 providers
AWS
AWS S38.2 TB
47 containers · 1243 findings
PIICRED
prod-user-uploads
3.1 TB412PII
backup-db-exports
2.8 TB567PII
config-secrets
240 GB264CRED
AZ
Azure Blob3.1 TB
23 containers · 891 findings
PIIPHI
patient-records
1.4 TB523PHI
hr-documents
890 GB241PII
analytics-raw
810 GB127PII
SP
SharePoint1.1 TB
12 containers · 234 findings
PII
Finance – Board Packs
680 GB145PII
HR – Onboarding
420 GB89PII
Total exposure across all providers12.4 TB

How it Works

Three Steps. One Report.

Connect

Analyze

Act

$4.2M$1.8M$890K$3.1M$560KQuantifying findings...
Actions Required

Stop Guessing.
Start Measuring.