Cyber Decision Platform

Kritis

Kritis is CTRL 18's Cyber Decision Platform. It maps your security posture to the CIS 18 Controls, shows the gaps the way an attacker would exploit them, models the financial risk in dollars, and puts it on one dashboard the CISO and the CRO can act on.

Kritis: MITRE ATT&CK coverage matrix
Kritis: composite cyber-risk posture
Why this, why now

Security spend is up.
Clarity isn't

Your board asks, "Are we secure?"

You respond with dashboards.
Auditors respond with findings.
Vendors respond with more tools.

What nobody provides is a clear answer on which risks matter most, what to fix first, and how much risk will actually be reduced.

Kritis turns security data into defensible decisions

The method

Posture in. Decisions out

Three moves take you from a wall of findings to a ranked set of decisions a board can fund.

01, MAP

Map against the CIS 18

Your posture is automatically mapped to the 153 safeguards of CIS v8, scored on maturity and scoped to your Implementation Group.

Nothing auto-fires
02, SEE

See gaps as attack paths

Each gap is projected onto MITRE ATT&CK and the Lockheed Kill Chain, a control weakness becomes a visible attack path, not a spreadsheet row.

ATT&CK · Kill Chain
03, DECIDE

Decide across People · Process · Technology

Gaps become a prioritised set of decisions, with the risk reduction quantified in dollars , so next quarter is obvious and defensible.

Risk in $
See it work

From a wall of findings
to a ranked decision

Your posture is mapped to the 153 safeguards of the CIS 18, scored on evidence, then re-prioritised the way an attacker would, so the worst, most exploitable gaps surface first, each with the loss it carries in dollars.

▸ Nothing auto-fires. Every scan is a deliberate click or a schedule you set.

Posture · CIS 18 Controlsprioritising…
01 Enterprise Assets
02 Software Assets
03 Data Protection
04 Secure Config
05 Account Mgmt
06 Access Control
07 Vuln Mgmt
08 Audit Logs
09 Email & Web
10 Malware Def
11 Data Recovery
12 Network Infra
Expected annual loss
0
CIS Controls
0
Safeguards
0
Implementation Groups
0
Source of control
A system of record for CISO decisions

For years, cybersecurity leadership has operated without a system of record, relying on spreadsheets, slideware, and disconnected point solutions to guide critical decisions.

Kritis changes that. It gives security leaders a unified command center to continuously evaluate posture, understand business risk, and decide what matters most.

CIOs have ITSM.
CROs have CRM.
CFOs have ERP.
CISOs now have CTRL 18.
See it in action

Inside Kritis

From posture to attack paths to a priced decision, the same picture the CISO and the CRO work from.

Kritis, CIS Controls maturity

CIS Controls maturity

Your posture mapped across the CIS Controls v8 domains, scored on evidence.

The capabilities

What's inside

01

CIS 18 Posture Mapping

Multi-framework guided assessment (CIS v8, DPDPA and more), scoped to your Implementation Group (IG1 / IG2 / IG3), every safeguard scored 0–4 on maturity against evidence, not a self-graded survey.

02

Attack-Path Visualization

Every gap is projected onto MITRE ATT&CK tactics and the Lockheed Martin Kill Chain, so a control weakness becomes a visible, prioritizable attack path across your loss scenarios.

03

Risk Engine (in $)

Probabilistic loss modeling (Monte Carlo) quantifies risk in dollars per loss scenario: ransomware, data breach, business email compromise, insider, cloud misconfiguration. Anchored to NIST SP 800-30 / IR 8286 and ISO 27005.

04

Compliance Mapper

A pluggable framework registry: CIS Controls v8.1.2, DPDPA 2023, SEBI CSCRF, NIST CSF 2.0, ISO 27001. Map once, report many.

05

Dual-View Executive Dashboard

A technical view for the CISO (attack paths, themes, gaps) and a financial view for the CRO (expected loss in $, loss-exceedance curves, compliance %). One source of truth, two audiences.

06

Board-Ready Reports

A financial board report, a technical security-posture report, and per-framework audit packs. Generated, not hand-assembled.

See what they see

Passive external scanning, nothing intrusive

Kritis includes passive reconnaissance of your external attack surface: DNS, SSL, headers, exposed services, leaked credentials, dark-web mentions. Manual or scheduled. Nothing auto-fires: every scan is a deliberate click or a schedule you control, and the scanner never performs active exploitation.

Real data, not self-grading

Evidence that populates itself

Kritis connects to the systems you already run, across cloud and on-premise, so safeguards are backed by live telemetry instead of someone's best guess. The integration surface grows with what customers actually ask for: cloud, identity, endpoint, network and email security, plus an on-premise appliance for the estate that never touches the public internet.

Who reads it
For the CISO

Where the gaps are, which safeguards close them, how each maps to a real attack path, and what to do next, in technical depth.

For the CRO / board

What the risk is worth in dollars, how it trends, where compliance stands, and whether the spend is working, in plain financial terms.

Also from CTRL 18

The rest of the house

See your posture, your attack paths and your risk on one screen

CTRL 18, from chaos to control.