Cybersecurity has a measurement problem, not a technology problem. I have always said it plainly, what is not defined cannot be measured, what is not measured cannot be improved, and what is not improved is always degraded. Most organizations do not lack tools. They lack a single architecture that tells them where they stand, what to do next, who owns the decision, and how today’s action connects to yesterday’s and tomorrow’s. That is the gap the Cybersecurity Compass Framework is built to close.
The Problem With How Organizations See Cyber Risk
Ask a Chief Information Security Officer (CISO) where the organization’s cyber risk is highest right now, and you will usually get a heat map. Red, yellow, green, updated quarterly, built for a board slide rather than a decision. Heat maps feel like management. They are not. They are a snapshot of a moving target, taken with the shutter left open too long. By the time the map reaches the boardroom, the exposure it describes has already changed.
This is the deeper confusion that recurs inside organizations. They confuse cyber risk assessment with cyber risk management. Assessment tells you where you stood. Management tells you what you are doing about where you stand, continuously, as conditions shift. One is a photograph. The other is a nervous system.
What organizations actually need is a single model that unifies the three things cybersecurity has to do. Manage cyber risk before a breach. Detect and respond during one. Recover and grow stronger after one. Each of the three feeds the outcome that matters most, cyber resilience, but none of them produces it alone, and it is not something an organization purchases and installs. It is earned continuously, by the whole system running as one, not achieved once by any single part of it. Most programs treat these as three separate functions, run by three separate teams, measured by three separate sets of metrics that never talk to each other. The Cybersecurity Compass Framework treats them as one continuous system with three points, not four, and not three silos.
The Architecture: Three Domains, One Direction
The metaphor of a compass is deliberate. A compass does not tell you where you are. It tells you which way to move given where you stand. Cybersecurity needs the same discipline, because the digital environment behaves like a stormy ocean, constantly moving, never fully mapped, and unforgiving of organizations that stand still.
A map and a compass answer different questions, and most of cybersecurity has spent its history building better maps. An asset inventory is a map. A vulnerability scan is a map. A heat map, despite the name, is still a map. Each one is a precise picture of terrain that already exists, and each one goes stale the instant that terrain moves, which on this ocean is constantly. A compass does not describe terrain at all. It answers a narrower question, which way reduces exposure right now, and it keeps answering that question no matter how unrecognizable the terrain becomes. This is also where the framework has to be honest about its own limits. Nothing here claims to forecast which storm arrives next, what the next campaign will look like, or when the next vulnerability class will surface. No instrument does that honestly. What a working compass promises is narrower and more durable, an organization that stays oriented regardless of which storm shows up, rather than one holding an increasingly detailed map of water that has already moved on.
The three domains of the Compass are Cyber Risk Management, before a breach. Detection and Response, during a breach. Cyber Resilience, after a breach. Each domain runs on the same three pillars, people, processes, and technology, and each domain feeds the next. Cyber Risk Management defines what matters and where exposure is growing. Detection and Response acts on that definition when the inevitable happens. Cyber Resilience turns what was learned back into a stronger starting position for the next cycle.
The mistake most organizations make is treating these as sequential phases with clean handoffs. They are not sequential. They are simultaneous and interdependent. The moment cyber resilience work uncovers a gap, it becomes an input to cyber risk management. The moment cyber risk management flags a growing exposure, it becomes an input to detection priorities. The Compass only works as a system if the needle keeps moving between all three, and only if someone in the organization actually owns keeping it moving.
Turning the Compass Into Motion: The CRML
A direction is not a plan. To move beyond theory, the Compass is paired with the Cyber Risk Management Lifecycle, the CRML. This is the engine that operationalizes the Cyber Risk Management domain of the Compass. It replaces the annual cyber risk review with a loop that never stops.
The CRML runs through seven stages. First, discover and value digital assets, because you cannot protect what you have not counted and cannot prioritize what you have not valued. Second, identify vulnerabilities, threats, and consequences across that asset base. Third, assess and calculate cyber risk, turning likelihood and impact into numbers a board can actually use. Fourth, implement defenses and controls that match the cyber risk you just calculated, not the cyber risk you calculated last year. Fifth, mitigate, executing the strategies that reduce likelihood or impact. Sixth, track and monitor continuously, because the threat landscape does not wait for your next audit cycle. Seventh, reassess, and start again.
The seventh stage is the one organizations skip, and it is the one that matters most. A lifecycle that stops at mitigation is not a lifecycle. It is a project with a finish line, and cybersecurity does not have a finish line. The CRML took shape as a response to that exact failure, the tendency to treat cyber risk management as something you finish rather than something you run.
Why a Lifecycle Still Needs an Engine Room
Here is the honest limitation of the CRML, worth naming plainly, because intellectual honesty is what separates a real framework from a rebrand. A lifecycle describes what should happen. It does not, by itself, make sure it happens at the speed the business and the attacker both demand. You can design the seven stages perfectly and still fail, because nobody owns the loop in real time.
That gap is what the Cyber Risk Operations Center, the CROC, is built to close. The CROC is to cyber risk what the Security Operations Center (SOC) is to detection and response, except its questions run in the opposite direction. The SOC asks what just happened and how fast we can contain it. The CROC asks what our exposure is right now, how it is changing, and what decision needs to be made today to reduce it before it becomes an incident at all.
This distinction matters more than it sounds. A SOC makes an organization faster at reacting. A CROC makes an organization more confident in acting, before the incident, in the investment decision, in the strategic conversation about whether a new digital initiative is worth the exposure it creates. The CROC operationalizes the CRML. It is where the seven stages stop being a diagram and start being someone’s job, every day.
There is a simpler way to say all of this, and it may be the core point of the whole framework. The SOC protects today. The CROC protects tomorrow. And Cyber Resilience, the third domain, protects the future, the organization’s capacity to absorb the next hit better than it absorbed the last one, and the one after that better still. Most of cybersecurity, the budgets, the job titles, the vendor pitches, the dashboards on the wall, has been built to protect today. That focus is not wrong. It has just never been enough on its own. An adversary only ever has to win today, once, and move on to the next target. A defender has to hold all three time horizons at once, today, tomorrow, and the future, continuously, for as long as the organization exists. That imbalance is not a technology gap that a better tool closes. It is a defender’s job, not an attacker’s, and it is exactly where this framework insists the industry’s attention now has to widen.
Put as three questions instead of three domains, the whole architecture reduces to this. Today, do we actually know our exposure, right now, not last quarter’s version of it. Tomorrow, can we think and decide faster than the adversary is moving, not by reacting quicker but by having already decided before the pressure arrives. And whatever happens next, will the organization come back more resilient than it went in, not merely restored to where it stood before. Detection and Response answers the first question, because nothing else in the Compass can protect exposure it cannot see. The CROC answers the second, because winning the thinking race means never entering it as a footrace at all. Cyber Resilience answers the third, not as a hope stapled onto the end of an incident report, but as a design commitment the organization makes to itself before it is ever tested.
The Rhythm That Connects Strategy to Execution: CyberRiskOps
If the Compass gives direction and the CRML gives structure, CyberRiskOps is the discipline that gives it rhythm. CyberRiskOps is not best understood as a framework. It is the operating system of modern cyber resilience, the continuous practice of identifying, contextualizing, prioritizing, mitigating, verifying, and monitoring exposure across a digital ecosystem that never holds still.
CyberRiskOps exists because of a question that keeps surfacing from CISOs at large institutions, at more than one, in more than one sector. How do we stop being reactive and start controlling our cyber risk landscape? The plain answer is that you cannot control what you only assess twice a year. CyberRiskOps replaces the periodic checklist with continuous operations, the same way DevOps replaced periodic software releases with continuous delivery. Cyber risk scoring becomes dynamic instead of quarterly. Controls are monitored for effectiveness, not just existence. The conversation moves from what was our top cyber risk last quarter to what is our cyber risk right now and how is it trending.
The Road, Not Just the Destination: A Maturity Path
A framework that only describes the destination leaves the CISO with no answer to the first question the Chief Financial Officer (CFO) will ask: where are we today, and what changes next. So the Compass is paired with a maturity path, the Cyber Risk Operational Model, that plots two things together, how exposed an organization is and how operationally mature its cyber risk practice has become.
At the bottom sits an organization that does not manage cyber risk at all. It is not necessarily reckless, it simply has no visibility, no cyber risk owners, no telemetry. The next stage is the spreadsheet stage, where a few concerned people in IT or compliance try to track cyber risk with Excel and email threads, reviewed occasionally, already stale by the time anyone reads it. Above that sits the heat map stage, the one most organizations mistake for maturity, offering the illusion of control through color rather than the substance of measurement.
An organization stuck building the same maximum defense around every asset is not being careful, it is being expensive and unprotected at the same time. Spend gets spread evenly across low-value and high-value assets alike, which means the assets that matter most end up no better defended than the ones that do not, just more heavily billed for. A cyber risk practice guided by the CRML’s own asset-valuation step routes the heaviest investment toward what actually matters and pulls back where the spending was never buying real cyber risk reduction to begin with. The same budget protects more, because it protects the right things harder. This is the economic case underneath the maturity path, not just the operational one.
The real inflection point is the next stage, where CyberRiskOps is adopted and cyber risk scoring finally becomes dynamic, fed by live telemetry rather than a calendar. From there, an organization becomes operationalized, the stage where the CROC stands up as a real function and cyber risk becomes an input into everyday decisions across IT, security, and the business. At the top sits the proactive stage, where a mature CROC functions as a strategic control tower, cyber risk is forecast rather than merely tracked, and the organization can commit to digital initiatives its competitors hesitate over, because it can see the exposure and manage it continuously.
Each stage builds on the one before it. Skipping stages does not accelerate the climb, it just means the organization is operating a CROC without the CRML discipline underneath it, or running CyberRiskOps without anyone accountable for the loop. The maturity path is not a scorecard to feel good about. It is a diagnostic for exactly which piece of the architecture to build next.
Who Owns the Loop: Governance Is Not a Footnote
None of this works if the wrong person owns it, an argument that belongs inside this framework rather than beside it, because a Compass without an owner is a diagram, not a system.
Every organization depends on three layers to sense, interpret, and act on cyber risk. An analytical layer that interprets telemetry and signals. A meaning making layer that translates those signals into business priority. An instinctive layer that triggers the actual response. When the CISO reports through IT, all three layers get bent through a technical lens built to prioritize uptime and budget rather than exposure and business impact. Signals get misread. Priorities get diluted. Reflexes slow down. This is not a talent problem or a tooling problem. It is a wiring problem, and it produces exactly the kind of organizational paralysis that turns a contained incident into a headline.
The Compass makes the fix concrete rather than aspirational. When the CISO sits at the executive level, the three domains, the CRML, and the CROC stop being a security department’s internal process and become an instrument the whole leadership team actually uses. Every reduction in exposure should translate into a measurable gain in cyber resilience, and every lesson from a breach should realign the Compass to the organization’s evolving reality. That translation only happens when the person accountable for the Compass has the authority to act on what it shows.
Where the Compass Meets a Framework Boards Already Know
Some readers will ask how this squares with the framework most boards already reference, NIST’s CSF 2.0. The relationship is complementary, not competing, and that was never an accident. The CRML took shape shortly before NIST released CSF 2.0, and the two solve different problems on purpose. CSF 2.0 names outcomes, govern, identify, protect, detect, respond, recover, and deliberately stays silent on how an organization achieves them, because a framework that tried to prescribe implementation for every sector and size would collapse under its own specificity. CSF 2.0 tells an organization what good looks like. The Compass, run through the CRML and CyberRiskOps, is how an organization actually gets there and keeps moving once it arrives.
The alignment goes deeper than convenience. CSF 2.0 places GOVERN at the center of its own wheel, informing the other five functions, which is the same argument this framework makes about who owns the loop. Neither treats governance as a compliance step sitting beside the real work. Both treat it as the thing that decides whether the real work happens at all.
Even the maturity language lines up without duplicating. CSF 2.0’s Tiers, Partial, Risk Informed, Repeatable, and Adaptive, describe how rigorously an organization governs cyber risk. The maturity path underneath the Compass describes something one level down, how operationally the organization actually runs cyber risk day to day. An organization can score well on Tiers and still have no CROC. The two measurements answer different questions, and an organization serious about cyber resilience needs both answered honestly.
The Loop Runs on Data It Must Own
There is a dependency in all of this that is easy to skip past and expensive to ignore. The Continuous Defense Loop between the CROC and the SOC, described below, only functions if both sides are reasoning from the same trustworthy signal. That depends on what this framework calls the Data Ownership Ratio, the proportion of an organization’s security relevant telemetry that it actually creates and owns, rather than imports as someone else’s exhaust.
A platform reasoning mostly on native, owned telemetry, especially across endpoint, email, and network, the three domains where an attacker must eventually reveal themselves, produces coherent, continuous understanding. A platform reasoning mostly on imported logs inherits someone else’s blind spots, someone else’s delays, and someone else’s meaning. The goal is not to own everything, which is not realistic in a distributed environment. The goal is balance, a Golden Ratio between owned depth and external breadth, enough native signal to give the loop a backbone, enough external context to keep it from becoming insular. Without that balance, the CROC predicts without validation, the SOC reacts without context, and the loop that is supposed to learn from itself has no memory to learn with.
Making the Compass Countable: CRI and CRQ
Direction and process still need a number a CFO can act on, which is where measurement enters the architecture. A live Cyber Risk Index (CRI) turns exposure into a single score that moves the way a financial metric moves, built from how likely a threat is to succeed against a given asset and how much damage that asset’s compromise would actually cause. That likelihood and impact calculation draws on real attack telemetry, known exposures, and the state of existing controls, so the score reflects what is actually happening rather than what happened last quarter.
Underneath that headline number sits a second layer of discipline, Cyber Risk Quantification (CRQ), which expresses exposure in the language a board already trusts, financial terms. Rather than a single guess, a defensible quantification model expresses a likely range of financial loss for a defined cyber risk scenario, built from the frequency an attack of that type is likely to occur and the monetary loss it would cause if it did, modeled through simulation across thousands of plausible outcomes rather than a single point estimate. This is what allows a security leader to walk into a budget conversation and say, this control is worth funding because it moves our likely loss range from this number to that one, rather than because it feels prudent.
The two work together inside the Compass. The CRI tells the CROC and the CROC’s leadership where exposure is concentrated today. CRQ tells the CFO what that exposure is actually worth in dollars, which is the only language that reliably wins budget arguments and board attention. Neither replaces the judgment the Compass provides. Both make that judgment countable.
Neither number means much floating on its own. Both need a third reference point, a cyber risk appetite the board has actually agreed to, a stated ceiling rather than an implied one. And the CRI itself reads better as two numbers than one. An altitude and a trajectory are not the same question, and treating them as one is how organizations get surprised. The altitude is where exposure sits today against that ceiling. The trajectory is whether the mitigation work already underway is closing the gap or falling behind it, visible before the next reading confirms which. A CROC watching only altitude learns about a widening gap the same day the board does. A CROC watching the trajectory alongside it sees the gap opening while there is still time to close it.
There is a third reading past altitude and trajectory, and it looks forward instead of at the present. Modeling user and endpoint behavior against historical incident patterns can put a probability on which specific machines are heading toward a specific class of infection weeks before anything actually happens. That is a genuinely different capability from either the CRI or CRQ, since neither one claims to see forward, only to describe now or to price now more precisely. A CROC that only reads exposure today is still, in a real sense, describing the recent past. A CROC that can also read where behavior is heading is the only one that earns the word proactive rather than merely claiming it. This is still forecasting exposure, not forecasting the storm itself. It says which machine is drifting into rougher water, not which campaign will find it or when. The needle still refuses to name next week’s storm. It only insists on reading the drift before the storm arrives.
The Asymmetry the Adversary Has Always Had
Everything described so far assumes an organization racing against itself, getting more disciplined, more continuous, more governed. That is only half the picture. The other half is that the game was never designed to be fair, and no framework, including this one, changes that fundamental ratio.
An organization has to defend every asset, every identity, every access path, every vendor connection, all at once, continuously, indefinitely. An adversary only has to find one opening, once. The defender must be right every time. The attacker only has to be right once. What the Compass changes is not that ratio, nothing can. It changes how visible the openings are, how quickly the anomaly gets caught, and how fast the organization contains the damage and keeps moving.
The asymmetry runs through decision speed as much as it runs through exposure. A defender operating inside real governance has to evaluate, validate, and coordinate before acting, because the organization has a business to run while it protects itself. That deliberation is not a flaw, it is the cost of being accountable to customers, regulators, and a board. An adversary carries none of that cost. It does not need consensus. It does not need to justify a decision to a stakeholder with a different cyber risk tolerance. It only needs to act. Early in an intrusion, a careful human decision can still outperform a fast one, because the situation is still constrained enough for judgment to add real value. That advantage does not last. Every additional unit of precision a defender buys costs time, and time is the one resource an adversary is always spending in its own favor. There is a point in nearly every incident where the attacker’s tempo overtakes the defender’s decision speed, and once that point passes, the race is no longer close.
This is exactly why the Compass insists on deciding before the pressure arrives rather than deciding faster under it. A decision made in the CROC, calmly, ahead of an incident, never has to win a speed race during one, because it was never entered into that race to begin with. Precision under pressure is a losing strategy against an adversary that carries no pressure of its own. Precision before pressure is not.
The Perimeter Runs Through Every Supplier
Everything described so far has been architecture for managing exposure inside the walls an organization controls directly. None of it stays inside those walls. Every organization operates inside a supply chain of suppliers, developers, integrators, and service providers, and an exposure inherited from any one of them is still the organization’s exposure to carry, whether or not the organization saw it coming.
Cybersecurity supply chain risk management is not a separate discipline bolted onto the Compass. It is the same CRML discipline applied to counterparties instead of internal assets. Know which suppliers touch which critical process and prioritize them by criticality. Understand what each one could expose you to before the relationship starts, not after. Assess and monitor that exposure continuously over the life of the relationship, the same way an internal system would be assessed, because a supplier’s posture changes with or without your knowledge. Plan for what happens after the relationship ends, since exposure does not end when the contract does.
A vendor’s breach is not a footnote for the compliance team, it is a cyber risk event that belongs inside the same Cyber Risk Index your own systems feed. Organizations that ring-fence third-party risk into an annual questionnaire are running a heat map by another name, static, occasional, and blind at the exact moment it matters. A CROC that only watches internal telemetry is watching half the attack surface it is responsible for.
The Storm Was Never Just Inside Your Own Walls
The asymmetry above is structural and permanent, as true a decade ago as it is today. What has changed is the adversary itself. The ocean now has a current pushing back that no longer tires, sleeps, or works alone.
For thirty years, every defense we built quietly assumed the attacker was human, with human limits. A person gets tired. A person can only run so many operations at once. A person can be arrested. An agentic adversary has none of those limits. It reads everything public about your organization and turns it into a tailored lure in minutes, work that once took a skilled operator weeks. It decides and acts inside the same breath, closing the gap defenders once had to prepare a response in. It persists without needing to sleep, and it scales at essentially no additional cost, because running the operation against one target or ten thousand costs the adversary the same effort.
This changes what governing the Compass actually requires. It is no longer enough to extend trust to a system because it is present, because it sounds legitimate, or because it claims a role, since an adversary’s agent can wear a uniform you issued and act from inside your own walls. Identity between systems has to be proven and re-proven at every handoff, the same discipline Zero Trust always demanded of people, now extended to every agent acting on the organization’s behalf. The answer to an adversary that finishes before you notice cannot be a faster reaction. It has to be a decision made earlier, upstream, in the CROC, before the race has a chance to start.
Closing the Loop: Where CROC, SOC, and the Compass Meet
The whole intention behind this framework can be said in a single line. Hold two different questions at once, answer both continuously, and never mistake one for the other. The first question is when, today, tomorrow, or the future, the clock that never stops advancing regardless of who is watching it. The second question is which way, proactive and predictive, reactive and defensive, or recover and improve, the compass reading that tells an organization what to actually do at whatever hour the clock reads. Most cybersecurity programs answer only one of these. They know the hour, mid-incident, say, but have no compass reading to act on once they know it. Or they know a direction that matters to them, prevention, say, and lose track of what hour it actually is everywhere else in the estate. A clock without a compass tells an organization when without telling it what to do. A compass without a clock does not know what moment it is answering for. The two have to turn together, because the hour and the direction change at the same instant, and an organization reading only one of them is navigating half blind. Guiding an organization through both dimensions at once, continuously, for as long as the organization exists, is the entire purpose this framework was built to serve.
The Compass, the CRML, and CyberRiskOps are not three competing ideas. They are one system described from three angles. The Compass gives the direction. The CRML gives the process. CyberRiskOps gives the tempo. And the point where all three become visible in daily operations is the Continuous Defense Loop between the CROC and the SOC.
The CROC governs intent. It continuously translates exposure, asset criticality, and cyber risk signals into decisions that are made calmly, before pressure arrives. The SOC enforces that intent at speed, because the priorities were already set upstream. Every incident then feeds back into the CROC, sharpening the next cyber risk score, refining the next assumption. This is not two teams cooperating. It is one loop, learning from itself, tightening with every cycle. Cyber Resilience is what that loop produces over time, not a capability an organization buys, but an outcome it earns by running the loop honestly, cycle after cycle.
Cybersecurity is not a project with an end state called secure. There is no such state. The organizations that understand this stop chasing a finish line and start building a system that gets stronger every time it is tested. That is what the Cybersecurity Compass Framework is built to do, run through the CRML, staffed by a governed CROC, paced by CyberRiskOps, grounded in owned data, made countable by the CRI and CRQ, extended through every supplier, honest about the asymmetry it can never erase, and aimed at an adversary that no longer rests. Not to make the storm smaller. To make sure the needle never stops pointing somewhere true.
References
Balduzzi, M., Reyes, R., Balaquit, J., Flores, R., and Zigh, B. Forecasting Future Outbreaks: A Behavioral and Predictive Approach to Proactive Cyber Risk Management. TrendAI Research. https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/forecasting-future-outbreaks-a-behavioral-and-predictive-approach-to-proactive-cyber-risk-management
TrendAI Research. More Than a Number: Your Cyber Risk Index Explained. TrendAI Technical Report, April 2026. https://www.trendmicro.com/content/dam/trendmicro/global/en/core/docs/report/rpt-risk-score-explained.pdf
TrendAI Research. Understanding and Empowering Security Decisions: Cyber Risk Quantification (CRQ) Explained. TrendAI Technical Report, April 2026.
Boehm, J., Curcio, N., Merrath, P., Shenton, L., and Stähle, T. The Risk-Based Approach to Cybersecurity. McKinsey & Company, Risk Practice, October 2019. https://www.mckinsey.com/~/media/McKinsey/Business%20Functions/Risk/Our%20Insights/The%20risk%20based%20approach%20to%20cybersecurity/The-risk-based-approach-to-cybersecurity.pdf
National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29, February 26, 2024. https://doi.org/10.6028/NIST.CSWP.29
Castro, J. (2024). Safely Sailing the Digital Ocean with the Cybersecurity Compass. ResearchGate. https://www.researchgate.net/publication/387410177 DOI:10.13140/RG.2.2.20696.00003
Castro, J. (2026). The Same Compass, a Different Ocean, Different Storms. ResearchGate. https://www.researchgate.net/publication/409261097 DOI:10.13140/RG.2.2.19705.63843
Castro, J. (2024). From Definition to Action: Measuring and Managing Cyber Risk. ResearchGate. https://www.researchgate.net/publication/388653064 DOI:10.13140/RG.2.2.15858.21448
Castro, J. (2024). Navigating the Lifecycle of Cyber Risk Management: A Strategic Blueprint. ResearchGate. https://www.researchgate.net/publication/388421392 DOI:10.13140/RG.2.2.14793.25447/1
Castro, J. (2024). From Reactive to Proactive: The Critical Need for a Cyber Risk Operations Center (CROC). ResearchGate. https://www.researchgate.net/publication/388194441 DOI:10.13140/RG.2.2.27408.93445/1
Castro, J. (2025). Cyber RiskOps: Bridging Strategy and Operations in Cybersecurity. ResearchGate. https://www.researchgate.net/publication/388194428 DOI:10.13140/RG.2.2.36216.97282/1
Castro, J. (2025). Cyber Risk Operational Model (CROM): From Static Risk Mapping to Proactive Cyber Risk Operations. ResearchGate. https://www.researchgate.net/publication/390490235 DOI:10.13140/RG.2.2.15956.92801
Castro, J. (2025). How a Cyber Risk Index (CRI) Can Be Used as a KPI in Your Cybersecurity Strategy. ResearchGate. https://www.researchgate.net/publication/389001302 DOI:10.13140/RG.2.2.32915.18728
Castro, J. (2025). Logs Telemetry and the Golden Ratio: Why the Data Ownership Ratio Will Redefine Cybersecurity Architecture and Cyber Risk Management. ResearchGate. https://www.researchgate.net/publication/397677257 DOI:10.13140/RG.2.2.21403.53288
Castro, J. (2026). The CISO Reporting Structure Is the Starting Point of Cyber Resilience Failure. ResearchGate. https://www.researchgate.net/publication/408316374 DOI:10.13140/RG.2.2.14467.67362
Castro, J. (2026). The SOC Protects Today. The CROC Protects Tomorrow. ResearchGate. https://www.researchgate.net/publication/408847696 DOI:10.13140/RG.2.2.17257.86884
Castro, J. (2026). Defending Agentic Systems: Six Powers Your Defenses Were Never Built to Stop. ResearchGate. https://www.researchgate.net/publication/406107002 DOI:10.13140/RG.2.2.32546.59840/1
Castro, J. (2026). Six Powers in the Hands of the Adversary: When the AI Agent Becomes the Attacker’s Best Hire. ResearchGate. https://www.researchgate.net/publication/406344684 DOI:10.13140/RG.2.2.23908.95361
Castro, J. (2026). Rethinking Zero Trust for the Agentic AI Era. ResearchGate. https://www.researchgate.net/publication/406634241 DOI:10.13140/RG.2.2.17165.29924
Castro, J. (2026). Cybersecurity: The Infinite Chess Game. ResearchGate. https://www.researchgate.net/doi/10.13140/RG.2.2.33672.58886 DOI:10.13140/RG.2.2.33672.58886
Castro, J. (2025). Attackers Only Need to Be Faster Than Our Decision Making Process. ResearchGate. https://www.researchgate.net/publication/398971490 DOI:10.13140/RG.2.2.14817.98404
Castro, J. (2025). Cybersecurity Paralysis When the Cyber Brain of the Organization Breaks. ResearchGate. https://www.researchgate.net/publication/397927310 DOI:10.13140/RG.2.2.25955.00802/1



