For investors, vCSOs & the boards they answer to

Cyber risk, grounded in evidence.

Theodolite deploys a scanner inside the environment you're invited into — a portfolio company, a client — and turns verified cloud evidence into coverage-qualified observed checks, severity-ranked Top Priorities, and an evidence-backed decision view. CIS Controls v8; every finding backed by live cloud evidence.

30-minute call. No slides. Real evidence from a guided walkthrough.

Scroll

Current evidence sources and references

CIS Controls v8IRIS 2025AzureAWSSharePointBox (beta)Cyber Due Diligence

Assessment evidence sources

Cloud Evidence

AzureAWSEntra ID

Assessment Evidence

CIS Controls v8Due DiligenceExact Mapping

Data Discovery

SharePointBoxBlob & S3

Control Evidence

Observed ChecksCoverageTop Priorities

Theodolite

>

Illustrative example

Start with the question the evidence can answer

“What did the scan observe — and what could it not observe?”

A different approach to cyber risk.

Traditional

  • Siloed scans with no business context
  • CVSS scores that mean nothing to the board
  • Weeks to compile a risk report

With Theodolite

Illustrative
PRIORITIES12
Coverage: Partial
Findings: 847
Priorities: 12
  • Coverage-qualified observed checks and failures
  • Evidence-backed risk reporting
  • Revenue-band annual-loss benchmark for context

The Story Behind Theodolite

“I built Theodolite because no tool gave me what I needed in that boardroom: a clear line from cloud evidence to the security decisions we had to make.”

Nick Shevelyov, Founder

Founder, Theodolite & vCSO

15 years CSO, SVB

Author, “Cyber War…and Peace” — on translating cyber risk for boards

Cyber Risk Evidence Map

Every finding backed by live cloud evidence.

Access Intelligence

Review provider-observed direct access across Azure, AWS S3, SharePoint, and bounded-beta Box with explicit unknown states. Complete account-wide effective reach, sensitive-data reach, and blast radius remain held where policy coverage or exact-generation evidence is incomplete.

See directly observed access
Observed Provider Grants
5 example grants
Observed resource: backup-vault
MFA readiness: Unknown
External: No
Evidence: Direct Azure role assignment observed
Observed resource: finance-site
MFA readiness: Unknown
External: Yes
Evidence: Direct SharePoint grant observed
Observed resource: operations
MFA readiness: Not observed
External: No
Evidence: Direct Box collaboration observed
Observed resource: quarterly-plan
MFA readiness: Unknown
External: No
Evidence: Direct SharePoint group grant observed
Observed resource: board-packet
MFA readiness: Unknown
External: Yes
Evidence: Direct Box shared-link evidence observed
Derived blast-radius analysisHeld
Assessment Evidence · Illustrative
1AUTO MAP
Asset InventoryMapped
Access ControlManual review
Risk AssessmentManual review
MonitoringManual review
1
Auto map
208
Review
209
Questions

Assessment Evidence

Work from a 209-question master — 153 CIS Controls v8 and 56 cyber due-diligence questions. One favorable mapping is currently release-enabled when exact, current evidence supports it; the rest require review.

Discuss the guided workflow

Data Discovery

Scan Azure, AWS, SharePoint, and bounded-beta Box for PII, PHI, and credential indicators. Raw findings and detailed scan output remain stored in the customer-side scanner database, not the control plane.

See what a scan surfaces
Illustrative Data Discovery
3 providers
prod-user-uploads
3.1 TB412PII
backup-db-exports
2.8 TB567PII
config-secrets
240 GB264CRED
patient-records
1.4 TB523PHI
hr-documents
890 GB241PII
analytics-raw
810 GB127PII
Finance – Board Packs
680 GB145PII
HR – Onboarding
420 GB89PII
Illustrative scanned volume12.4 TB

How it Works

Three Steps. One Report.

Connect

Analyze

Act

CriticalHighHighMediumLowPrioritizing findings...
Actions Required

Stop Guessing.
Start With Evidence.