Methodology & Limitations
This page describes how Praevyn produces a cybersecurity maturity grade, what its outputs represent, and — importantly — what they do not represent. Reviewers, boards, insurers and auditors should read this page before relying on any Praevyn report.
What Praevyn is
An executive-ready cybersecurity maturity assessment grounded in recognized frameworks.
Praevyn is a decision-support platform. It structures a self-assessment across eleven control domains and produces a grade, a set of findings, and a prioritized roadmap referenced to recognized cybersecurity guidance.
What Praevyn is not
- It is not a certification, audit, or attestation.
- It is not legal, regulatory or insurance advice.
- It is not a penetration test, vulnerability scan or technical assessment of live systems.
- It does not guarantee compliance with any law, framework, contract or insurance policy.
- It does not guarantee insurance eligibility, coverage, pricing or acceptance of submitted evidence.
Scoring methodology
Deterministic scoring with framework-referenced recommendations.
Each question has a defined weight and, where applicable, a critical-finding penalty. Category scores are calculated from the weighted proportion of controls answered favorably, less any critical-finding penalties. The overall grade is a weighted average of category scores. Grades map as follows:
- A: 90–100 (Low risk)
- B: 80–89
- C: 70–79 (Moderate risk)
- D: 60–69 (High risk)
- F: below 60 (Critical risk)
Scoring is deterministic: the same answers always produce the same grade. The AI layer is used only to explain findings and draft narrative recommendations; it does not change the score.
Frameworks referenced
Findings and recommendations reference recognized cybersecurity guidance so reviewers can trace each item back to its source. Frameworks referenced include:
- NIST CSF 2.0
- NIST SP 800-53
- NIST SP 800-61 Rev. 3
- NIST SP 800-171
- CISA Cross-Sector CPGs
- CIS Controls v8
- OWASP Top 10
- FTC Safeguards Rule
- Microsoft Security Baselines
- AWS Well-Architected (Security Pillar)
- Azure Security Benchmark
- Google Workspace security guidance
Referencing a framework is not the same as certifying compliance with it. Formal compliance requires an independent assessment by a qualified party.
Worked example: from assessment answer to remediation
To demonstrate that framework references are backed by concrete mappings — not marketing breadth — the following worked example traces a single assessment response through every stage of the Praevyn lifecycle. Every finding on the platform is produced by an equivalent chain.
- Step 1 — Assessment responseIdentity & Access domain, question IAM-04:“Is phishing-resistant multi-factor authentication enforced for all administrators and privileged accounts?”Reviewer answers: No. Weight: 3 (high). Critical-finding flag: yes.
- Step 2 — FindingF-IAM-04: Privileged accounts lack phishing-resistant MFA.Deterministically generated from the negative response; the AI layer only drafts the human-readable narrative.
- Step 3 — RiskR-2025-014: Account takeover of a privileged identity.Auto-created in the Risk Register with likelihood High, impact Severe, inherent score 20/25.
- Step 4 — Control mapping
- NIST CSF 2.0 — PR.AA-02, PR.AA-03
- NIST SP 800-53 Rev. 5 — IA-2(1), IA-2(2), IA-2(11)
- CIS Controls v8 — 6.3, 6.5
- CISA Cross-Sector CPGs — 2.H (Phishing-Resistant MFA)
- ISO/IEC 27001:2022 — A.5.17, A.8.5
- FTC Safeguards Rule — § 314.4(c)(5)
- Step 5 — RecommendationEnforce FIDO2/WebAuthn (security keys or platform passkeys) for every administrator, break-glass and service-owner account; disable SMS and voice OTP as fallback for privileged roles.
- Step 6 — Evidence sourceIdentity provider conditional-access export (e.g. Entra ID / Okta) showing the phishing-resistant authentication-strength policy scoped to the privileged-role group, plus a screenshot or CSV of enrolled authenticators. Attached to the remediation record with SHA-256 hash, uploader and timestamp.
- Step 7 — Remediation taskTask REM-014 assigned to the IAM owner with a 30-day due date. On completion the owner records a resolution note (> 20 characters); the risk transitions to Mitigated, the finding is marked Remediated, the next assessment re-tests IAM-04, and posture metrics, framework alignment and the executive report update accordingly.
Every assessment answer follows this same seven-step chain — response → finding → risk → control mapping → recommendation → evidence source → remediation task — so any framework reference in a Praevyn report is traceable back to a specific question, a specific control identifier, and a specific piece of evidence.
Cyber-insurance readiness summary
Provides a directional view of commonly requested security controls. Coverage, pricing and evidence requirements are determined independently by each insurer and broker.
Praevyn does not guarantee insurance eligibility, coverage, pricing or acceptance of submitted evidence.
Data sources and reliance on inputs
Results are calculated from answers submitted by the organization being assessed. Accuracy depends on the reviewer's knowledge of the environment and the quality of the evidence available. Praevyn does not independently verify the answers provided.
Environments change. A grade reflects the state of controls at the point in time the assessment was completed and should be re-run when the environment, workforce or regulatory scope changes materially.
Role of AI in the platform
Language models are used to help draft explanations, remediation narratives and responses in the AI assistant. Model outputs may contain errors and should be reviewed by a qualified reviewer before acting on them. AI output does not alter the deterministic score.
Appropriate use
Praevyn is intended to help organizations understand their cybersecurity posture, prioritize remediation, and prepare materials for internal stakeholders, boards, brokers and insurers. It is not a substitute for qualified professional advice or an independent audit.
Platform disclaimer
Praevyn is a cybersecurity maturity decision-support platform. It does not provide certification, legal advice, a penetration test or a guarantee of compliance or insurance eligibility.
