Cyber Governance Risk & Compliance, built for the 80%
Minimum Viable Protection: Where Cyber Risk Appetite Meets Cyber Security Posture
Minimum Viable Protection (MVP) is a cyber governance, risk and compliance (GRC) platform that solves a problem almost every organisation has and almost none have solved: knowing how much cyber risk the board is willing to carry, and whether the security controls actually in place match it. MVP is a world first. It is the only platform that establishes, scores and contrasts an organisation's cyber risk appetite against its measured cyber security posture.
Scoring cyber risk appetite starts with the board & exec
MVP begins where cyber security should begin, in the boardroom. Directors and executives complete a structured online questionnaire that scores the organisation's cyber risk appetite across four dimensions: revenue, reputation, regulation and personally identifiable information (PII). The output is a defensible, numerical statement of how much risk the leadership team is prepared to accept, expressed in language the board owns rather than jargon it tolerates.
Measuring cyber security posture against recognised standards
The platform then measures where the organisation actually stands. A 20 question maturity assessment, aligned to ISO/IEC 27001:2022, the NIST Cyber Security Framework (CSF) and CIS Controls v8, produces a cyber security posture score on the same scale as the risk appetite score. For the first time the two numbers sit side by side, and the gap between them becomes visible, measurable and impossible to argue with.
A remediation plan ranked by criticality
Closing that gap is the point. MVP generates a remediation plan that ranks every action by criticality and targets a posture at or slightly above the agreed risk appetite. Reach that point and the organisation has achieved Minimum Viable Protection: appropriately secure, evidenced, and no longer guessing. A built in auditor function lets an internal or external assessor be invited in to review the evidence loaded against each required control, confirming that what is claimed is genuinely in place and meets the required standard.
Built for the 80 percent
MVP is deliberately scoped. It is not built for the five percent of the market pursuing formal accreditation against a major standard, nor for the fifteen percent too small to warrant a structured cyber risk programme. It is built for the 80 percent of organisations worldwide who simply need to be appropriately secure, and who have never had a credible way to define, reach or prove that position. It’s built so that Directors, Execs and IT teams can sleep well at night, knowing they have achieved an appropriate cyber posture.
Alignment is the real achievement
The platform's breakthrough is alignment. MVP puts boards, executives and technical IT teams on the same page, working from the same scores toward the same target. Internal IT functions and managed service providers (MSPs) gain a governance backed rationale for the tools they recommend, which demolishes sales cycles and removes guesswork from security investment decisions. Every stakeholder, from the chair to the systems administrator, is finally pulling toward a common goal. No other cyber GRC platform has achieved that.
Find your MVP
Cyber security is a basic necessity for everyone, no matter the budget. And we feel passionately about that. You’ll be pleasantly surprised at how little it could cost you to audit your cyber risk posture, and get security plans in place using our MVP method.
Minimum Viable Protection (MVP) does exactly what the name suggests. It is a complete assessment that seeks to lift mid-sized companies to achieve a minimum defensible cyber posture, unique to their organisation's requirements.
Using our tried-and-tested MVP framework, we’ll ensure your reputation stays intact, your revenue streams are secure, and you don’t fall foul of the
New Zealand Privacy regulators.
The MVP approach uses your industry and business type to rapidly assess your cyber security risk profile. We call this your MVP - Minimum Viable Protection. Your MVP is the minimum baseline your company needs to not be considered negligent.
This unique methodology saves our clients thousands by making sure they spend the right amount of money, in the right places. By quantifying your risk level first, we make sure you’re not over-investing and your revenue, reputation and regulatory exposure are protected at the minimum possible cost.
How We Do It
Risk Appetite
Calculating risk appetite is an important first step of risk assessment. How can you know where to start if you don’t know how much risk you are willing to take? This module of MVP looks at how much risk the organization is willing and able to take in pursuit of its strategies and business goals by providing a score based on six key criteria. This will also determine the level of granularity required for a Cyber Posture Assessment.
Cyber Posture
The next module of MVP looks at the overall current cyber posturing of an organization and allows us to find which areas are lacking with our gap analysis. This allows us to assist you with prioritizing your efforts towards the appropriate level of compliance to fit your budget and resources. Information Security compliance frameworks can be daunting, especially if this is all new to you. We’ve done the heavy lifting and simplified them down
Remediation
Taking the results from your Cyber Posture Assessment, we will create a report and action plan with costings that can be presented at your next board meeting. By performing gap analysis, we can assist you with prioritising your efforts towards the appropriate level of compliance to fit your budget and resources. We will work with you along every step of the way to achieve compliance and ensure that your business is adequately protected.
Try our FREE Risk Appetite Assessment tool!
We’ve turned the MVP Process into an online app!
Organisations of all shapes and sizes can use this tool to gain some understanding of areas of cyber risk, their current Risk Appetite, and associated scores.
Contact Us
Email
[email protected]
Phone
(09) 242 1418
Find Us
82 Symonds Street, Grafton,
Auckland, New Zealand 1010

