Including the parts that are not flattering. A product whose whole argument is that it tells you what you did not already believe cannot be coy about its own limits.
A model of your estate with known attack paths run against it. You describe what you have, what you cannot afford to lose, and which controls are in place and at what maturity. The engine runs 23 attack paths through that model and each one stops at the first control that holds it.
What you get back is which paths reach the things you cannot lose, where each was stopped and by what, and what changes if you raise a control. Not a severity score and not a list of findings.
No. Nothing is installed, nothing is scanned, no credentials are handed over and no cloud account is connected.
This is the clearest difference between BreachForge and most tools in this space, and it is deliberate rather than a limitation we grew into. Tools that connect to your cloud can prove more, and the cost is a security review, a procurement conversation and somebody inside your organisation with the authority to grant it. Plenty of organisations never get past that, and their exposure does not wait for them.
If you want the picture to rest on evidence rather than on your answers, you can upload configuration exports. Those are read in your browser and never sent anywhere.
The model you build is yours and stays in your account. Evidence uploads never leave your browser, so a Microsoft Secure Score export is parsed on your machine, compared against what you recorded, and the comparison is shown to you. The file is not transmitted, not stored and not retained.
Nothing you enter is used to train anything.
No, and nothing that models rather than attacks can. Nothing is executed against your systems, so nothing is proven in the sense a penetration tester means it.
A path reaching your customer records means your recorded controls do not stop it. It does not mean somebody has done it. Where a customer, an insurer or a certification scheme wants evidence that a specific weakness can be used, that is a penetration test and we will say so rather than talk around it.
What a model does instead is decide what is worth testing, so the fortnight you pay a tester for is spent on the paths that reach something rather than on a scope drawn around a budget.
Those four are on the product pages too, not buried here.
When you need proof. A customer, insurer or scheme asking for evidence that something is exploitable wants a penetration test.
When a certification names an independent test. Nothing modelled satisfies that, ours included.
When nobody can list what you are running. Start with discovery and a scanner. A model of an estate you cannot describe is a model of a guess, which is why the first thing the builder asks for is what you actually have.
A scanner tells you which software has a known flaw. It is automated, cheap and thorough, and it returns a list ranked by a severity score that cannot see which of your systems matters.
BreachForge tells you which of those flaws sit on a path to something you cannot lose. Most organisations already have the first answer and are stuck on the second. Four hundred findings ordered by score is not a plan; ordered by what they reach, it is.
It models exposure. Whichever label that attracts, the honest description is that it answers one question: if this attack ran against your estate as you have described it, how far would it get and what would stop it.
It is not adversarial exposure validation in the sense that term is increasingly used, because validation in that sense requires connecting to your environment and resolving what is actually permitted. That is a real capability and a real trade, and the trade is the access.
It is not control testing either. Nothing fires a payload to see whether your endpoint agent notices.
Categories in this market move faster than products do. What matters is whether the answer is useful and whether anybody has told you what it cannot do.
Probably, and we would rather say so. These are stages rather than alternatives. A scanner finds it, a model decides which of it matters, a test proves the ones that do, and the model updates when the fix lands.
If the budget stretches to one, it depends where you are. No inventory, start with a scanner. An inventory and a list you cannot prioritise, that is us. A regulator or a customer asking for evidence, that is a test, and no amount of modelling substitutes.
It is not a compliance tool and it does not produce an audit report. What it can tell you is how much of your exposure those schemes actually touch, and the answer surprises people.
The 115 controls in the engine are mapped to both. Measured against that mapping:
| Scheme | Of the 115 controls |
|---|---|
| Cyber Essentials | 21 are in scope |
| Cyber Essentials Plus | 10 are actually tested |
| ISO 27001:2022 Annex A | 115, all of them |
Cyber Essentials covers nothing at all in three areas: security operations, resilience and the human layer. It also misses eleven of the fourteen identity controls, including phishing-resistant multi-factor authentication and app consent governance.
That is not a criticism of the scheme, which is deliberately a baseline. It is the reason a certificate and a clear exposure picture are different things.
No. It is the same five technical controls, verified by an assessor with hands-on testing rather than self-declared. The difference is assurance, not scope.
So a CE Plus certificate means somebody tested patching, malware protection, the boundary firewall, local admin restriction and the hardening baseline on a sample of your devices. Everything else you hold is a claim.
Organisations of roughly fifty to five hundred people who cannot justify a full-time CISO, and the vCISO firms and managed providers who serve them.
For a provider, several named environments sit on one account, so you model each client separately and switch between them. The discovery phase of an engagement, the part that normally takes weeks of interviews and diagrams, becomes an afternoon of modelling that stays live afterwards rather than becoming a document.
This is the question behind most of the others, and it is getting worse. The average CISO tenure is now around eighteen months, and a survey of 1,001 security leaders across the US and UK in 2026 found half had considered leaving the profession over the pace of AI capability, with only a quarter disagreeing. Experienced people are retiring, moving to quieter roles or going into consulting, and the organisations left behind hire someone less experienced who then has to learn an estate from scratch.
That handover is a security event in itself. The picture of the estate usually lives in one person's head, supported by a report from the last engagement, and when they go it goes with them. The new arrival spends a quarter rebuilding an understanding that already existed.
A model does not leave. It is a description of your estate, your crown jewels and your controls that somebody else can open, read and re-run on their first week rather than their first quarter. Change a control, see which paths close. That is the whole handover.
Figures from CSO Online, 50% of CISOs see Mythos as a sign to exit the profession, September 2026.
Partly, and it is worth being precise about how much. Concern about personal liability among security leaders has risen to 78 per cent from 56 per cent a year earlier, and recruiters report that candidates now ask about indemnification and directors and officers cover before they ask about budget or headcount.
What BreachForge produces is a record of reasoning: what the estate looked like, which paths reached what, which change was chosen and what it closed. That is a defensible account of a decision at a point in time, and it is the thing people usually cannot produce after the fact.
It is not legal protection and we are not going to imply that it is. It does not indemnify anybody, it is not insurance, and no vendor artefact substitutes for advice from people who do that for a living.
An afternoon to model an estate for the first time, and seconds to re-run it after that. Changing a control and watching the paths change is the part a report cannot do, and it is why the picture is worth keeping after an engagement ends.
£8,500 a year at the founding rate, £10,500 standard. It is on the pricing page because a price you have to ask for is a price that varies by who is asking.
For comparison, a vCISO retainer is commonly two to four thousand pounds a month, so this is roughly a month of one, for a year, for the part of the work that does not need a person.
Saleem Yousaf, through Cyber Spartans Ltd. The scoring engine, the attack path library and the control set are the work of somebody who has spent a career doing this by hand and got tired of repeating the same weeks of discovery for every client.
Five scanners run against BreachForge itself on a schedule, and every finding that is not being fixed carries a written reason. We hold the shape of that picture in public because a product that asks you to record where you are exposed should be able to say where it is.
What is not published is the detail. Paths, line numbers and rule identifiers are a map for somebody else, and there is no version of publishing those that is anything other than careless.
Model it in an afternoon and watch 23 attack paths run against what you actually have. Nothing installed, no access, nothing to connect.
Book a demo Why modelling, at length