Which security capabilities matter for this threat?
Pick a threat, then build a capability stack. The ledger shows how the stack changes operating burden across the six CSF functions: steps absorbed, handoffs removed, detection stage shift, posture balance. Structural and ordinal claims only.
Which threat are you defending against?
1 of 21 selectedWhich capabilities are you evaluating?
3 of 9 selectedCapability impact matrix
Every position is counted from this threat's own ledger: across is how many distinct steps a capability affects, up is how many of those it takes off a human entirely. The dividing lines sit at the midpoint of this threat's range, so they move with the threat and are not a standard.
What the catalog cannot reach
This section ignores your stack. It asks what every capability category in the catalog could do for this threat if you owned all of them, which is a property of the catalog rather than of a selection, so it does not change as you toggle.
30 of 32 steps stay human whatever you buy.
Of the 32: 2 could be taken off a human by some category, 2 could only ever be accelerated so a person still acts, and 28 are untouched by anything in the catalog.
The floor is the base of a business case, not a verdict on importance. A step no capability can take off a human is not a low-value step; it is a step you will always staff.