Skip to content

Cybernance

Austin-based cyber risk governance platform built on the NIST Cybersecurity Framework, giving boards and executives a maturity-scoring system for oversight and regulatory compliance.

Visit Website ↗ + Add to Compare
40/100Emerging / Unranked

Overview

Cybernance, founded in Austin, Texas in 2016 by Mike Shultz, Bob Barker and Charlie Leonard, sells governance rather than detection: its platform, built around a proprietary Cybergovernance Maturity Oversight Model (CMOM) mapped to the NIST Cybersecurity Framework, is meant to give corporate boards and executives a structured way to assess and document an organization’s cyber risk posture across people, process and policy — not to monitor a network or catch an attacker.

The company has kept the platform aligned with the current version of the framework, updating to NIST CSF 2.0, and has picked up several third-party distribution and integration relationships: a collaboration with insurance broker Lockton Companies, availability of Cybernance’s audit capability through Finastra’s FusionStore marketplace for financial institutions, and reported use by Texas school districts working to meet state-mandated cybersecurity requirements. Those partnerships are a more useful signal of real adoption than the company’s own marketing, given that Cybernance remains a small team by industry standards.

One caution worth flagging directly: at the time of this review, Cybernance’s own public website showed signs of neglect, including what appeared to be injected spam content unrelated to the company’s business — a notable observation for a vendor whose entire pitch is disciplined cyber governance. For CISOs, Cybernance is a reasonable low-cost option for board-level NIST CSF governance reporting, particularly where a Lockton or Finastra relationship already exists, but the state of its own web presence warrants direct diligence on the vendor’s current operational rigor before relying on it for regulatory documentation.

Innovation Matrix Assessment

Innovation Velocity 4/10

The platform has been updated to align with NIST CSF 2.0 and gained a Finastra FusionStore marketplace listing, showing some continued development, though at a modest pace consistent with a small team.

Operational Value 4/10

Nearly a decade of operation with a small (roughly 11-50 person) team is a moderate track record; the company's own website showing signs of neglect, including apparent injected spam content observed during this review, is a direct, negative data point on current operational rigor for a governance-focused vendor.

Market Momentum 4/10

New distribution relationships (Lockton Companies, Finastra FusionStore, reported use by Texas school districts under state cybersecurity mandates) suggest incremental channel traction, but reported revenue (~$1.8M as of 2021) and headcount remain small.

Category Disruption 3/10

A NIST-CSF-mapped board governance and maturity-scoring platform is a well-established category with several competitors; Cybernance's proprietary CMOM model is a reasonable implementation rather than a novel approach.

Real-World Efficacy 3/10

Third-party distribution deals (Finastra, Lockton) provide some independent validation of the product's usefulness to those partners' customer bases, but the observed state of Cybernance's own public website undercuts confidence in the vendor's current operational and security hygiene.

Enduring Relevance 6/10

Board-level cyber risk governance mapped to NIST CSF remains relevant given SEC cyber-disclosure requirements and state-level K-12 and public-sector cybersecurity mandates like the one reported in Texas.

Why CISOs Should Care

Offers a low-cost, NIST CSF-aligned way to generate board-ready cyber risk maturity reporting, useful for organizations that need governance documentation but lack the budget for larger GRC platforms.

What Makes It Different

A proprietary Cybergovernance Maturity Oversight Model (CMOM) purpose-built for board and executive-level reporting, distributed through insurance-broker (Lockton) and core-banking marketplace (Finastra) channels rather than sold as a standalone enterprise GRC suite.

The Matrix Verdict

40/100 — EMERGING / UNRANKED

A small, low-cost NIST CSF governance tool with some genuine third-party distribution traction, but the poor state of the company's own public website at the time of this review is a real caution flag that buyers should weigh against its governance-focused value proposition.

Editorial Note: Claims vs. Verified Findings

Partnership claims (Lockton, Finastra FusionStore, Texas school district usage) are drawn from company press releases and were not independently confirmed with the named partners; the observation regarding the state of Cybernance's own website (stale content, apparent injected spam) was directly observed during this research rather than reported by any third party, and is flagged here as an independent, verifiable finding rather than a vendor claim.

Sources