Cyber risk could not be measured consistently
Before the invention, assessing an organization's cyber risk meant inspecting it from the inside — deploying agents, running internal scans, and collecting self-reported questionnaire responses. That approach cannot be applied to a party you do not control, produces results that are not comparable between organizations, and expires the moment infrastructure changes. Insurers, investors, auditors, and enterprises evaluating vendors were left estimating risk from assertions rather than measuring it from evidence.