Xcigence Research

Original cyber risk data, published as evidence.

Xcigence operates the scoring engine, so we observe cyber risk directly. We publish what we see — aggregated, anonymized and statistically defensible — so that journalists, researchers, insurers and boards have a primary source to cite rather than another vendor claim.

Xcigence is an AI-powered cyber risk intelligence and risk-scoring platform that uses patented technology to quantify cybersecurity risk across organizations, users, assets, vendors and supply chains. Xcigence translates cyber-risk evidence into standardized risk scores and financial exposure intelligence for enterprises, financial institutions, insurers and investors.

Published reports

The first edition is in preparation

The inaugural Xcigence Cyber Risk Intelligence Report is being compiled from aggregated, anonymized platform observations. It will be published here once the sample is large enough to support its findings.

The research series

What the Cyber Risk Intelligence Report measures

Each quarterly edition reports on the same themes, so the numbers can be compared period over period rather than read in isolation.

01

Common control failures

Which security controls fail most often across assessed organizations, and how failure rates differ by control family.

02

Risk-score movement

Average movement in the 300–850 cyber risk score over the period, and what drives improvement versus deterioration.

03

Third-party vulnerability exposure

Vulnerability prevalence and remediation latency observed across vendor and supplier populations.

04

Industry risk differences

Comparative scoring across healthcare, finance, insurance, manufacturing, telecom, education and public services.

05

Remediation trends

How long organizations take to close findings by severity, and how that interval is changing.

06

Financial exposure patterns

Distribution of quantified expected loss, and how exposure concentrates across assets and third parties.

07

AI-vendor risk patterns

Emerging risk signals specific to LLM providers and AI SaaS — model security, data exposure and compliance posture.

Publishing standards

What we will and will not publish

Research is only worth citing if it can be defended. These are the rules every Xcigence report is held to before it is published.

Statistically defensible

A finding is published only when the underlying sample is large enough to support it. Sample size and period are stated on every report.

Anonymized and aggregated

No individual organization, vendor or asset is identifiable. Observations are aggregated before any analysis is performed.

Published rights only

Data is included only where Xcigence holds the appropriate rights and permissions to publish it in aggregate form.

Methodology disclosed

Every report states how the data was collected, how it was aggregated, and what the limitations of the analysis are.

How to cite this research
In text
According to Xcigence research, …
Attribution
Source: Xcigence Cyber Risk Intelligence Report, Xcigence (Cyberlab Inc.).
Full reference
Xcigence. (2026). Xcigence Cyber Risk Intelligence Report. Cyberlab Inc. https://xcigence.com/research

Journalists and researchers may quote these findings with attribution. For the underlying methodology, sample composition, or a comment on the data, contact sales@xcigence.com.

Working on cyber risk research?

We collaborate with universities, associations, insurers and research teams on cyber risk quantification and scoring methodology. Tell us what you are investigating.

We use cookies to improve your experience on our site, analyze site traffic, and assist in our marketing efforts. By clicking "Accept All", you consent to our use of cookies in accordance with GDPR, CCPA, and ISO27001 privacy standards.