Video available in the interactive version.
ShieldsUP Cyber Defense Readiness in the AI Era
A live, sectioned workshop experience: capture the customer context, walk one domain at a time, then turn answers into an executive decision, roadmap, Cisco accelerator path, and source-backed practitioner library.
Facilitator note
Run the assessment as an interview, not a form. Complete one domain at a time, mark non-applicable controls as N/A, capture evidence in notes, and use the Results section to align on funded remediation or explicit risk acceptance.
Progress: the top bar tracks answered controls out of 54. A domain check appears when all six controls are answered or marked N/A.
The patch cycle is no longer the control plane.
Project Glasswing is the frame; Mythos is the warning. The report treats AI-assisted vulnerability discovery as an operating-model problem, not as another tooling category.
Frontier models alter the economics of finding and chaining vulnerabilities. The assessment therefore scores current-state controls only, not intent or roadmap claims.
Unpatched, unsupported, over-exposed, or poorly segmented infrastructure stops being latent risk. It becomes a time-window problem.
Scores flow into a three-phase path: Exposure Assessment, Infrastructure Modernization, and Defense Resiliency.
Video available in the interactive version.
Video available in the interactive version.
Use the assessment to decide what must be funded, owned, or explicitly accepted.
Assessment — one domain at a time
Complete the engagement context, tune domain weights if needed, then facilitate each domain view in sequence.
Assessment context
Required. To start the assessment: a reference, a date, and scope or industry. Assessor and rosters are optional (they enrich the report cover).
Domain weight editor
Official scoring always uses the locked default domain weights. Scenario weighting is optional and must sum to 100; if it does not, the scenario score is withheld.
Decision-ready summary & The Ask
Auto-generated from the assessment and editable for board language. Narrative fields persist in autosave and JSON exports.
Score at a glance and analytical dashboardDomain radar, SAFE surfaces, CTEM strip, ODM, NIST CSF 2.0 and answer-quality views.
Executive readiness view
Overall score, banding, domain breakdown, SAFE surface scores, CTEM strip and Protection-Level rollup.
Cisco overall bands: Emerging · Developing · Established · Advanced
Domain radar
Readiness by domain
Ranked by score, sized by weight — longer is stronger; thicker bars carry more of your overall score.
SAFE attack-surface scores
CTEM phase strip
Domain heatmap
Protection-Level view — ODM current → target
Average current and target by Outcome-Driven Metric category. Current defaults to stage-derived proxy unless overridden.
Function heatmap (non-scoring)
Read-only mapping from ShieldsUP domains to CSF 2.0 Functions. Recover is indicative only; see Defense Resiliency phase.
Low-confidence answers to revisit
Confidence and evidence annotations never change score; they guide follow-up validation.
Recommendations and domain narrativePreserved advisory cards, pillar framing and lowest-domain expansion.
Full findings backlogSeverity, domain, owner, effort and expandable remediation detail for every sub-Optimal control.
Findings & recommendations
Automatically generated for answered controls below Optimal, severity-sorted using the catalog rule.
Prioritized action planningQuick wins versus strategic moves, derived from the existing findings pool.
Quick wins vs strategic moves
Prioritized actions for execution planning, derived deterministically from severity, weight and remediation effort signals.
3-phase roadmapExposure Assessment, Infrastructure Modernization and Defense Resiliency mapped from findings.
Roadmap
Sub-Optimal findings mapped into Exposure Assessment, Infrastructure Modernization and Defense Resiliency phases.
Cisco Accelerator
The assessment body remains vendor-agnostic; this closing section converts the lowest-scoring domains into a fundable Cisco starting point.
Further Reading & Sources
Linkable source library for the framework, scoring methodology, AI-security scope, Zero Trust validation, governance context, and Cisco delivery path. Embedded for offline use; links open externally only when selected.
Assessment methodology & provenance
Reusable instrument anchored in Cisco and industry operating models.