What You're Actually Selling: Decision Support, Not a Checklist
Cordaata's own framing is exactly right and worth repeating verbatim to a prospect: "full visibility, clear direction on risk prioritization, and financial clarity." Read that again — it's not "we help you pass an audit." It's "we help you decide." A CISO at a 2,000-person company doesn't wake up needing a compliance certificate; they wake up needing to walk into a budget meeting and say, with a number behind it, which of a dozen possible investments actually reduces the company's real exposure the most. Almost nothing on the market answers that question in the buyer's own systems and numbers instead of a generic industry benchmark — that's the whole pitch.
The MechanismThe FORRI Framework
- Cordaata ingests data across every business process, system, data asset, service, and dependency in an organization — not a generic template applied to everyone the same way.
- Each entity gets a FORRI impact profile — Financial, Operational, Reputational, Regulatory, IP & Data — then relevant risk scenarios are identified specifically for how that system is actually used, not from a generic library.
- Scenarios run through a quantification engine calibrated against published, sector-specific incident data, producing Annualized Loss Expectancy (ALE) at the scenario, system, and organization-wide level, plus control-maturity scoring.
Dashboard vs. Decision SupportThe Distinction That Sells This
- A risk dashboard shows a heatmap and lets the CISO guess what to do about it. A decision support system ranks the options in a common unit — dollars of expected loss avoided — so "buy this tool" and "hire this analyst" and "accept this residual risk" become directly comparable line items, not three different vibes.
- Control-maturity scoring plus per-scenario ALE is, functionally, a ranked capital-allocation list. That's the sentence to use with a CFO in the room, not just a CISO.
The Real InsightCISOs Make Dozens of Prioritization Calls a Year on Gut Feel
- Patch this or that first? Buy this tool or add headcount? Accept this risk or transfer it via insurance? Almost every mid-market security leader makes these calls off intuition, a vendor's scary demo, or whoever's loudest in the room — not a comparable financial number across the options.
- Cordaata replaces the gut-feel currency with one common unit. That reframes the entire sales conversation from "do you have a risk problem" (everyone says yes) to "can you currently rank your top 10 risk decisions by dollar impact" (almost nobody at this size can).
Handle With CareYou Have No Case Studies Yet — Lean on the Mechanism
- Cordaata is a 2–10 person, 2025-founded company out of Antwerp, Belgium, with no named customers, funding round, or press coverage found anywhere, and no confirmed U.S. presence or legal entity. That's normal for this stage — but you cannot open with "here's who trusts us."
- Real, named competitors in cyber-risk quantification — Kovrr, Axio, RiskLens, Safe Security, FortifyData, DeNexus, and France's Citalid/C-Risk — are better funded and more established. Don't lead with "Made in Europe" in the U.S. — it barely registers with American mid-market buyers and can even invite an unnecessary data-residency question. Lead with the decision-support framing and the mechanism instead.
Ideal Customer: 500–5,000 Employees, Regulated or Semi-Regulated
This is a deliberately narrower target than "any company with a CISO." The sweet spot is a company big enough to have named security leadership and real financial stakes, small enough that it almost certainly lacks a dedicated risk-quantification function — and answerable to some external regulator or overseer, so a real number matters to someone beyond the security team itself.
500–5,000 employees — large enough for a named security leader and real stakes, small enough to lack a dedicated CRQ or GRC-quant function.
Answers to some external regulator or overseer — SEC (if public), a state insurance commissioner, NCUA, HIPAA/OCR, or a state utility commission.
Has a named CISO or Head of Information Security already — someone whose job gets easier with a ranked, quantified list, not someone starting from zero.
Is actively making a budget, M&A-integration, post-incident, or new-technology tradeoff right now — a live decision moment beats a "someday" conversation.
Can you name the actual security leader, or a regional vCISO/consultancy serving them, within two LinkedIn connections?
Buyer Category 1 — DirectThe Mid-Market CISO or Security Leader
- Who: a named CISO, Head of Information Security, or VP of IT Risk at a 500–5,000-employee company in banking, insurance, credit unions, healthcare, or utilities — see tab 07 for named Florida and Georgia examples.
- What a "yes" looks like: a security leader who reports informally on risk today but cannot rank their own top ten risk decisions by dollar impact if asked in the next meeting.
Buyer Category 2 — ChannelRegional vCISO Consultancies & MSSPs
- Who: Southeast-U.S.-serving fractional CISO firms selling to multiple mid-market clients — Cordaata names "virtual CISOs and consultants" as a target audience directly on its own site.
- Why this matters more for a 2-person startup: one signed vCISO partner covering Florida or Georgia clients can put the platform in front of a dozen mid-market end-clients at once.
Buyer Category 3 — ChannelGRC & Compliance Consultancies
- Who: firms running risk-assessment or compliance-readiness engagements for insurers, banks, or healthcare clients who need a quantification engine to plug into their own deliverables. Protiviti — a major GRC consultancy and Founding Advisory Partner of the FAIR Institute — already runs its own CRQ practice, making it both a possible partner and a serious competitive presence in the same conversations.
Buyer Category 4 — EmergingCyber Insurance Brokers
- Who: brokers — Marsh runs a named, public Cyber Risk Quantification practice — increasingly asking mid-market commercial clients for quantified risk data before binding or renewing cyber policies.
- Why it fits: ALE output is exactly the kind of number an underwriter can use. Coalition and At-Bay build their own proprietary scoring into underwriting — closer to competitors than partners.
Your Product's Strength vs. Their Structural Weakness
Every good pitch is one strength curing one weakness. At this size band, the weakness is sharper than at a large enterprise: there's usually no internal team dedicated to answering "what's our real exposure," and no external mandate forcing the question either.
Product StrengthA Ranked, Defensible Number — Not Just Visibility
- Cordaata's FORRI engine doesn't score an organization against a generic template — it models risk on how that specific business actually operates: its real systems, dependencies, and revenue-generating processes.
- The output is a single financial figure — Annualized Loss Expectancy — per scenario, system, and org-wide, ranked. That's the strength: it turns "we have a lot of risks" into "here are our top ten, in dollar order."
Customer WeaknessNo Dedicated Function, No External Forcing Function
- At 500–5,000 employees, almost nobody has a dedicated risk-quantification analyst or team — the CISO or a generalist IT-risk manager is doing this on the side, if at all, usually with a spreadsheet or a qualitative heat map inherited from an old audit.
- Unlike a Fortune 500, there's often no single external mandate forcing the issue — some targets answer to the SEC, some to a state insurance commissioner, some to NCUA, some to HIPAA/OCR, and some to none of the above beyond their own board's risk appetite. That patchwork (tab 05) is itself part of the weakness: nobody at this size has one clean answer to "what does our regulator actually require us to know," so almost nobody has built the muscle to know it anyway.
Secondary WeaknessThe CISO's Own Credibility Gap
- This is personal, not just organizational: Cordaata's own content — "The Strategic CISO: From Gatekeeper to Business Growth Enabler" — is built around the fact that most security leaders are seen internally as a cost center that says no, not a strategic voice the board or CFO trusts with numbers.
- That's a real, separate self-interest lever: the same tool that gives the company a defensible number also gives the CISO personally a seat at the budget table. Sell to both motives at once.
The Thesis, One LineSay This, Almost Verbatim
- "You almost certainly know you have cyber risk. What you probably can't do is rank your top ten risk decisions by dollar impact if I asked you to do it right now. That's not a compliance gap — that's a decision-support gap, and it's the one thing Cordaata is built to close."
- This single framing works as a cold-open line, a follow-up after a conference conversation, and the frame for a discovery call.
The RACE Plan — Reach, Act, Convert, Engage
Built around the reality of a 2-person, pre-case-study startup entering a new region: small, bounded first asks against a named, researched target list — not a broad, undifferentiated campaign.
01 · ReachOpen With the Diagnostic, Not the Product
- Objective: get the one-line thesis (tab 03) in front of a named CISO from tab 07, or a regional vCISO/consultancy from tab 06.
- Do this: ask whether they can currently rank their top 10 risk decisions by dollar impact. Let their answer tell you which weakness (organizational or personal) to lean on next.
02 · ActTurn the Open Into a Bounded Pilot
- Objective: a small, free, or low-cost ask — not a full-platform commitment.
- Do this: offer to run one real business-critical system through the FORRI model and hand back a genuine ALE number within an agreed timeframe.
- Success metric: a scoped snapshot accepted, with a named system and a delivery date.
03 · ConvertTurn the Snapshot Into a Signed Contract
- Objective: one paid engagement — your first, so treat the commercial terms as flexible in service of getting it signed.
- Do this: frame the next step around the decision the snapshot enabled — "here's the ranked list your board saw; here's what a live, quarterly version looks like."
04 · EngageTurn One Customer Into Your First Case Study
- Objective: convert your first deal into the proof point every future "Reach" conversation currently lacks.
- Do this: expand from the pilot system to org-wide coverage; ask directly for a reference once there's a real result.
The Regulatory Patchwork — Why Every Sector Needs This Anyway
There's no single federal law forcing every mid-market company in Florida or Georgia to quantify cyber risk the way NIS2 does in the EU. Instead there's a patchwork by sector — which is actually a better story for a decision-support pitch: none of these frameworks tell a company its true financial exposure, no matter which one it answers to. That's the gap Cordaata closes regardless of the regulator.
Public CompaniesSEC Cybersecurity Disclosure Rules
- Every SEC-reporting company — roughly half of the top 20 in tab 07 are publicly traded — must disclose a material breach within 4 business days (Item 1.05) and describe the board's cyber-risk oversight process annually (Item 106), in effect since September 2023.
InsurersNAIC Insurance Data Security Model Law
- Applies to state-licensed insurers (the model law's own threshold is as low as 10 employees) — requires an annual risk assessment, a written information security program, an incident response plan, and notifying the state insurance commissioner of a cybersecurity event, typically within about 3 days.
- Honest caveat: sources conflict on Florida's and Georgia's exact adoption status and statute numbers — confirm directly with each state's Office of Insurance Regulation before citing a specific law by number to a prospect.
Credit UnionsNCUA Part 748
- Federally insured credit unions must maintain a written information security program; the board must approve it, review it at least annually, ensure adequate resourcing, and receive an annual status report — a direct, verified board-oversight requirement.
Healthcare & UtilitiesHIPAA and State/Federal Infrastructure Oversight
- Healthcare systems and health-data processors answer to the HIPAA Security Rule's risk-analysis requirement. Investor-owned and municipal utilities face a mix of state public-service-commission oversight and, for parts of the bulk power system, NERC CIP standards — real but less codified as personal board liability than the frameworks above.
"Whether you answer to the SEC, your state insurance commissioner, the NCUA, or HIPAA, none of those frameworks actually hand you a number for your true financial exposure — they just check whether you have a program. Cordaata is the layer underneath all of them that tells you what your risk is actually worth in dollars, so you can defend a budget decision to whichever regulator, board, or CFO is asking."
How to Actually Find Them
For a 2-person startup with no case studies and no U.S. presence, the fastest path to a pipeline is real communities and channel partners — not cold-calling a purchased list.
JoinFAIR Institute — Nearest Southeast Chapter
- 8 U.S. chapters exist, none in Florida or Georgia specifically — the closest is likely Washington D.C. or a virtual chapter meeting. The FAIR Institute is the leading nonprofit for cyber-risk-quantification practitioners; joining virtually still gets you into the exact community that already believes in this discipline.
- Honest caveat: RiskLens, a direct Cordaata competitor, was built by FAIR's own co-creator — expect some home-field advantage for that name in these rooms.
Partner WithRegional GRC & vCISO Consultancies
- Protiviti — national GRC consultancy with Atlanta and Florida offices, a FAIR Institute Founding Advisory Partner running its own CRQ practice.
- Optiv, FRSecure, Atlant Security — national vCISO/GRC firms serving Southeast clients; FRSecure and Atlant are closer in size to a first Cordaata partnership than Optiv.
Show UpRegional Events
- Regional "Cybersecurity Summit" circuits run in Atlanta and other Southeast metros multiple times a year — smaller rooms, easier real conversations than a national conference.
- State-level insurance and banking trade associations (Florida Bankers Association, Georgia Bankers Association, each state's Insurance Council) run annual conferences that put dozens of tab-07 targets' leadership in one room at once.
Insurance ChannelMarsh's Cyber Risk Quantification Practice
- A named, public broker practice — worth a direct conversation given how many tab-07 targets are themselves insurers who also buy cyber coverage.
Search SmartLinkedIn
- Title-search: CISO, Head of Information Security, IT Risk Manager, Chief Risk Officer at the named companies in tab 07 directly — a far more efficient search than a broad regional sweep.
ContentRepurpose the Existing Blog
- Cordaata already has on-message blog content — "Cyber Risk in Financial Terms: A CFO Dashboard Guide for CISOs," "Tiered Risk Analysis," "Proactive Security Capacity Planning" — built for exactly this buyer. Share it directly with named tab-07 contacts rather than writing new material from scratch.
Top 20 Targets: Florida & Georgia
Real, named, 500–5,000-employee companies in regulated or semi-regulated industries, researched and verified against company filings, press, and public employee-count data — not invented. Florida naturally dominates this list: its unique, hurricane-driven property-insurance market produces far more mid-market regulated companies in this exact size band than Georgia does. Employee counts vary by source and are approximate; verify directly before a live conversation.
Public, SEC-Reporting — Clearest Regulatory Driver
| # | Company | HQ | Sector | ~Employees | Why It Ranks Here |
|---|---|---|---|---|---|
| 1 | Heritage Insurance Holdings | Tampa, FL | P&C Insurance (NYSE: HRTG) | ~550 | An insurer that models catastrophe risk for a living is a natural buyer for a tool that quantifies its own cyber risk. SEC Item 106 applies directly; smallest, most nimble insurer on the list. |
| 2 | HCI Group | Tampa, FL | P&C Insurance (NYSE: HCI) | ~594 | Publicly known for leveraging technology in underwriting — likely more receptive to a modern quantification tool than a traditional carrier. |
| 3 | Universal Insurance Holdings | Fort Lauderdale, FL | P&C Insurance (NYSE: UVE) | ~1,000–1,070 | Same insurer logic as HRTG/HCI, larger scale — a bigger first deal if the pitch lands. |
| 4 | Amerant Bank | Coral Gables, FL | Bank (NASDAQ: AMTB) | ~692 | Smallest public bank on the list — likely the fastest first conversation to book among the banks. |
| 5 | Colony Bankcorp | Fitzgerald, GA | Bank (NYSE: CBAN) | ~450–800 | Smallest public bank overall; operates across Georgia, Florida, and Alabama — a cross-state bonus target. |
| 6 | Ameris Bancorp | Atlanta, GA | Bank (NASDAQ: ABCB) | ~2,710 | Georgia's clearest public-bank target — mature enough to have real budget, not so large it has its own quant team already. |
| 7 | Synovus Financial | Columbus, GA | Bank (NYSE: SNV) | ~2,854 | Largest Georgia bank in scope — a bigger prize if a relationship with Ameris opens the door to a warm intro. |
| 8 | Seacoast Banking Corporation of Florida | Stuart, FL | Bank (NASDAQ: SBCF) | ~1,000–2,000 | One of the largest community banks headquartered in Florida (~$20.8B in assets) — solidly public, solidly mid-market. |
| 9 | BankUnited | Miami Lakes, FL | Bank (NYSE: BKU) | ~1,600–2,100 | Major public Florida bank; sources on exact headcount vary, confirm directly. |
| 10 | SouthState Corporation | Winter Haven, FL | Bank (NASDAQ: SSB) | ~5,100 | Largest bank on the list, right at the top edge of the target band — the biggest deal, but also the most likely to already have some internal risk-quant capability. |
State/Federal-Regulated, Not SEC-Reporting
| # | Company | HQ | Sector | ~Employees | Why It Ranks Here |
|---|---|---|---|---|---|
| 11 | VyStar Credit Union | Jacksonville, FL | Credit Union | ~2,300 | In 2024, a botched platform conversion caused a 10-day outage and a joint NCUA/CFPB enforcement action explicitly citing "management and governance failures and assumption of excessive risk" — not a cyberattack, but a real, dated, public example of exactly the risk-governance gap this product addresses. |
| 12 | Citizens Property Insurance Corporation | Jacksonville, FL | State-Created Insurer | ~1,200–1,600 | Florida's state-backed property insurer of last resort — intense political and media scrutiny means any incident becomes a statewide news story, raising the stakes on demonstrable risk management. |
| 13 | City National Bank of Florida | Miami, FL | Bank (privately held) | ~1,000 | Not SEC-reporting (owned by a Chilean parent), but still federally/state bank-regulated — a clean, well-capitalized private target. |
| 14 | Suncoast Credit Union | Tampa, FL | Credit Union | ~2,620 | Florida's largest credit union by assets and membership — NCUA Part 748 applies directly, including the annual board report requirement. |
| 15 | Delta Community Credit Union | Atlanta, GA | Credit Union | ~1,400+ | Georgia's largest credit union — same NCUA Part 748 driver as Suncoast/VyStar. |
| 16 | Tampa Electric (TECO Energy) | Tampa, FL | Utility | ~3,713 | Critical-infrastructure operator under state PSC oversight — a breach or outage carries public-safety and rate-case consequences. |
| 17 | JEA | Jacksonville, FL | Municipal Utility | ~2,200+ | Publicly accountable municipal electric/water utility — an incident becomes a City Council matter, not just a technical one. |
| 18 | Halifax Health | Daytona Beach, FL | Public Hospital System | ~4,130 | HIPAA Security Rule risk-analysis requirement applies directly; public hospital district status adds political visibility. |
| 19 | Phoebe Putney Health System | Albany, GA | Nonprofit Hospital System | ~4,300 | One of Georgia's largest independent regional medical centers — HIPAA-driven, and still independent rather than absorbed into a mega-system. |
| 20 | Cotiviti | Atlanta, GA | Healthcare Payment Integrity / Data Analytics | ~1,001–5,000 | Processes enormous volumes of healthcare claims data for payer clients — HIPAA exposure plus contractual audit obligations from every payer it serves, a compounding-risk profile. |
Employee counts above come from a mix of company filings, LinkedIn, and third-party data aggregators that don't always agree — treat every number as approximate and confirm before quoting it back to a prospect. Several targets (Halifax Health, JEA, Citizens Property, the credit unions) are public or quasi-public entities, not SEC filers — their board-reporting exposure comes from HIPAA, NCUA, or plain political accountability, not Item 106. Atrium Health Navicent (Macon, GA) was deliberately excluded despite its size (~4,600–7,000 employees) because it's now part of the much larger Advocate Health system, where security decisions likely roll up enterprise-wide rather than staying local.
First-Touch Scripts
Rehearsal scripts, not real quotes — adapt once you have a named contact from tab 07.
In-House CISO — Cold Outreach
Lead with the decision-support gap, not a generic product pitch — it's a question almost nobody at this size can answer well.
vCISO / Consultancy — Channel Pitch
This is a partner pitch, not an end-user pitch — the value is volume, not a single seat.
A Target With a Real, Dated Trigger
When a target has a public, named incident — like VyStar's 2024 outage — reference it precisely and respectfully; it's public record, not gossip.
- Before any call: confirm the contact's actual title and current employee count directly — the figures in tab 07 are approximate and sourced from mixed dates.
- After first contact: send one relevant Cordaata blog post matched to their role.
- If no response in 5 business days: follow up once with a different angle — never a bare "just checking in."
Your First 90 Days
Sequenced around the named targets in tab 07 rather than a generic territory sweep.
- Days 1–15: Verify current titles and employee counts for the top 5 Tier 1 targets; join the FAIR Institute (virtually if no nearby chapter); ask Cordaata's founders for any warm contacts at Protiviti, Optiv, FRSecure, or Atlant Security.
- Days 16–45: First outreach wave to the top 5 Tier 1 targets plus VyStar (the clearest dated trigger); one channel-partner conversation with a regional vCISO firm.
- Days 46–75: Follow up; expand outreach to Tier 2; aim for 2–3 real discovery calls booked from named tab-07 targets.
- Days 76–90: Bring your strongest lead — end-customer or channel partner — back to Cordaata's founding team for a joint call once it's warm enough to matter.
- Ongoing: Re-verify employee counts and regulatory status for any target before a live meeting — several figures in tab 07 come from sources that disagree with each other.
Sources
- Cordaata — Homepage
- Cordaata — About
- SEC — Cybersecurity Risk Management, Strategy, Governance & Incident Disclosure Rules
- NAIC — Insurance Data Security Model Law (MO-668)
- NAIC — Model Law State Adoption Tracker
- NCUA — Board of Director Engagement in Cybersecurity Oversight
- Banking Dive — VyStar Outage
- NCUA — Statement on CFPB Enforcement Action Against VyStar
- Heritage Insurance Holdings (NYSE: HRTG)
- HCI Group (NYSE: HCI)
- Universal Insurance Holdings (NYSE: UVE)
- Amerant Bank (NASDAQ: AMTB)
- Colony Bank (NYSE: CBAN)
- Ameris Bank (NASDAQ: ABCB)
- Synovus Financial (NYSE: SNV)
- Seacoast Banking Corporation of Florida (NASDAQ: SBCF)
- BankUnited (NYSE: BKU)
- SouthState Corporation (NASDAQ: SSB)
- Citizens Property Insurance Corporation
- City National Bank of Florida
- Suncoast Credit Union
- Delta Community Credit Union
- TECO Energy / Tampa Electric
- JEA
- Halifax Health
- Phoebe Putney Health System
- Cotiviti
- The FAIR Institute
- Protiviti — Cyber Risk Quantification Services
- Marsh — Cyber Risk Quantification