Investment catalog

Play CISO Simulator free Free · no signup · plays in 30–45 min
Start playing →

Every product, hire, and service CISO Simulator makes available, grouped by category. 105 vendor-neutral entries — each with posture contribution, team requirements, and the cybersecurity risks it helps mitigate.

How a CISO budget actually breaks down

A modern CISO budget runs across roughly fourteen capability layers. The biggest line items are usually Headcount (the team itself), SIEM (analyst tooling that scales with log volume), IAM (the identity layer), and Compliance (audits + attestations). Operational tooling (EDR, NDR, AppSec, Cloud) makes up the next tier. Architecture investments and Insurance round out the bottom. The right mix depends on the company's stage, sector, and threat profile — a Series-B SaaS company won't budget like a regulated bank or a hospital network.

Best-of-Breed vs Platform — the consolidation question

Every CISO eventually faces the platform question: do you buy the best individual product in each category (best-of-breed) or commit to a platform that covers many categories at once (XDR, SASE, M365 E5, CNAPP, SSE)? Best-of-breed maxes posture per dollar but multiplies vendor management overhead. Platforms cap posture at a discount but reduce friction and integration cost. CISO Simulator models this trade-off explicitly — events occasionally fire that punish over-platform or over-best-of-breed strategies.

Why the catalog is vendor-neutral

The catalog uses category descriptors — Mid-Tier EDR, Continuous Control Monitoring, TPRM Platform, Customer Trust Center — instead of real vendor names. The mechanics reflect how each category of tool actually works in practice. This makes the game evergreen (vendor logos rotate, capabilities don't) and makes it useful as a thinking tool for real procurement: when you can't compare brand to brand, you compare capability to capability.

The full catalog

20 categories. Click a product for its posture contribution, team requirements, mitigated risks, and where it fits in a real CISO program.

AI Security 11

AppSec 4

Architecture 3

Awareness 3

Backup 2

Cloud Sec 3

Compliance 20

Data Sec 3

EDR 3

Email Sec 2

Endpoint Mgmt 1

Governance 10

Headcount 8

IAM 4

Insurance 1

Network 9

Platform 4

Services 8

SIEM 4

Vuln Mgmt 2

Play CISO Simulator free →