The binary language of security hides useful information
Security reporting favours clean states. Green or red. Passed or failed. Compliant or non-compliant. MFA deployed or not deployed.
Those states are useful for individual tests. They become misleading when they are used to describe a whole enterprise.
An organisation can have strong identity controls across most SaaS applications and none around one heritage terminal service. It can have good IT observability and sparse OT visibility. It can have deterministic rules for known malicious operations and only behavioural signals for activity that has never been seen before.
The title of this paper is intentionally uncomfortable. The figure of 67% is illustrative, not a benchmark. It represents a more useful statement than “we are secure”: we know where our controls hold, where they do not and how confident we are in that map.
Certainty about partial coverage is more useful than confidence without a denominator.
The purpose of measurement is not to lower ambition. It is to make the next control decision precise.
A posture is meaningful only when the denominator is known
Consider the statement that MFA is complete. Complete across which identities? Which applications? Which administrative paths? Which remote vendor sessions? Which OT engineering connections? Which machine-to-machine interactions?
The same problem appears with monitoring. An organisation may collect logs from thousands of endpoints and still have no interaction-level evidence from the small number of systems that matter most to the critical service.
A useful security posture therefore needs a denominator. The set of material interactions. The controls that should apply to them. The evidence that those controls actually applied. The exceptions that remain.
This framing aligns naturally with Data Mediation because the unit of control is the interaction. A policy can be attached to the path where a user, system or agent requests data or action. Coverage can then be described in operational terms: which material interactions are mediated, which controls are bound to them and which evidence is retained.
Deterministic controls create the part we can state with certainty
Some security decisions should not be probabilistic.
If a policy requires MFA before a privileged terminal session, the session either passes the MFA gate or it does not. If a class of user must never receive a card number, the field is masked or the response is denied. If an OT remote-access path may reach only one engineering workstation during an approved maintenance window, any other destination is rejected.
These are deterministic controls. The policy is explicit and the permitted outcome is defined in advance.
A Programmable Data Agent can enforce those controls in the interaction path. The important architectural property is independence from the target system. A deterministic rule can be applied around an HTTP request, a database query, a mainframe session or an industrial exchange provided the protocol and operating context are understood.
This creates the part of the security posture that can be stated with genuine certainty: for the interactions within scope, this policy version was applied and these outcomes were enforced.
Probabilistic intelligence expands what can be seen
Not every risk can be expressed as a fixed rule before it appears.
An account may behave differently from its baseline. A series of individually permitted transactions may become suspicious because of their velocity. A PLC may receive a technically valid command at a time or state that makes no operational sense. A model may identify a new pattern in vulnerability research that has not yet been translated into a standard control.
These techniques produce scores, likelihoods and hypotheses. They are valuable because they expand the field of observation beyond what was known in advance.
They are also different from enforcement. A 92% fraud score is not itself a business decision. An anomaly alert is not an isolation policy. A frontier model’s interpretation of a vulnerability disclosure is not permission to change a production control system.
The architecture should preserve that distinction.
Data Mediation composes intelligence and enforcement in the path
Data Mediation provides a place where probabilistic intelligence can inform deterministic action without becoming the authority itself.
A behavioural model can raise the confidence that an interaction is risky. The policy can then require a second factor, route the transaction for approval, reduce the permitted amount, mask additional data or deny the operation. The model contributes intelligence. The policy determines the action.
The same composition works in OT, but the controls and approvals are different. A process anomaly may increase scrutiny of a command path or trigger operator review. It should not bypass interlocks, safety constraints or engineering authority.
Probabilistic intelligence informs. Deterministic policy decides. Data Mediation enforces.
The separation allows AI and statistical techniques to add value without transferring control of the enterprise to them.
This is already a familiar pattern in fraud. Velocity, geography, device characteristics and historical behaviour may contribute to a score. The outcome can still be explicit: allow, challenge, refer or deny. Data Mediation generalises that pattern beyond a single fraud engine and makes it composable with other security and risk controls.
The right scope may be a transaction, journey, system, domain or estate
Security programmes often fail when they choose only between two extremes: a local point control or an enterprise-wide transformation.
Data Mediation can be composed at smaller and larger boundaries.
A single transaction can carry a field-level masking rule. A customer journey can combine identity, fraud, privacy and AI controls. A system boundary can mediate all administrative access. An OT site can govern selected connections between engineering, historian and enterprise zones. An enterprise programme can publish approved control patterns for reuse across many systems.
The Composable Agentic Platform retains the capability, its functional logic, its non-functional requirements and its operating evidence. Teams can therefore reuse the pattern without pretending that every deployment has the same risk tolerance or safety case.
This is how a security posture becomes composable rather than monolithic.
An honest map turns uncertainty into a programme of change
Once the denominator is explicit, the organisation can stop arguing about whether it is “secure” and start deciding where to move the boundary next.
The map might show deterministic MFA across 82% of material human access paths, strong interaction evidence across 71% of critical transactions and anomaly detection across 90% of a particular domain. The exact numbers will vary. Their value is that they reveal both coverage and absence.
The remaining work can then be prioritised by consequence. A missing control around an exposed OT engineering path may matter more than improving an already mature SaaS control. A critical data path without field-level policy may deserve attention before a low-value application with incomplete telemetry.
Data Mediation does not make the percentage itself important. It makes the denominator and the path to improvement operational.
This also creates the bridge to the next paper. Once an organisation can combine probabilistic intelligence with deterministic enforcement, a newly discovered risk no longer has to wait for the target application to be changed before a temporary control can exist.
The mature posture is the one that can explain its uncertainty
Cyber risk cannot be reduced to a single score. It can, however, be decomposed into material interactions, explicit controls, observed evidence and known gaps.
Data Mediation provides an architecture for making that decomposition executable. Deterministic rules govern what must be certain. Probabilistic techniques extend visibility into what is not. The platform composes the two at the scope where the consequence exists.
The organisation with the clearest map of where its controls hold is better positioned than the organisation that claims certainty everywhere.
References
National Institute of Standards and Technology. Cybersecurity Framework 2.0 ↗.
Cybersecurity and Infrastructure Security Agency. Cross-Sector Cybersecurity Performance Goals ↗.
UK Department for Science, Innovation and Technology and National Cyber Security Centre. Cyber Governance Code of Practice ↗.
TomorrowX. Composable Agentic Platform.
TomorrowX. Components, boundaries and non-functional requirements.
TomorrowX. Historical implementation records covering risk-based authentication, fraud controls, data access governance and market-specific policy enforcement.