The threat horizon
Three horizons. The exposure is present tense; only the deadline is future.
Horizon 1 · now → 2027
Present and mandated
The threats already in your estate and the deadlines already set.
Horizon 2 · 2027 → 2030
Emerging and supply-chain
Continuous drift, multi-source key trust, and AI-accelerated cryptanalysis.
Crypto drift widens every sprint you don't measure.
Horizon 3 · 2030+
Critical infrastructure and nation-state
OT/ICS crypto, space-link attacks, 20-year IP confidentiality, quantum-enabled adversaries.
Not a rebuild
How we absorb new threats
New attack classes arrive as content, frameworks, parsers, adapters, on the same platform, not rebuilds.
A new NIST framework
Ships as a Comply mapping and evidence template, no new product.
A new key-source vendor
Ships as an Orchestrate adapter behind the same policy engine.
A new language to scan
Ships as a Discover parser feeding the same CBOM.
