Citalid Launches Decision History to Give CISOs and Risk Managers Full Visibility Into Their Cyber Decisions

With two new modules available today, the event log and platform snapshots, Citalid enables its clients to trace, compare, and justify how their cyber risk evolves over time. A third module dedicated to metrics tracking is planned by the end of the year.
Paris, 15 september 2026. Citalid, Europe’s leading cyber risk quantification (CRQ) platform, today announced the launch of Decision History, a new capability on its Citalid Core platform. Decision History gives CISOs and Risk Managers the means to trace, compare, and justify the evolution of their cyber risk exposure, without rebuilding that history by hand.
For years, the challenge for CISOs was translating technical exposure into a defensible monetary figure, the very figure risk committees had long expected without a reliable method to produce it. That question is now settled: risk quantification methods, FAIR foremost among them, are no longer a differentiator, everyone understands the principles. What matters now is operational pragmatism: a process that fits into existing tools and stays traceable over time, particularly for organizations that have used Citalid for several years and now need to demonstrate that their past decisions held up, notably for insurance purposes.
The event log: who did what, and with what impact
The event log tracks every action performed on the platform for a given scope, whether triggered by a user or by the system. Each entry answers four questions: who, what, when, and with what impact, expressed as the value before and after the change, and can be expanded to show the detail field by field.
This module serves a daily need: finding, filtering, and understanding actions taken by users or by the system within the current version of Citalid Core.
The event log documents every action individually. It supports operational traceability, auditability, and the analysis of variations observed within a risk analysis, a direct pillar of any cyber risk governance approach.
Snapshots: freeze a state to compare it later
The second module lets users freeze the entire platform at a given moment, to retrieve it later in read only mode exactly as it was. A snapshot marks the moments that actually matter in the life of an organization: a fiscal year close, a board meeting, an audit, an insurance renewal. Each of these moments becomes a fixed reference point to return to, concrete proof that cyber risk analysis is not a static exercise frozen on a slide, but a living process, anchored in the real pace of the business.
A snapshot preserves everything that gives an analysis its value: risk scenarios and their results, defense profiles and maturity levels, asset inventory, security solutions, insurance policies, budget data, survey responses, external security ratings, recommendations, measurement scales, feared events, and loss simulation results.
“Cyber risk quantification methods are now well understood and mastered across the market. What sets organizations apart is the ability to embed them in a process that is reliable and traceable over time,” said Léo Coqueblin, VP Product at Citalid. “That is the whole purpose of Decision History: giving our users a full record of their own cyber decisions, so they can justify them year after year, notably for insurance purposes.”
History will be completed by the end of the year with a third capability: metrics tracking over time. It will offer a macro view of how key indicators evolve across multiple periods, with an AI generated summary that explains, in plain language, the drivers behind a variation, for example how a change in exposure surface affects annual expected loss.
Want to see Decision History in action on your own environment?
Talk to a Citalid expertThe longevity of a cyber risk management program is often threatened when the CISO or another project lead moves on, causing the program to lose continuity. A complete, accessible history that every stakeholder can consult reduces that dependency and fits the same logic of sustainable CRQ program governance already covered in Citalid’s complete guide to Cyber Risk Quantification.
About Citalid
Citalid is a leading SaaS platform for cyber risk quantification. Founded in 2018 by two Cyber Threat Intelligence experts, Citalid helps businesses and insurers make informed decisions by translating dynamic threat data into actionable financial indicators.
Press Contact
Citalid: Marie Giesbert, Chief Marketing Officer (marie.giesbert@citalid.com)
