ForesightOps Insights · Enterprise Risk Intelligence

    Orienteering the Spectrum.
    Finding Your Bearings Across the Facets of Enterprise Risk.

    The technology is moving at turning-point speed. The frameworks most enterprises rely on were written for slower terrain. Introducing PRISM, a living instrument for reading the ground as you move.

    InsightsReading time 8 minWill Evans · Fugue Strategy Advisors
    What It Costs to Move Fast Without the Map
    $10.22M
    average cost of a US data breach in 2025, an all-time high
    IBM / Ponemon · 2025
    97%
    of AI-related breaches hit organizations without proper access controls
    IBM / Ponemon · 2025
    40%+
    of agentic AI projects forecast to be canceled by end of 2027
    Gartner · June 2025
    17%
    of large IT programs go so badly they threaten the company's existence
    McKinsey & Oxford

    Orienteering is the practice of reading terrain you have not mapped, moving through it, and correcting as you go. Enterprise leaders are doing the same kind of work right now, under conditions they did not train for.

    Last week, Anthropic released Claude Mythos Preview. It autonomously discovered thousands of zero-day vulnerabilities across every major operating system and every major web browser, including one in OpenBSD that had survived twenty-seven years of expert review. It escaped a sandbox it was told to stay in. It tried to hide that it had. Anthropic chose not to release it.

    Four days later, CrowdStrike joined Anthropic's Project Glasswing coalition and stated plainly that AI capabilities have crossed a threshold that changes the urgency required to protect critical infrastructure. The EU AI Act's next enforcement phase takes effect on August 2. Automated audit trails. Cybersecurity requirements. Incident reporting obligations. Penalties up to seven percent of global revenue.

    That is the terrain your programs are being delivered across, right now. Agentic systems with write access to enterprise data. Regulations that have become law. And inside the organization, six people in six rooms, each managing a different shard of the risk, in a different vocabulary, with no moment when the whole picture lands in one place.

    This piece introduces PRISM, the instrument built for reading that spectrum together.

    I
    A turning point, in the Perez sense

    New Paradigm.
    Old Scaffolding.

    Every technological revolution of the last two hundred years has followed a structurally similar arc. A new general-purpose technology irrupts. Financial capital floods toward it, faster than the institutions that would normally govern it can adapt. In the heat of that flood, irrational exuberance tends to trump the kind of risk and financial due diligence that would ordinarily be required. The bubble inflates. The bubble breaks. On the far side sits deployment, the long absorption of the new paradigm into everyday infrastructure, labor markets, organizational form, and cultural common sense.

    This is the pattern the economist Carlota Perez reconstructed across five successive surges, from steam and railways through mass production and on into information and telecommunications. The frame sits inside the Schumpeterian tradition of creative destruction, with one consequential addition. Revolutions arrive in surges of fifty to sixty years. Each surge contains a turning point, the stretch when institutions either catch up to the new paradigm or fail to.

    We are inside one now.

    Mythos is a capability signal. The AI Act, ISO 42001, NIST AI RMF, and OWASP's LLM Top 10 are institutional signals. Agentic systems with write access to enterprise data are the signal on the ground. Each of these moved faster than the governance machinery built around them.

    I see the present as the 1930s, the turning point of the IT surge. The power of AI, IoT, 3D, robots, blockchain is there to be shaped.

    Carlota Perez · 2019

    Risk in this cycle has a particular shape. Systems that find vulnerabilities faster than humans can patch them. Regulators expecting audit trails on AI outputs. Boards realizing the operational risk register does not cover agentic systems already in production.

    The frameworks that governed your last transformation were built for a different kind of ground. They still work on the parts of the portfolio that resemble the last decade. They go quiet on the parts that do not.

    II
    Six rooms, six vocabularies

    Risk Is Already Being Managed.
    In Six Places at Once.

    Risk in a large enterprise gets managed. It gets managed in six places at once.

    The Project Manager maintains a RAID log in Jira. The Security Architect tracks findings from the last penetration test. The Compliance Officer monitors obligations in a spreadsheet Legal owns. The Enterprise Architect carries unresolved design concerns from a deck three months ago. The Delivery Lead watches velocity. The CISO reviews a vulnerability dashboard the PM has never opened.

    Each of these people is paying attention. Each is managing real risk. They are doing it in separate rooms, at separate times, with separate vocabularies, and there is no moment when all of it lands in the same place at the same time.

    When a program runs into trouble, the post-mortem almost always finds the signals were there. In the RAID log. In a Slack thread. In a security finding someone marked accepted and never revisited. They were never in the same room at the same moment, in front of the people who could have acted on them.

    The bottleneck is at the top of the bottle.

    Gary Hamel · Strategy as Revolution · HBR, 1996

    Strategy is the pattern that shows up in the decisions, over time, as the organization moves through real conditions and responds to what it finds there. Plans are useful artifacts. Plans are different from strategy. Henry Mintzberg made this point forty years ago, and most enterprises still quietly refuse to accept it in practice.

    For turbulent environments, strategy has a usefully small operational definition. A single rule that unifies decisions around the real constraint, derived from the aspiration the organization is actually trying to achieve. This is Peter Compo's formulation, and it works precisely because it is small enough to fit in a team's working memory. The rule gets chosen once the bottleneck is named. The bottleneck gets named once the organization holds a shared picture of the ground it is operating on.

    The absence of that shared picture is what holds the rest back.

    III
    Strategy as a rule

    A Rule Needs a Picture
    The Whole Table Can See.

    A useful strategy rule has to survive stress. It has to hold across multiple plausible futures, including the ones leadership is actively hoping against. That stress test, what Compo calls fitness, is the move that separates a strategy rule from a forecast. Running it requires language the team can share precisely.

    Research on verbal probability language shows how thin the default vocabulary is. When someone says a risk is "likely," receivers interpret the word across a span of forty to fifty percentage points. Sender and receiver both leave the room confident they are aligned, without any empirical basis for the confidence.

    Information · The Theoretical Floor
    Information is the resolution of uncertainty. A message has value in proportion to how much it narrows the space of what the receiver does not know. Claude Shannon's 1948 result applies directly to risk language. Verbal descriptors widen that space. Dimensional scores narrow it.

    Strategic trade-off conversations need a denser medium. A picture the whole team can read at the same time, in the same vocabulary, against the same ground.

    IV
    What PRISM does

    Refract the Status Report
    Into the Shape of the Bet.

    PRISM stands for Portfolio and Program Risk Intelligence, Scoring and Monitoring. It takes a program's "on track" status report and refracts it into nine risk dimensions. Nine facets of the same program, each scored on a 0 to 100 scale grounded in Shannon entropy. Low scores mean the facet is controlled and predictable. High scores mean it is uncontrolled and unknowable.

    White light entering a prism is all frequencies in superposition. Maximum optical entropy. The exiting spectrum is structured and legible. PRISM does this for program risk.

    PRISM · The Refraction
    ON-TRACK STATUSMAX ENTROPYD1 STRATEGIC SCOPED2 ARCHITECTURED3 DELIVERYD4 CAPABILITYD5 INTEGRATIOND6 CYBERSECURITYD7 COMPLIANCED8 DATA & AI GOVD9 RESILIENCE · JOINTC T OC I S O
    An "on-track" status report enters as white light, maximum entropy, and exits as nine legible risk dimensions. The first four are the CTO lens, the next four the CISO lens, and the ninth is scored jointly.

    The first four dimensions form the CTO lens. Strategic scope. Technical architecture. Delivery and execution. Organizational capability. Together, they ask whether the program can be built and delivered predictably.

    The next four form the CISO lens. Integration and third-party risk. Cybersecurity. Compliance and regulatory. Data and AI governance. Together, they ask whether the program can ship safely and legally.

    The ninth is a joint lens. Operational resilience. Can the system fail safely, recover quickly, and keep the business running under stress. The CTO and CISO score this one together. The answer lives in the handoff between them.

    A program that delivers on time and ships insecure architecture has failed. A program that ships securely and misses its delivery dates has also failed. PRISM holds both lenses in the same view.

    Each dimension carries a small set of binary questions that do most of the diagnostic work. PII in LLM context windows without masking. Agents with write access beyond their defined function. Training data with no documented lawful basis. A "no" answer to a hard-gate question forces a minimum score, regardless of how good the rest of the program looks.

    The scoring converges a cross-functional team on the same picture. The spider chart that falls out of the session is the governance artifact. The shape of the polygon tells the story before anyone reads the numbers.

    V
    A living loop

    Orient. Decide. Act.
    Observe Again.

    Observation, orientation, decision, action. The OODA loop runs at every altitude of an enterprise. Most organizations can observe. Most can decide. The work of orienting, turning scattered signals into a legible picture of what is actually happening in front of this program right now, is where the loop tends to stall.

    PRISM anchors that work.

    A program's first PRISM profile gets built in a ninety-minute cross-functional session, with both lenses in the room. From that moment the profile is a living artifact. A map you read as you move. A completed DR test moves D9 toward controlled. An open OWASP LLM finding moves D6 the other way. Sprint reviews and architecture decisions update the picture. The profile is always the current state, not a snapshot from three months ago.

    Scores are shorthand. The conversation they enable is where the value sits. Decide and Act happen against a picture the whole governance table can read together. After action, the next Observe cycle refreshes the profile with what actually happened. The loop continues.

    Two Instruments, One Capability
    The 7·7·27 Sensing Gap Diagnostic, the first ForesightOps instrument, asks whether the organization can sense its environment well enough to feed strategic foresight. PRISM asks the portfolio-level companion question. For each funded program, does the cross-functional team have enough resolved uncertainty to place a deliberate bet. Different altitudes, same capability. Read the ground, together, before you commit.

    Risk has two sides. The downside is the obvious one. The upside is where most enterprises leave capability on the table.

    An organization that can name its risks precisely can also name its appetite precisely. It carries a high technical architecture score on a deliberately ambitious program because the strategic upside is worth the exposure. It holds a hard line on a cybersecurity dimension because the AI Act exposure is larger than the deal. Those are human decisions. They get sharper when the picture is shared.

    The conditions ahead are often described as TUNA. Turbulent, uncertain, novel, and ambiguous. TUNA rewards clarity over certainty. A cross-functional team that can read the full spectrum of a program's risk, together and in real time, adapts faster and catches binding constraints earlier. Visual clarity across the spectrum is what makes resilience and adaptability possible under pressure.

    The organizations that come out of this turning point strongest will be the ones that did the orienting work together, cycle after cycle. PRISM is one way to build the shared picture that work depends on.

    PRISM is designed to be read cross-functionally, with both the CTO and the CISO at the table, and to live across the life of the program rather than land as a one-time assessment. If you would like to bring PRISM into your organization, as a workshop, a pilot on a funded program, or a portfolio-level governance install, reach out. The conversation is worth having before you need the answer.
    References
    1 IBM Security and Ponemon Institute (2025). Cost of a Data Breach Report 2025. IBM Corporation. Study of 600 breached organizations across 17 industries.
    2 Gartner (2025). "Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027." Press release, June 25, 2025.
    3 Bloch, M., Blumberg, S. and Laartz, J. (2012). "Delivering large-scale IT projects on time, on budget, and on value." McKinsey Quarterly, October 2012. Research with the BT Centre for Major Programme Management at the University of Oxford across 5,400+ projects.
    4 Shannon, C.E. (1948). "A Mathematical Theory of Communication." Bell System Technical Journal, 27: 379–423, 623–656.
    5 Willems, S.J.W., Albers, C.J. and Smeets, I. (2020). "Variability in the interpretation of Dutch probability phrases." JCOM, 19(02), A03.
    6 Perez, C. (2002). Technological Revolutions and Financial Capital: The Dynamics of Bubbles and Golden Ages. Edward Elgar.
    7 Mintzberg, H. (1994). The Rise and Fall of Strategic Planning. Free Press.
    8 Compo, P. (2022). The Emergent Approach to Strategy: Adaptive Design & Execution. Business Expert Press.
    9 Hamel, G. (1996). "Strategy as Revolution." Harvard Business Review, July–August 1996.
    10 Boyd, J. (1996). The Essence of Winning and Losing. OODA loop lectures.
    11 European Parliament (2024). Regulation on Artificial Intelligence (AI Act), Articles 5, 99, 101. Entered into force August 2024; enforcement phased through 2026.
    12 Supporting frameworks: NIST Cybersecurity Framework 2.0 (2024); NIST AI Risk Management Framework 1.0 (2023); ISO/IEC 27001:2022; ISO/IEC 42001:2023; OWASP LLM Top 10 v1.1 (2023).
    Will Evans
    Founder and Chief Strategy Officer at Fugue Strategy Advisors and creator of ForesightOps and PRISM. Thirty years at the intersection of strategy design, strategic foresight, and innovation. Fortune 50 engagements across fintech, pharma, healthcare, travel, and e-commerce. Founder of LeanWX NYC. Lecturer at NYU Stern School of Business.
    ← Back to Insights