# Provable Cyber Resilience (CybersecurityExpert.co.uk) > Provable Cyber Resilience is an independent cybersecurity assurance research platform that tests whether cybersecurity controls actually work under real operational conditions, rather than simply existing as policy or documentation. Founded by David Whitelegg, founder of the IT Security Expert blog, with more than 25 years of cybersecurity leadership experience. The platform's central focus: most organisations can show that controls are implemented, but far fewer can prove those controls remain effective under stress, change and time. The site combines research, commentary and a set of free interactive AI Labs tools, built on the Invisible Risks frameworks, to explore that gap in practice. ## Core Concepts - Control effectiveness: whether a control operates reliably in practice, not just whether it exists or is documented. - Evidence-led cybersecurity: grounding assurance claims in current, independently testable evidence rather than inherited assumptions or compliance artefacts. - Cyber resilience: the ability of an organisation's services to withstand and recover from disruption. - Exposure: how vulnerable a critical service is, based on control strength, dependencies and recovery readiness. - Operational resilience: how failures and dependencies propagate across services under pressure. - Minimum Viable Organisation (MVO): the smallest set of services an organisation cannot operate without, and whether its continuity plan restores them first. - Drift and remediation: the gap between a remediation's original fix date and its real status, including deferral language that can mask it. - Assurance drills: tabletop exercises structured to produce evidence, not just discussion. - Dashboard and metric integrity: whether metrics reported to boards and executives are genuinely sourced, validated and owned. - Control failure: how a weak or failed control escalates into real incident impact across a service or environment. ## AI Labs Eight free, interactive tools, no sign-up required. - [AI Labs overview](https://www.cybersecurityexpert.co.uk/ai-labs): Introduction to the full set of tools and the concepts they test. Simulate and explore: - [Assurance Drill Generator](https://www.cybersecurityexpert.co.uk/assurance-drill-generator): Generates a tabletop drill tailored to a chosen critical service, with each stage specifying the assurance evidence it should produce. - [Control Failure Simulator](https://www.cybersecurityexpert.co.uk/control-failure-simulator): Simulates how a control weakness can escalate into a real-world incident across services and environments. Assess exposure and prove controls: - [Threat Exposure Assessor](https://www.cybersecurityexpert.co.uk/threat-exposure-assessor): Scores how exposed a critical service is to real-world threats, based on control strength, dependencies and recovery readiness. - [Control Assurance Validator](https://www.cybersecurityexpert.co.uk/control-assurance-validator): Tests whether a control genuinely works, using failure-based evidence logic rather than compliance assumptions. Map resilience and test the plan: - [MVO Mapper](https://www.cybersecurityexpert.co.uk/mvo-mapper): Identifies the minimum set of services an organisation cannot operate without and checks whether its continuity plan restores them first. - [Operational Resilience Mapper](https://www.cybersecurityexpert.co.uk/operational-resilience-mapper): Maps critical services, dependencies and failure paths to show how disruption spreads and where resilience breaks down. Prove reporting and remediation: - [Dashboard Integrity Score Auditor](https://www.cybersecurityexpert.co.uk/dashboard-integrity-auditor): Scores whether board- and executive-reported metrics are genuinely evidenced, sourced, validated and owned. - [Drift-to-Fix Tracker](https://www.cybersecurityexpert.co.uk/drift-to-fix-tracker): Measures how far remediation fix dates have slipped from their original commitments and flags deferral language in status updates. ## Provable Platform (in development) - [Provable Platform](https://www.cybersecurityexpert.co.uk/provable): The platform's future direction — a continuous cybersecurity assurance environment intended to extend the AI Labs' single-shot assessments into ongoing control validation, drift detection, and unified evidence-based reporting. Currently in development; the AI Labs tools remain the free, available implementation of these ideas today. ## About & Background - [About Provable Cyber Resilience](https://www.cybersecurityexpert.co.uk/about): The platform's purpose, independence, and the gap between reported security posture and operational reality that it focuses on closing. - [About David Whitelegg](https://www.cybersecurityexpert.co.uk/david-whitelegg): Background on the platform's founder. - [What Is Cybersecurity Control Effectiveness?](https://www.cybersecurityexpert.co.uk/what-is-cybersecurity-control-effectiveness): Explains the difference between compliance and control effectiveness. - [What Is Evidence-Led Cybersecurity?](https://www.cybersecurityexpert.co.uk/what-is-evidence-led-cybersecurity): Explains the evidence-led approach to cybersecurity assurance. - [The Book](https://www.cybersecurityexpert.co.uk/book): A forthcoming book on cybersecurity assurance, evidence and resilience by David Whitelegg. Currently unpublished and under consideration by a publisher. ## Optional - [IT Security Expert Blog](https://blog.itsecurityexpert.co.uk): Independent cybersecurity commentary blog founded in 2007 by David Whitelegg. A separate, longstanding publication that forms the historical foundation of this work.