COMING SOON [PERCH] is in final pre-launch. Be the first to know when it goes live. Get launch updates
INDUSTRIAL CYBER RISK · OT

Cybersecurity is complex. Getting started shouldn't be.

[PERCH] is your self-guided journey to cyber confidence — configured by certified specialists and supported by AI at every step. Know exactly where you stand, what to fix first, and how you compare to your market — and watch your resilience grow, week after week.

[PERCH] · DAILY HOME
[PERCH] Home with the guided [PERCH] Path wheel and prioritized roadmap
JOURNEY NIST CSF 2.0 EXPOSURE ISA/IEC 62443 EVIDENCE DECLARED NEXT STEP ALWAYS NAMED
[PERCH] PATH
6
Guided NIST functions
Guided by the six NIST CSF 2.0 functions Nothing to install — no sensors, no agents Threat intelligence included in every plan
BUILT ON INTERNATIONALLY RECOGNIZED STANDARDS
NIST CSF 2.0 ISA/IEC 62443 CISA KEV & ICS MITRE ATT&CK/ICS
WHAT [PERCH] IS

Understand where you are. See where to go. Get there — guided.

[PERCH] is a cybersecurity maturity and performance platform that puts your whole journey in one place: risk, maturity, performance, compliance and actionable guidance. It prioritizes the improvements that pay off first, benchmarks you against your market, and through PULSE keeps you connected to reality — the attacks hitting your sector right now, mapped to your own asset inventory, with clear guidance on how to protect it. And you're never alone: our AI assistant supports the entire journey, clearing doubts about any question, any result, any next step.

THE BACKBONE — [PERCH] PATH

A guided journey through the six NIST CSF 2.0 functions.

You are never lost. [PERCH] always shows where you are, what's missing and what the next step is. Work saves automatically and resumes exactly where you stopped — and finishing a step in any area counts as progress on the journey.

GOVERN

Who decides, what matters, how much risk is acceptable?

Organization and site identity, criticality, stakeholders, risk tolerance and regulatory context.

IDENTIFY

What exists, what's critical, what do we know?

Declared asset inventory (manual or CSV/XLSX import), criticality review and risk context enriched with threat intelligence.

PROTECT

Which safeguards exist, and where are the gaps?

Access and identity controls, declared segmentation, exposure posture, configuration review and improvement actions.

DETECT

Can we observe a relevant change?

Detection readiness, data sources, declared baseline and observations recorded in the Journal.

RESPOND

Can we investigate, decide and act?

Response readiness, roles and escalation, investigation records, threat context and response actions.

RECOVER

Can we restore, validate and learn?

Recovery readiness, backup freshness evidence, continuity, action validation and lessons learned.

A note on language: in [PERCH], "complete" means the journey activity was done — never that a security function is "solved". We keep that distinction inside the product, and we keep it here.

AI-GUIDED · EXPERT-CONFIGURED

AI that guides you. Specialists who stand behind it.

Plenty of tools promise "AI-powered security". Here is what that actually means in [PERCH] — and why you can defend every number it gives you.

The engine: classic AI, expert rules — not a black box

The [PERCH] scoring engine is built on classic AI and machine learning, running on rules established by our team of certified cybersecurity specialists. Every score, priority and recommendation traces back to expert-defined logic you can explain to a board or an auditor — it never comes out of an unexplainable black box.

The assistant: AI support across the entire journey

From your very first question to your executive report, the built-in AI assistant is at your side — clarifying what a questionnaire item means, explaining what a result implies, and suggesting what to do next. No specialist on staff required: the journey explains itself.

The foundation: internationally recognized standards

Everything is anchored in NIST CSF 2.0 and ISA/IEC 62443 — the frameworks boards, insurers and regulators already recognize. New to these standards? We explain each one in plain language in our FAQ.

[PERCH] · AI ASSISTANT AT WORK

The built-in assistant clarifying questionnaire items and explaining results — AI support from the first question to the final report.

INSIDE THE PRODUCT

Six areas, one continuous journey.

Everything connects back to the same profile — so work done anywhere counts as progress everywhere.

01

Daily Home

Your return screen. Three decision paths — the function wheel, the prioritized roadmap and priorities by function — plus one recommendation with visible reasoning that you're free to dismiss. Every morning, one question: what should I do first today?

02

[PERCH] Path

The guided journey itself. Each step shows its purpose, status, evidence base, confidence level and the action to continue. Your team doesn't need a NIST specialist to start — the product leads, step by step, in your team's language.

03

Operations — Assessment

A structured questionnaire about your environment: sector, sites, shutdown criticality, OT usage, vendor and remote access, MFA, segmentation, backups, detection and response. One session of objective questions produces the prioritized picture — installing nothing, touching nothing in the plant.

04

Operations — Dashboards & Actions

Executive and technical views: Overview, Performance, Cyber Risk, Frameworks, Assets & Pulse, Benchmark, Roadmap, Report and History. Actions is where remediation lives — every action with an owner, a deadline, a status and validation by evidence.

05

Exposure — 62443 & External Threats

Self-assessment guided by ISA/IEC 62443 with Security Level Targets per zone, plus the weekly sector threat publication: activity level, campaigns, techniques, prioritization candidates and recommended defenses — mapped to your declared environment.

06

Strategic Profiles & Administration

Journal, Current Profile, Target Profile, Gap Analysis and Improvement Plan — the one-page answer to the board's question. Plus sites, users, permissions, audit trail and MFA on every plan.

THE LONG GAME

Your profile is never rebuilt. It gets deeper.

From day one, [PERCH] builds a living profile of your site: what's true today, where you need to get to, the distance between them and what to do first. Every line carries three separate facts — what is implemented, where the evidence came from, and how much we trust it.

Evidence level What it means Availability
DeclaredYou told us, through a guided form or assessment answer.Available now
DocumentedA document or policy is attached that supports the declaration.Available now
ImportedIt came from a spreadsheet or third-party system (CSV/XLSX import).Available now
ObservedIt came from technical collection in your own environment, not from a declaration.Future evolution
CorrelatedCross-checked between independent sources that confirm each other.Future evolution
ValidatedProven by test or verification with a recorded result.Future evolution

The sentence that sums it up

The profile is never redone — it gets deeper. The same line that today reads "declared · low confidence" will read "observed · high confidence" once that evidence exists. Your history, your targets and your decisions stay intact. New evidence sources feed the same profile — no migration, no reconfiguration.

COMPETITIVE DIFFERENCE

Six things that make [PERCH] different.

01

The whole journey, on every plan

Every customer, from Starter to Alliance, completes all six NIST functions with the included features — guided forms, assessment, spreadsheet import, attached evidence. There is never a "buy more to continue".

02

Complete threat intelligence on every plan

The weekly sector publication — activity level, campaigns, techniques, actors, recommended defenses and relevance to your environment — is included in every tier. With competitors, intelligence is the premium layer. Here it's the shop window.

03

Honesty about evidence

Everything you declare is labeled as declared. What isn't known appears as "no evidence" — never as an invented good or bad score. Buying a plan or a feature never moves a score. Only new evidence moves it.

04

From advisory to traceable action

A recommendation — say, mitigating a CISA advisory — becomes an action with an owner, a deadline, a status and validation by evidence. Not a forgotten PDF. The complete trail stays auditable in the Journal.

05

An international yardstick your board understands

Exposure measured by ISA/IEC 62443, with Security Level Targets explained in plain language, and maturity by NIST CSF 2.0 Tiers — always with the concrete path to the next level.

06

Coherent pricing

Plans scale by size and governance — sites, users, collaboration — not by access to intelligence or to the journey itself. Threat intelligence is not an upsell.

STRAIGHT TALK

What [PERCH] does not do.

In operational technology, overpromising destroys credibility in the first technical meeting. So here are the limits, in writing, before you buy.

  • It does not detect intrusions or monitor traffic. There is no sensor and no NDR. [PERCH] answers the question that comes before that: am I an easy target, where, and what do I fix first?
  • It does not predict "probability of attack". Nobody can calculate that honestly. What we measure is the alignment between your exposure profile and the profile of the victims of active campaigns.
  • It does not claim an actor is in your environment. Actors are shown as prioritization candidates. Attribution belongs to CISA and the FBI, and we always cite the source.
  • It does not certify you. [PERCH] delivers guidance and structured self-assessment aligned with NIST and IEC — never certification or a formal compliance attestation.
  • It does not replace your OT monitoring platform. If you run Nozomi, Claroty or Dragos, [PERCH] complements them — it's the decision and record layer above the findings. If you don't run them, it structures the journey anyway.
  • It has no ready-made connectors today. Integration is via spreadsheet import (CSV/XLSX). Named vendor connectors and a public API are roadmap, not current capability — and we won't pretend otherwise.

See the full journey, area by area.

Explore the product Get pricing
FAIR QUESTIONS

What people ask us first.

"I already have Nozomi / Claroty / Dragos."

Good — [PERCH] doesn't replace your detection. It's the decision and record layer above it: it turns findings into prioritized risk, actions with an owner and executive evidence, independent of which technical vendor you use.

"I don't have a cybersecurity team."

That's exactly the scenario this journey was designed for. Guided forms in your language, examples, autosave, and the product always naming the next step. No stage requires a specialist or an extra tool.

"Isn't this just another questionnaire?"

The assessment is the starting point — the difference is continuity: living priorities, traceable actions, weekly intelligence for your sector, versioned profiles and an auditable decision trail. Consulting ends; the journey continues.

"How do I know the numbers are trustworthy?"

Every data point carries its origin, evidence base and confidence. What's declared appears as declared; what isn't known appears as "no evidence". And no number changes because you bought something — only evidence changes it.

PRE-LAUNCH

[PERCH] is almost ready.

We're putting the final touches on the platform. Leave your corporate email and we'll tell you the exact launch date — plus early-access pricing before it goes public.

JOURNEYSix NIST CSF 2.0 functions complete
PILOTRunning with design partners
LAUNCHGeneral availability — date to be announced soon
Please use your corporate email address — free providers are not accepted.
You're on the list. We'll be in touch the moment we go live.
THE TEAM BEHIND [PERCH]

Built by Multisum Cybersecurity & Services

Multisum is a startup dedicated to protecting the critical infrastructure that sustains modern society — from energy, water, food, and pharmaceuticals to communication and transportation systems.

Our name reflects the power of multiplying and adding: when expertise, partnerships, and purpose converge, the results are greater than the sum of their parts. [PERCH] is that idea, productized.

BEYOND THE PLATFORM
  • Cybersecurity Assessmentson-site and remote evaluations aligned with ISA/IEC 62443, NIST, CISA and CIE.
  • Business Intelligence & Data Analysisdata foundation, Tableau-driven analytics, and predictive modeling.
  • Security & BI Trainingsecurity awareness, social engineering defense, SQL and Tableau instruction.
READY WHEN YOU ARE

Plans scale by size — never by access to the journey.

STARTER
$299/mo
PROFESSIONAL
$799/mo
BUSINESS
$1,499/mo
ALLIANCE
Custom

Save 15% with annual billing — and up to 30% as a Strategic Partner.

Compare all plans