Drata's Partner POV series spotlights the leaders and teams in our partner ecosystem who are helping customers modernize security, compliance, and trust. In each installment, we share a partner's on-the-ground perspective on what they're seeing in the market—what's changing, what's proving difficult, and what's working—plus practical takeaways for building stronger, more resilient programs.
In this edition, we're joined by John Frazzini, CEO of X-Analytics. He shares what's top of mind for teams trying to put AI to work on real risk decisions—and why pairing Drata's continuous, evidence-backed control monitoring with X-Analytics' patented cyber risk intelligence helps organizations move from measuring compliance to measuring, and reducing cyber risk.
Introducing X-Analytics
Cybersecurity has no shortage of metrics: vulnerability counts, alert volumes, patch rates, control coverage, and more. Yet despite all of it, security teams are still looking for a practical, systematic, and defensible way to prioritize actions by risk reduction. That's what X-Analytics solves.
Through its market-proven and patented cyber risk ontology, X-Analytics measures an organization's exposure to cyber risk and automatically connects it to the actions that reduce it. In minutes—and with the data, processes, and context a team already has—X-Analytics generates a dynamic cyber risk profile that leaders use to prioritize risk-management decisions.
Because it models exposure from every angle and retains that context over time, an X-Analytics cyber risk profile compounds with every change, evolving as the threat environment shifts, as the business grows, and as the program improves. The result is a repeatable, personalized, and agentic approach that turns program data into prioritized, pragmatic guidance.
What Led X-Analytics to Partner With Drata
What drew X-Analytics to Drata, Frazzini told us, was a shared sense of purpose. "Drata has built its business around supporting its customers, earning their trust, and helping them prove it," he said. "That emphasis on trust is exactly what drew us in. We feel strongly about our own principles, and everything we build comes back to one goal: empower a more resilient world. When we looked at how Drata operates, we saw a company that feels the same way. That alignment—more than any single feature—is what made the partnership make sense."
It has only grown from there. What began as a shared read on the customer's problem—that knowing your control posture and knowing what to do about it shouldn't live in separate places—became a two-way integration that closes the loop between them. As the two companies have worked together, the collaboration has deepened around that same idea: giving customers a clearer path from where they stand to the actions that make them more resilient.
Top of Mind Challenges
The most common theme Frazzini and the X-Analytics team see right now is that AI is accelerating both the pace of threats and the volume of signals security teams must sift through. With more data to process and less time to remediate, teams need to quickly and reliably distinguish between what matters and what's just noise.
Customers come to X-Analytics with questions their existing tools can't answer on their own:
- "What's our exposure, and are we getting better or worse?" X-Analytics measures cyber exposure, benchmarks it against industry peers, and tracks how it moves over time—so teams can show the value of the program through the improvements they've made.
- "What mitigation investments reduce the most risk?" X-Analytics’ cyber risk intelligence ranks available actions by the exposure each one reduces, so budget goes to the controls that move risk the most.
- "Which vulnerabilities present the greatest exposure?" X-Analytics prioritizes vulnerabilities by the risk they actually carry, not severity alone, so the ones carrying the most risk rise to the top.
- "How much risk does this acquisition present, and what should we do about it?" X-Analytics measures a target's cyber exposure and connects it to remediation, so teams can price the risk and plan before and after close.
- "How much exposure does this supplier introduce, and how should we manage it?" X-Analytics models the exposure a given supplier adds to the profile, informing everything from tightening the relationship to setting liabiltity coverage requirements.
Security, Compliance, Risk, and Trust Trends
The clearest trend the X-Analytics team reports: risk and compliance teams are hitting a wall on the way to letting AI inform real risk decisions. Leaders believe in the technology, but few are willing to hand it a decision that actually matters.
The reason is that AI is only as good as the context and structure it's given. Point a capable model at raw program data and you get answers that sound right but can't be trusted, defended, or replicated. The goal hasn't changed—these teams are still trying to reduce exposure—but without a systematic way to aim AI at it, they generate more work instead of less risk. The differentiator isn't the model everyone can access; it's the structure you feed it and the model you leverage.
In cyber risk, that structure is a cyber risk management ontology: a consistent, well-defined way to represent exposure, controls, threats, and the relationships between them. It's the structure that allows you to build a harness that lets AI reason about risk on solid ground, instead of guessing—the difference between AI you can demo and AI you can stand behind.
That's exactly what X-Analytics is built on. Its patented, market-proven ontology is what lets X-Analytics' agentic solution turn raw program data into prioritized, business-ready guidance. While much of the market raced to bolt AI onto existing approaches, X-Analytics built the foundation first.
The Underestimated Shift
The most underestimated shift is that the constraint in cyber risk has moved from detection to decision. For years, the hard part was seeing risk. Today, visibility is no longer the problem—the problem is what to do with all the data.
“When you have more signals than ever, the advantage goes to whoever can prioritize them systematically and consistently. Seeing risk is table stakes now. Deciding what to do about it is what sets programs apart.” says Frazzini.
That makes risk management a matter of deciding, not just detecting and remediating. The information teams need is usually already in the tools they own; what's missing is a consistent way to turn it into a ranked, defensible set of actions. It's the principle X-Analytics is built on: connect to what you already have, measure the exposure behind what it surfaces, and show which actions reduce the most risk. AI acts fast. The question is whether it's acting on the right instructions.
How Drata + X-Analytics Work Together
Drata and X-Analytics solve two halves of the same problem. Drata continuously monitors control implementation status and keeps a live, evidence-backed view of where controls stand. X-Analytics interprets that implementation status as control effectiveness, measures what it means in terms of cyber risk exposure, and ranks the actions that reduce the most risk. Together, they close the loop between knowing the state of your controls and knowing what to do about it.
In practice, Drata's control implementation status flows directly into X-Analytics, giving the cyber risk profile a continuously monitored view instead of a point-in-time snapshot. X-Analytics ingests that data to measure exposure and prioritize the control improvements that reduce the most risk, then pushes those actions back into Drata as tasks, so teams act on them where they already manage their controls. Measure, prioritize, act, and re-measure, all without changing the program.
This is something neither product does alone. A control and compliance view tells you where you stand, but not which gaps carry the most risk or which to fix first; risk intelligence needs current control data (context) to stay accurate. Bring them together and every control carries a risk value, every task is ranked by the exposure it reduces, and compliance work becomes measurable risk reduction. Drata customers gain risk intelligence embedded into the program they already manage, while X-Analytics customers gain real-time control posture feeding their risk context.
Where Customers See the Biggest Gains
The combination pays off most anywhere a team turns control status into a decision. A few workflows benefit most:
- Risk-based control prioritization. Rather than working the compliance checklist top to bottom, teams focus on the control gaps that reduce the most risk. Drata shows where controls stand, X-Analytics ranks the gaps by the risk each carries, and the prioritized work feeds back into Drata. Security and GRC teams benefit most, because their day-to-day effort now maps directly to risk reduced.
- Board and executive reporting. Compliance posture is hard to translate on its own. Together, "we're 95% compliant" becomes "here's our exposure, and here's how much it has fallen as we've closed gaps." CISOs, executives, and boards benefit because they can communicate in a shared language.
- Budget and investment decisions. When it's time to decide where the next dollar goes, the combination shows which control investments buy down the most risk per dollar. CISOs and CFOs benefit because spend is always tied to a measurable, explainable business case.
- Continuous audit and risk readiness. Because Drata monitors controls continuously, the X-Analytics risk profile stays current between audits—so teams walk into an assessment, or a board meeting, with an up-to-date view instead of a point-in-time snapshot.
Across all of these, the pattern holds: the people doing the work get a prioritized path through it, and the people funding it can see the return. Compliance effort and risk reduction finally point in the same direction.
Why the Pairing Clicks for GRC Teams
What resonates most with X-Analytics customers is Drata's continuous control monitoring. Control effectiveness stays current in Drata and feeds directly into X-Analytics, so the risk intelligence stays current too — and customers watch their exposure move as their controls improve. "That live connection is what makes the pairing special," says Frazzini. "For many teams, it's the first time in GRC they can easily and defensibly draw the line between risk and compliance."
What's Coming Next
X-Analytics has been on a long journey toward a single mission: helping businesses reduce risk. First, the team built its cyber risk ontology. Then it validated that ontology with the toughest customers imaginable—insurance carriers who wrote it into their underwriting, one of the world's most complex enterprises that used it to shape strategy, and private equity firms that rely on it to govern cyber risk across a combined portfolio of more than $1 trillion. From there, X-Analytics re-architected its solution to harness what's now possible with AI.
The next step, and what Frazzini is most excited to bring to the partnership, is enabling businesses to own their cyber risk intelligence—building on the same continuous, evidence-backed foundation the Drata integration provides. More to come soon.
See what X-Analytics + Drata can do for your organization today.

