Evident Research

The Hidden Cost Explosion

AI finds more risk. Supplier dependence, regulatory clocks, insurer proof, and board defensibility turn that risk into administrative work. The hidden cost is the work of proving security across all of those surfaces at once.

2022 baseline3.4x modeled workload by 202816% interaction share
Finding pressure5.4
Supplier exposure2.3
Regulatory clocks2.4
Insurance proof2.0
263%

CVE submission growth from 2020 to 2025, cited from NIST.

37.4h

Average weekly vendor assessment work in Whistic's 2025 survey.

84%

Initial supplier assessments requiring follow-up in the same survey.

24/72h

Regulatory clocks increasingly convert proof into timed work.

interactive dataset

Inspect the public evidence and the model assumptions.

data mode
postgres24 tables registered
view

Proof work grows fastest when the pressures collide.

This model starts 2022 at a baseline and shows how finding volume, supplier review, regulatory clocks, and insurance proof combine into more administrative work.

Download CSV
3.4x

Modeled growth in proof workload from the 2022 baseline to 2028.

16%

Share of the 2028 modeled workload created by interactions between drivers.

Finding pressure5.4More discovered and enriched risk signals.
Supplier exposure2.3More vendor review, follow-up, and response lag.
Regulatory clocks2.4More classification and evidence work on deadlines.
Insurance proof2.0More control evidence, renewal, and claim-readiness work.

Modeled index, not a market forecast. Replace assumptions with run data.

drilldown

Row detail

Select a row to see the fields behind the chart. Public-source rows carry source IDs and caveats where the source provides them.

year
2028
Finding pressure
5.4
Supplier exposure
2.25
Regulatory clocks
2.4
Insurance proof
2.05
Supplier interaction
1.2302
Regulatory interaction
0.729
Insurance interaction
0.3113
Direct driver load
12.1
Work created between drivers
2.2705
Modeled proof workload
14.3705
Interaction share
0.158
source tier
Evident model
caveat
Indexed model from the research paper; not a measured market forecast.
one level above compliance

Optimization target: economic impact, not just passing proof.

Evident's trust graph should not stop when proof exists. It should ask whether proof was rejected, whether an incident created real cost, whether admin cost missed its target, and where reusable evidence can reduce the next cycle.

triggerobligationworkproofeconomic impact
source registry

Every public claim stays attached to a source tier and caveat.

PublisherSourceTierStatus
AI Incident DatabaseAI Incident Database SnapshotsPublic primaryregistered
CISAKnown Exploited Vulnerabilities CatalogPublic primarydownloaded_1623_records
Cloud Security AllianceSTAR Level 1 Security Questionnaire CAIQ v4Public primaryregistered
CVE ProgramCVE List V5Public primaryregistered
European CommissionCyber Resilience Act Reporting ObligationsPublic primaryregistered
European UnionDigital Operational Resilience ActPublic primaryregistered
European UnionNIS2 DirectivePublic primaryregistered
FIRSTEPSS Current ScoresPublic primarydownloaded_341602_records
HHS OCRBreach Portal Notice to the Secretary of HHS Breach of Unsecured Protected Health InformationPublic primaryregistered
MITRECWE ListPublic primaryregistered
MITREMITRE ATLAS DataPublic primaryregistered
NAICCyber Insurance ReportPublic primaryregistered
NAICReport on the Cybersecurity Insurance MarketPublic primaryregistered
NISTNVD CVE API 2.0Public primarydownloaded_4000_records
OMB/OIRAOMB/OIRA Paperwork Burden InventoryPublic primaryregistered
OWASP FoundationOWASP Top 10 for LLM ApplicationsPublic primaryregistered
SECCybersecurity Risk Management, Strategy, Governance, and Incident DisclosurePublic primaryregistered
Shared AssessmentsWhat's New in the 2025 SIG UpdatePublic survey/vendorregistered
WhisticThird-Party Risk Management 2025 Impact ReportPublic survey/vendorregistered