The question
Cyber insurers publish the controls they require before they will bind a policy. This study asks a plain question: how much faster does a defender bring an environment from its default state up to that published baseline with AI help than without it.
The method
The target is a named carrier's published application, chosen and hashed at freeze so the bar is theirs, not ours, and anyone can check it. Two arms: the same defender working alone, and working with an AI assistant that advises and drafts while the defender makes every change. A control counts only when we verify it in place, probed rather than taken on the operator's word, and we report the rate of controls claimed but not actually holding as a result in its own right. The two arms run across different environment variants in counterbalanced order, and the design's limits are written into the protocol up front.
Publication transparency
Time to verified completion, the unverified-claim rate, and the full protocol, whichever way the result falls.