Introduction
X-Analytics and Drata are now integrated.
Through the Drata MCP connector and the Drata-specific AI tools, Drata's continuous control monitoring data feeds your X-Analytics cyber risk profile, where control status becomes control effectiveness, control effectiveness informs annualized loss exposure, and X-Analytics returns a prioritized set of risk reducing actions.
Drata covered the partnership in its Partner POV on X-Analytics. The two solutions address complementary halves of one problem: Drata continuously monitors control implementation and maintains an evidence-backed view of control status, while X-Analytics measures cyber risk exposure in financial terms and prioritizes the actions that carry the greatest risk reducing benefit. The capabilities and full setup guide are below.
Key Capabilities
- X-Analytics Profile Informed by Drata: With the Drata MCP connector + the selected Drata-Specific AI Tool, users can inform their NIST CSF 2.0 and CIS CSC 8.1 frameworks leveraging their Drata DCF results.
- Financial Exposure Translation: By leveraging Drata DCF results, X-Analytic provides a determination of cyber risk in financial terms and prioritized guidance. The DCF data maps into a specific framework (such as NIST CSF 2.0 or CIS CSC 8.1) to inform overall control effectiveness, which further informs annualized loss exposure.
- Prioritized Risk-Reducing Actions: After X-Analytics determines your cyber risk posture in financial terms, it provides a ranking of NIST CSF categories and CIS CSC controls that offer the most risk reducing opportunity if fully implemented. This is critical in risk management, and this proves that all framework controls are not equal in risk reducing value.
- Agent-Driven Updates: At any time, you can run the Drata-Specific AI Tools in X-Analytics to calibrate your risk cyber risk profile, and to gain access to a revised prioritized list of actions.
Prerequisites
- Drata account holder must have Drata permissions to create API keys.
- Drata account holder must also have an X-Analytics account, which grants permission to create MCP Connectors.
- Within X-Analytics, the Drata account holder must have access to at least one configured profile to associate the Drata MCP Connector. An X-Analytics profile is a complete cyber risk model for a specific, measurable entity (such as your whole organization, a business unit, a region, an acquisition, or even a critical application or process). X-Analytics scopes cyber risk in dollars, threat scores, control effectiveness, mitigation opportunities, reports, etc. to a profile.
Permissions & Data Table
The X-Analytics Drata MCP Connector requires a direct API integration between X-Analytics and Drata. Creating an API Key within Drata is easy. You just need to navigate to Settings (left navigation bar), select API Keys, and then select Create API Key (top right side of dashboard). For ease, you can select all read and write for Scope Access.
At a minimum, the following tools must be configured with Read access.
| Permission/Scope | Why It's Needed | Data Accessed |
| drata_workspaces_list | Allows X-Analytics to access relevant Drata workspaces | List Workspaces (read) |
| drata_frameworks_list | Allows X-Analytics to access relevant control frameworks in Drata | List Frameworks (read) |
| drata_controls_list | Allows X-Analytics to read control status and readiness so control posture can be scored in the cyber risk profile | List Controls (read) |
| drata_controls_get | Enables X-Analytics to get control scores so control posture can be scored in cyber risk profile | Get Control (read) |
Step-by-Step Setup
Step 1: Create a Drata API Key
- Log into your Drata account.
- Go to Settings (left navigation bar), select API Keys, then select Create API Key (top right side of dashboard).
- Within the Create API Key screen, answer the questions under Basic Details, then select Next.
- Now you need to define Scope Access. For ease, you can just select All Read and Write under Set Scope for All, and then select Save and Finish.
- Copy the API key and paste into a secure location. You need this information to establish the X-Analytics Drata MCP Connector. If you misplace or lose this API Key, you will need create a new API Key.
- At this time, find your Drata Connector URL (such as https://public-api.drata.com)
Step 2: Within X-Analytics, Create Drata MCP Connector
- Log in to your X-Analytics account.
- In the left navigation bar, select Settings, then select Manage Connectors, within "Connectors settings for profile" select the profile you want informed by Drata.
- Under MCP Name, you will see Drata, select Connect. In a new pop-up window, enter your API URL and API Key, and select Connect.
- In a new screen, you will see a list of all tool permissions. The default setting is "ask each time", which means X-Analytics will ask you for permission upon each use. Within this screen, you can change each Drata tool to "always allow" or "block". After making necessary changes on this screen, select the back button (next to the Drata title bar).
Step 3: Run the select Drata Agent, within X-Analytics' AI Tools
- Go to Insights and select your associated profile (using the profile drop down selector).
- Go to AI Tool (within the left navigation bar), search Drata (within the search field), chose which Drata AI tool you want to use, and select "Inform ..."
- Follow the directions within the Drata AI tool. If you select to use inform your profile using Drata, then this will result in downstream updates to your cyber risk exposure and prioritized guidance.
Step 4: After Updating Your Profile Using Drata
- Go to Insights and view how Drata data updated your cyber risk exposure.
- At this time, you can leverage all X-Analytics insights and tools to make prioritized decisions, simulate investment/divestment decisions, and generate new shareable artifacts to articulate your cyber risk updates.
Important Notes
You can completely control Scope Access between Drata and X-Analytics.
If you lose your API key, then you will need to create a new API Key and establish a new X-Analytics Drata MCP Connector.
With any active Drata MCP Connector, you control the use and frequency of running the X-Analytics specific Drata AI tools. Additionally, all X-Analytics AI tools require human-in-the-loop to ensure you authorize all changes to your X-Analytics profile.
Questions
Existing X-Analytics customers can contact their Customer Success Manager for help creating the Drata MCP connector or choosing which profile to inform with Drata data.
Drata customers who are new to X-Analytics can request a demo to see control monitoring data translated into financial cyber exposure and prioritized action.
For anything else, reach us at customersuccess@x-analytics.com.