Cyber:GRC
Sign in
ISO/IEC 27001:2022 aligned

 Information security management, in one place.

Supplier assurance and agreements, ISMS projects and change control, incidents, identity governance, backup and disaster recovery, XDR log intelligence and threat hunting, registers and board reporting — every module sharing one 3×3 risk methodology and one audit trail.

3×3

Single risk methodology across suppliers, projects and exceptions

Annex A

Controls mapped to policies, evidence and supplier answers

XDR

Cross-domain telemetry, detections, hunting and attack-graph investigations

Onboarding → assessment → agreements → audit

Supplier assurance

Supplier register

Legal entity, hosting, classification and representatives with every linked artefact in one file.

Magic-link assessments

Suppliers answer the ISO 27001:2022 questionnaire without an account; evidence lands on the record.

3×3 CIA risk scoring

Inherent and residual ratings on a strict likelihood × impact matrix, banded Low / Medium / High.

NDA, DPA & ISA lifecycle

Template-versioned agreements, dual e-signature and a full envelope event trail.

Audits & sign-off

Annual supplier audits with evidence capture, R&CC review and a PDF sign-off pack.

Cloud docs & exit plans

Provider T&Cs, DPAs, sub-processor lists and enforced data-portability exit plans.

Initiation → design → build → test → closure

ISMS projects & change

ISMS project register

Initiation → Design → Build → Testing → Deployment → Closure, gated by R&CC approvals.

ISO Specification (SSOW)

AI-drafted scope of work mapped to Annex A controls, versioned and approved before build.

Risk & residual acceptance

Extract risks from the specification, treat them, then formally accept residual risk on the matrix.

Change control

Project and BAU change requests, external token approvers and append-only implementation logs.

Tasks, DPIAs & BIAs

AI-assisted planning linked to risks and changes, with DPIA and BIA generators.

Corrective actions

CAPAs from findings and incidents with owners, due dates, evidence and lock-on-completion.

Backups, DR, configuration, incidents & secrets

Operations & resilience

Backup monitoring

Veeam job ingestion, plan-vs-actual coverage and missing-backup alerting per server.

Disaster recovery

Runbooks, tested status and replication tracking across the Hyper-V estate.

Configuration & CMDB

Approved baselines, CI references, immutable revision history and MS-Info viewer.

Incident management

Lifecycle, evidence, RCA, SLA clocks, regulatory notification advice and PIR generation.

Device inventory

Live host inventory with BitLocker posture, groups and access permissions.

Password register

AES-256-GCM secrets with per-record permissions, reveal logs and step-up MFA.

Entra ID, multi-domain AD, GPO and bulk change

Identity governance

Identity (Entra)

User lookup, licence review, sign-in log analysis and account state management.

On-premises AD

Mirrored users, groups, computers and OUs across multiple domains, with revisions and one-click reversion.

Provisioning & offboarding

365 account creation, licence pools, group management and clean-down without deletion.

AD topology explorer

Live directory graph with drag-and-drop OU moves, search-to-expand and in-place user creation.

Bulk attribute management

Filtered targeting, impact preview, ADSI write-back and full rollback of any bulk change.

Policy Studio & directory GPOs

Describe intent in plain English to draft Group Policy, or harvest and edit existing GPOs via the agent.

AD & M365 reports

24 prebuilt reports including lockout analysis, licence usage and sign-in risk.

Telemetry → detection → hunting → response → investigation

XDR Log Intelligence

XDR Log Intelligence

Windows event telemetry from HMAC-signed agents, agent health and host risk scoring across the estate.

Log Explorer

Normalised events with fast filtering over millions of rows, backed by daily rollups for instant dashboards.

Detections & bulk triage

MITRE-mapped detections with underlying command evidence, one-click bulk remediation and suppression.

Cross-domain connectors

Entra sign-ins and directory audits, Cato network telemetry and endpoint feeds ingested every five minutes.

Response playbooks

Automated containment with a blast-radius guard that blocks privileged accounts, Tier 0 OUs and servers.

Threat hunting

Indicator management with scheduled sweeps and tracked hunt outcomes.

Behaviour analytics (UEBA)

Per-entity baselines with z-score anomaly scoring, nightly rebuilds and first-seen flags.

Attack graph & investigations

Interactive cross-domain graph, attack timeline, AI assessment and STIX 2.1 export.

Case operations

Auto-seeded live cases, continuous re-correlation, SLA/MTTR metrics and a MITRE heatmap.

Threat feeds, network, service desk and assets

Intelligence & integrations

Threat intelligence (SIG)

Approved external feeds, acknowledgement tracking and recommended policy wording changes.

Prioritised stories

Clustered, source-credibility-weighted stories feeding straight into BIA reporting.

Cato network reports

Live GraphQL metrics for sites, throughput and security events with automated report generation.

Ticket trends

InvGate service-desk ingestion with volume, category and resolution trend analysis.

TechFlow ICT assets

Asset lookup with automated end-of-life tracking against suppliers and projects.

BYOD & Azure app registrations

Device approval portal with compliance audits, plus enterprise app credential lifecycle and alerting.

Policies, legal, permits, competency, reporting

Governance & registers

ICT policies

Versioned library with acknowledgement tracking and Annex A control satisfaction references.

Legal & regulatory register

Obligation tracking with refresh hooks and evidence linked per requirement.

Permits to work

Sequential refs, project linkage and approver sign-off.

Staff competency

Skills matrix with current vs target levels, evidence and immutable history.

Cryptography register

Annex A 8.24 certificate and key inventory with 90/60/30-day expiry alerting and exceptions.

Registers, board pack & manual

Unified registers, PDF/DOCX board pack and a downloadable platform manual.

Access control, workflow, search and agents

Administration

Access governance

SAML SSO, group RBAC, attribute rules, segregation-of-duties matrix and step-up MFA.

Workflow designer

Low-code multi-stage approvals with reminders, escalations, SLAs and conditional routing.

Unified search

One ⌘K bar with natural-language querying across risks, controls, assets, suppliers, audits, policies, incidents and actions.

My Dashboard

Pin any module as an interactive live widget for one-click access.

Platform roadmap

Guided delivery workflow where each topic is closed out by explicit acceptance.

Agents & integrations

MCP server, interactive Teams approvals, on-prem AD/GPO/XDR agents and scheduled sync jobs.

One methodology, end to end

Every risk — supplier, project, exception or incident — is scored on the same 3×3 likelihood × impact matrix and banded Low / Medium / High. No "Critical" tier, no 5-point scales, no reconciliation between registers at audit time.

A.5 OrganisationalA.6 PeopleA.7 PhysicalA.8 Technological

Evidence, not assertions

R&CC approval gates on ISMS stages, DPIAs and change requests. Append-only implementation evidence, immutable audit events, template-version locking on issued agreements, and a board pack export covering KPIs, open risks and exceptions.

Sign in to the platform