CyberGrape – cyber security certification and GRC platform for small business
CyberGrape – GRC platform for SMB1001 security certification
Pricing

Cyber security for growing businesses

One partner for the whole of your security.

Most growing businesses end up with a patchwork. One company does the training, another watches the network, a consultant turns up for the audit, and a spreadsheet holds the rest together. We bring the five parts that actually matter into one place.

Take a free assessment

Built for Australian businesses from 5 to 500 people.

GRAPE
Five bundles, one platformHover any pad to see what that bundle covers.
4.8 Google ratingVerified client reviews
Award winningNZ 2023 winner, ARN 2026 finalist
SMB1001 certifiedGold, two years running
Clients globallyAU, NZ and South Africa

The problem

You already know the moment
this goes wrong.

It is rarely the dramatic hack. It is the ordinary Tuesday when something arrives that you cannot answer quickly.

The questionnaire lands

Your biggest customer sends a forty question security review and gives you a week. Nobody knows where half the answers live, so it eats the week instead.

The insurer asks for proof

Renewal comes round and the form wants evidence, not intentions. You have done a lot of the work. Showing it is the hard part, and the premium reflects that.

The supplier gets breached

A company you send data to is in the news. You find out when your clients do, and you have no way to tell how exposed you actually are.

Why we are built this way

Grapes do not grow alone.

They grow in clusters, and every berry on the bunch is fed by the same vine. We took the name seriously when we built the business.

Five bundles make up the cluster. Each one stands on its own, and each one is stronger because the others are there. A risk you find in one shows up as a control in another, and as a training module in a third, without anybody rekeying it.

Underneath them all sits one platform, and every client we look after runs on it. Your data is fenced off and only yours, but the engineering, the framework libraries, the integrations and every improvement we make are shared across the whole vine. That is why a business of twenty people can run the sort of security programme that used to need a full time team and a six figure budget.

One board, many clients

Every client gets their own cluster of pads. Nobody shares a trace.

Your businessA law firmAn engineering firmAn MSP's clientsOne platform underneath, carrying all of them

What we do

The five bundles.

Governance, Risk, Advisory, Protection and Education. Pick one to see what is inside it.

Governance

Know what good looks like, and prove you are doing it.

Policies your people will actually follow, mapped to the standard your customers care about, with the evidence sitting behind every control. When somebody asks you to prove it, the answer is already there.

What is inside

  • A full policy suite written for your business, not copied from a template
  • Alignment to SMB1001, ISO 27001, SOC 2 or NZISM, whichever fits
  • Control tracking with evidence attached, kept current as things change
  • Board and audit reporting you can send without editing

Where most clients start, usually ahead of certification.

More on Governance

You do not have to buy all five. Most clients start with whichever bundle is hurting most and grow into the others. Because it is one platform, nothing gets rebuilt when you expand.

See it in action

The platform your team
will actually use.

Track your certification progress tier by tier, and monitor every vendor in your supply chain in real time. Built in house, so when you need something changed, we can change it.

SMB1001 compliance
Bronze to Diamond
Security posture
Real-time score
Vendor risk
Black Kite powered
Evidence packs
Auto-generated

SMB1001:2026 · ISO 27001:2022 · SOC 2 · NZISM built in. Supplier risk powered by Black Kite.

Why CyberGrape

Expert-led.
Practically priced.
Evidence-backed.

We do not just advise, we measure. Our clients leave every engagement with documented evidence of their security posture, not a slide deck and a handshake.

4.8 ★
Google rating
Verified client reviews across Australia and New Zealand
30+
Years of ICT and security experience
CISSP certified, enterprise architecture background
4
Frameworks built into the platform
SMB1001:2026, ISO 27001:2022, SOC 2, NZISM: switch the lens without redoing the work

What clients say

Trusted by organisations
that take security seriously

“CyberGrape has helped us mature our security posture in a way that’s measurable and defensible. They don’t just tell us we’re safe: they show us the evidence.”

RC
Rob CairnsSecurity Programme Technical Solution Manager, Tower Insurance

“We needed a trusted partner who understood our risk, not just our technology. CyberGrape has been that partner: practical, straight-talking and always on top of what’s changing.”

JH
Josh HickfordCEO, Taranaki Foundation

Find out where you actually stand.

Half an hour on a call and you will have a clearer picture of your security than most businesses your size ever get. If we are not the right fit, we will tell you that too.

Take a free assessment