CyberGrape – cyber security certification and GRC platform for small business

Platform

Everything you need. One place.

Full GRC — compliance, risk, incidents and legislation — in one platform.

Security score
Compliance
Action Hub
Incident response
Vendor risk
Legislation alerts

Capabilities

One platform. The full GRC lifecycle.

From daily compliance evidence collection to post-incident lessons learned, CyberGrape covers every stage — and surfaces what needs attention before anyone has to go looking.

Security score

Risk register

Compliance status

Action Hub

Incident response

Third-party risk

Privacy legislation alerts

Trust Portal & evidence packs

Compliance

Built around SMB1001 certification.

Every feature in the platform is designed to support your SMB1001 journey. The compliance module maps all 39 controls across five tiers, tracks evidence in real time, and tells you exactly what is missing — from Bronze through to Diamond. ISO 27001, NZISM and other frameworks share the same evidence library.

  • Control mapping across all five SMB1001 tiers
  • Automated evidence from connected integrations
  • Gap analysis with prioritised remediation steps
  • Assessor-ready evidence pack generated automatically
  • ISO 27001 SoA, NZISM and more in the same workspace
See SMB1001 certification

Action Hub

Turn gaps into action. Track every fix.

Compliance gaps, risk treatments, incident findings and policy tasks all land in the same Kanban board. Assign owners, set priorities and due dates, attach evidence and track progress to completion — with a full audit trail behind every item.

  • Actions linked to risks, controls, incidents or policies — context travels with the task
  • Must / Should / Could priority levels with workload visibility across the team
  • Syncs with Microsoft Planner via Teams integration — work where your team already works
  • Evidence attachments and comments make every item an auditable work record
Microsoft Teams

Microsoft Planner sync

Action Hub tasks appear in your team's Planner board automatically when Teams integration is active.

Incident Response

A command centre for when things go wrong.

Log and classify incidents, assign an incident commander, track severity and reportability, and maintain a time-stamped response record from first alert to lessons learned. When an incident closes, recovery actions flow straight to Action Hub and linked risks are flagged for review.

  • Classify severity, assign commander and capture response across the full lifecycle
  • AI-drafted incident response plan with roles, escalation paths, containment procedures
  • Tabletop exercises scheduled via Case Management — test the plan before you need it
  • Append-only timeline preserves every action taken — ready for regulatory reporting
  • Incident findings spawn Action Hub tasks and trigger risk register reviews on closure

Notifiable breach ready

Fields for occurred, detected, acknowledged, contained and resolved timestamps support NDB scheme and Privacy Act reporting requirements.

Third-Party Risk

Know your supply-chain exposure. No questionnaires needed.

Powered by Black Kite's continuous OSINT and threat-feed monitoring, the platform delivers real-time vendor risk ratings, Ransomware Susceptibility Index scores and breach alerts — without sending a single questionnaire to a supplier.

0–900 risk ratings

Live scores across hundreds of technical risk categories — updated daily from open-source and threat-feed sources.

Ransomware Susceptibility Index

A proprietary score that estimates each vendor's likelihood of a ransomware incident, informed by real-world attack patterns.

Financial impact modelling

FAIR-based dollar estimates of breach impact help you prioritise which vendor relationships need the most attention.

Breach and change alerts

Instant notifications when a vendor's exposure changes — so you can act before the breach becomes your problem.

Explore third-party risk management
Required for SMB1001 DiamondControl 4.9.0.1

Diamond requires demonstrated supply-chain risk management. Black Kite monitoring satisfies this control with continuous, evidence-backed vendor assessments.

Insurance and procurement ready

Vendor scorecards and documented risk ratings support cyber-insurance applications, procurement due diligence and DORA / NIS2 alignment.

Privacy Legislation Monitor

Know when privacy law changes. Before it affects your programme.

The platform checks official AU and NZ legislation registers, privacy regulators and parliamentary sources twice daily. When a new Privacy Act compilation, amendment, regulator notice or code of practice is detected, it lands in a searchable change log with a summary and source link — and alerts go out before teams need to scramble.

  • NZ Privacy Act 2020 — official gazetted versions and amendment acts
  • NZ Privacy Commissioner — guidance, enforcement decisions, codes of practice
  • Australian Privacy Act 1988 (Cth) — new compilations via the Federal Register of Legislation API
  • Australian privacy-related Bills and amendment acts
  • Configurable in-app and email alerts by jurisdiction, source and change type

What this provides. The monitor flags detected changes and helps teams assess impact and update policies. It does not constitute legal advice or automatic compliance updates.

Integrations

Connects to the tools you already use.

The platform pulls evidence directly from your existing security stack and syncs remediation work back to Microsoft Planner. No manual uploads. No copy-paste.

Black Kite
CrowdStrike
uSecure
KeepIt
CheckRed
PowerDMARC
Microsoft Teams
NinjaOne
Bitdefender

And more integrations added regularly.

MSPs

Built for MSPs too.

The CyberGrape Platform is multi-tenant by design. MSPs can manage their entire client base from one console — running SMB1001 programmes, monitoring incidents and tracking vendor risk across dozens of clients simultaneously.

Multi-client console

One dashboard for your entire portfolio. Switch between clients in a click. See every client's security posture, open incidents and compliance gaps at a glance.

Client reporting

AI-generated executive reports for every client. Board-ready, branded and exportable in minutes rather than hours.

Learn more about the MSP console

See the full platform in minutes.

Connect your tools, run the assessment and know exactly where you stand across compliance, risk and your vendor landscape. No commitment required.