Platform
Everything you need. One place.
Full GRC — compliance, risk, incidents and legislation — in one platform.
Capabilities
One platform. The full GRC lifecycle.
From daily compliance evidence collection to post-incident lessons learned, CyberGrape covers every stage — and surfaces what needs attention before anyone has to go looking.
Security score
A clear, measurable score that shows your current security posture at a glance. No ambiguity, no guesswork.
Risk register
Log, rate and track every risk your business faces. Assign owners, set treatment deadlines and link risks directly to controls and incidents.
Compliance status
See exactly where you stand against SMB1001, ISO 27001, NZISM and other frameworks. Know your gaps before an auditor finds them.
Action Hub
Turn gaps, risks and incident findings into tracked, owned tasks. Syncs with Microsoft Planner so remediation work lives where your team already works.
Incident response
A structured command centre for security incidents — from first report through containment, recovery and post-incident review. AI-assisted response plans included.
Third-party risk
Real-time vendor risk ratings, ransomware susceptibility scores and breach alerts powered by Black Kite. Know your supply-chain exposure without asking a single supplier.
Privacy legislation alerts
Automated monitoring of AU and NZ privacy legislation. Twice-daily checks of official registers, regulators and parliamentary sources — alerts land before change affects your programme.
Trust Portal & evidence packs
Share compliance proof with customers via a branded Trust Portal link, and export assessor-ready evidence packages in one click.
Compliance
Built around SMB1001 certification.
Every feature in the platform is designed to support your SMB1001 journey. The compliance module maps all 39 controls across five tiers, tracks evidence in real time, and tells you exactly what is missing — from Bronze through to Diamond. ISO 27001, NZISM and other frameworks share the same evidence library.
- Control mapping across all five SMB1001 tiers
- Automated evidence from connected integrations
- Gap analysis with prioritised remediation steps
- Assessor-ready evidence pack generated automatically
- ISO 27001 SoA, NZISM and more in the same workspace
Action Hub
Turn gaps into action. Track every fix.
Compliance gaps, risk treatments, incident findings and policy tasks all land in the same Kanban board. Assign owners, set priorities and due dates, attach evidence and track progress to completion — with a full audit trail behind every item.
- Actions linked to risks, controls, incidents or policies — context travels with the task
- Must / Should / Could priority levels with workload visibility across the team
- Syncs with Microsoft Planner via Teams integration — work where your team already works
- Evidence attachments and comments make every item an auditable work record

Microsoft Planner sync
Action Hub tasks appear in your team's Planner board automatically when Teams integration is active.
Incident Response
A command centre for when things go wrong.
Log and classify incidents, assign an incident commander, track severity and reportability, and maintain a time-stamped response record from first alert to lessons learned. When an incident closes, recovery actions flow straight to Action Hub and linked risks are flagged for review.
- Classify severity, assign commander and capture response across the full lifecycle
- AI-drafted incident response plan with roles, escalation paths, containment procedures
- Tabletop exercises scheduled via Case Management — test the plan before you need it
- Append-only timeline preserves every action taken — ready for regulatory reporting
- Incident findings spawn Action Hub tasks and trigger risk register reviews on closure
Notifiable breach ready
Fields for occurred, detected, acknowledged, contained and resolved timestamps support NDB scheme and Privacy Act reporting requirements.
Third-Party Risk
Know your supply-chain exposure. No questionnaires needed.
Powered by Black Kite's continuous OSINT and threat-feed monitoring, the platform delivers real-time vendor risk ratings, Ransomware Susceptibility Index scores and breach alerts — without sending a single questionnaire to a supplier.
0–900 risk ratings
Live scores across hundreds of technical risk categories — updated daily from open-source and threat-feed sources.
Ransomware Susceptibility Index
A proprietary score that estimates each vendor's likelihood of a ransomware incident, informed by real-world attack patterns.
Financial impact modelling
FAIR-based dollar estimates of breach impact help you prioritise which vendor relationships need the most attention.
Breach and change alerts
Instant notifications when a vendor's exposure changes — so you can act before the breach becomes your problem.
Diamond requires demonstrated supply-chain risk management. Black Kite monitoring satisfies this control with continuous, evidence-backed vendor assessments.
Vendor scorecards and documented risk ratings support cyber-insurance applications, procurement due diligence and DORA / NIS2 alignment.
Privacy Legislation Monitor
Know when privacy law changes. Before it affects your programme.
The platform checks official AU and NZ legislation registers, privacy regulators and parliamentary sources twice daily. When a new Privacy Act compilation, amendment, regulator notice or code of practice is detected, it lands in a searchable change log with a summary and source link — and alerts go out before teams need to scramble.
- NZ Privacy Act 2020 — official gazetted versions and amendment acts
- NZ Privacy Commissioner — guidance, enforcement decisions, codes of practice
- Australian Privacy Act 1988 (Cth) — new compilations via the Federal Register of Legislation API
- Australian privacy-related Bills and amendment acts
- Configurable in-app and email alerts by jurisdiction, source and change type
What this provides. The monitor flags detected changes and helps teams assess impact and update policies. It does not constitute legal advice or automatic compliance updates.
Integrations
Connects to the tools you already use.
The platform pulls evidence directly from your existing security stack and syncs remediation work back to Microsoft Planner. No manual uploads. No copy-paste.









And more integrations added regularly.
MSPs
Built for MSPs too.
The CyberGrape Platform is multi-tenant by design. MSPs can manage their entire client base from one console — running SMB1001 programmes, monitoring incidents and tracking vendor risk across dozens of clients simultaneously.
Multi-client console
One dashboard for your entire portfolio. Switch between clients in a click. See every client's security posture, open incidents and compliance gaps at a glance.
Client reporting
AI-generated executive reports for every client. Board-ready, branded and exportable in minutes rather than hours.
See the full platform in minutes.
Connect your tools, run the assessment and know exactly where you stand across compliance, risk and your vendor landscape. No commitment required.

