G · Governance
Policies your team actually follows, and your auditor can verify.
Expert security leadership without the full-time hire. A central policy library with templates, version control, staff sign-off tracking and automatic evidence pack integration.
Governance
Policies in a folder don't count as evidence.
Most businesses have security policies somewhere. They were written two years ago, saved to a shared drive, and acknowledged by exactly one person who no longer works there. When an auditor asks for evidence that staff are aware of your password policy, "it's in the folder" is not an answer.
The CyberGrape policy module changes the relationship between your policies and your certification. Every policy is published from the platform, acknowledged by your team with a tracked timestamp, and automatically mapped to the SMB1001 controls it supports. Your evidence is built as you go.
Every policy lives in one place: versioned, published, and visible to your whole team and your auditor.
Acknowledgements are recorded per employee with a timestamp. No spreadsheet chasing required.
Publish a policy and it automatically satisfies the linked SMB1001 controls in your evidence pack.
When your certifier asks for evidence, you export: not scramble. The evidence builds continuously.
What the policy module does.
Every feature is designed to make your policies useful: not just filed.
Policy library
A central library for every security policy your business operates. Acceptable use, password management, data handling, incident response, AI use: each version controlled, each linked to the SMB1001 controls it satisfies.
Platform policy templates
Starting from scratch is the hardest part. The CyberGrape Platform includes pre-built policy templates aligned to SMB1001 requirements. Edit them to match your business: the structure and compliance mapping are already done.
Staff acknowledgement and sign-off
Every policy can be sent to your team for acknowledgement directly from the platform. Tracked per employee, timestamped, and automatically included in your SMB1001 evidence pack. No chasing people for email confirmations.
Version control and history
Every policy change is versioned. You can see who edited a policy, what changed, and when. Your auditor can see the full history. Your team always has the current version in front of them.
SMB1001 control mapping
Each policy is automatically mapped to the SMB1001 controls it supports. Publish a password policy and the relevant controls update. The platform connects the documentation to the certification evidence without manual work.
Evidence pack integration
Policy documents, version history and staff sign-off records all flow directly into your SMB1001 evidence pack. By the time you are ready to certify, your policy evidence is already compiled.
Templates for every policy SMB1001 requires.
The platform includes pre-built templates for every policy type required across the five SMB1001 tiers. Customise them for your business: the SMB1001 control mapping is already done.
What is inside Cyber Governance.
Everything included in the Governance bundle when you subscribe to the CyberGrape Platform.
Explore the other GRAPE bundles.
Risk
Know what could hurt you, before it does.
A ranked view of what actually threatens the business, including the suppliers you depend on. Not a hundred page report: a short list of what matters and what to do about it.
Advisory
Security leadership without the salary.
A senior security leader in your corner for a set number of hours each month. Someone who owns the plan, sits in the meetings that matter, and turns the technical into decisions you can actually make.
Protection
Watched, defended and backed up.
The day to day defending. Someone is watching your systems around the clock, so a problem at two in the morning gets handled at two in the morning rather than discovered on Monday.
Education
Turn your team into the first line of defence.
Most incidents start with a person, not a firewall. This is the bundle that changes behaviour, in short pieces people will actually finish rather than an annual video nobody watches.
Policies that work as evidence, not just documents.
Get started and have your first policies published and acknowledged in your first week.

