CyberGrape – cyber security certification and GRC platform for small business

Security Command Centre

Your entire security posture. One screen.

Pulls live data from every tool in your environment and tells you, in plain language, where you stand. No spreadsheets. No switching between dashboards.

Platform overview
app.cybergrape.io/security-command-centre
Security Posture
74/100
Active Alerts
3
Controls Covered
40/52
Cert Level
Gold
Live Threat FeedLast updated 2 min ago
CriticalExposed RDP port detected on endpoint, NinjaOne report2 min ago
HighSSL certificate expiring in 6 days, PowerDMARC domain18 min ago
MediumFailed login attempts exceeded threshold, 14 attempts1 hr ago
Connected Integrations
CrowdStrike
Arctic Wolf
Qualys
NinjaOne
PowerDMARC
CheckRed
Black Kite
usecure

Most businesses are flying blind.

The average SMB uses eight or more security tools. Each has its own dashboard, its own alerts, its own login. No single person has the full picture at any moment, which means problems go unnoticed, compliance gaps persist, and boards get told "everything is fine" because nobody knows it isn't.

Without a command centre
Six separate dashboards, six separate logins
Threats detected in one tool, unknown to the others
Compliance status lives in a spreadsheet someone updates monthly
Board reports assembled manually the night before the meeting
Certification gaps discovered at audit time, not before
No single number that tells you where you actually stand
With the Security Command Centre
One view across every connected tool
Threats surface in real time regardless of which tool caught them
Compliance status updated automatically as tools report in
Board summary always current, no manual assembly required
Certification gaps visible the moment they open
One posture score that reflects your actual controls

What the command centre shows you.

Live security posture score

A single number that tells you where your business stands right now. Updated continuously as controls are implemented, evidence is collected, and your connected tools report in. Not a snapshot: a live view.

Threat and alert feed

Live threat intelligence from your deployed security tools: endpoint alerts, email security events, cloud posture findings, surfaced in one place. Your command centre, not six separate dashboards.

Control coverage at a glance

See which SMB1001 controls are fully implemented, partially implemented, or missing, across all five tiers simultaneously. Know exactly what stands between you and your next certification milestone.

Connected integrations

Data pulled directly from CrowdStrike, Arctic Wolf, Bitdefender, Qualys, NinjaOne, PowerDMARC, CheckRed and more. Evidence collected automatically from your existing stack, not entered manually.

Certification readiness tracker

A real-time progress view against your target SMB1001 tier. See what's done, what's outstanding, and what requires a consultant to complete. Never be surprised in an audit.

Board-ready summary view

A high-level view designed for leadership, not security engineers. Risk posture, certification status and outstanding actions in plain language, ready to screenshot for your next board meeting.

Automatic evidence collection

Data from your tools, not entered by your team.

Most security dashboards require someone to manually update them. The CyberGrape Security Command Centre pulls live data from your connected tools (endpoint agents, email security, cloud posture, patch management) and surfaces it automatically.

When a new vulnerability is detected by Qualys, it appears in your command centre. When CrowdStrike isolates a threat, it is logged. When a staff member fails a phishing simulation, it registers against your awareness training control. You see the picture as it actually is, not as it was when someone last updated a spreadsheet.

Every data point collected from an integration is mapped to the SMB1001 and ISO 27001 controls it evidences. The evidence does not need to be attached separately. It arrives with its control mapping already in place.

CrowdStrikeEndpoint detection and response
Arctic WolfManaged detection and response
QualysVulnerability scanning
NinjaOnePatch management and endpoint monitoring
PowerDMARCEmail security and domain protection
CheckRedCloud security posture management
Black KiteSupply chain and vendor risk
uSecureSecurity awareness training
Cisco MerakiNetwork monitoring
Cisco UmbrellaDNS security
KeepitCloud backup status
MicrosoftEntra ID, Intune, Defender
Evidence flow: tool to control
Updated continuously from connected integrations
CrowdStrike
1.12.0.0: EDR
Detection count, threat status
PowerDMARC
2.12.1.0: Email auth
DMARC policy, domain health
NinjaOne
1.4.0.0: Patching
Patch compliance %, device count
Qualys
8.8: Vulnerability mgmt
Open CVEs, remediation status
uSecure
5.1.0.0: Training
Completion rates, phish scores
CheckRed
5.23: Cloud security
Misconfiguration findings
Last updated 4 minutes ago

SMB1001 certification readiness

Know exactly where you stand against your target tier.

The certification readiness tracker maps every data point from your connected tools to its corresponding SMB1001 control. You can see, in real time, which controls are evidenced, which are partially covered, and which have no evidence yet.

When you are ready to certify, the evidence pack does not need to be assembled. It is already there. CyberGrape works with CyberCert to take your readiness through to an issued certificate and verifiable digital badge.

SMB1001 certification programme
Control coverage by tier
Bronze15/16 controls
Silver10/13 controls
Gold11/18 controls
Platinum5/15 controls
Diamond1/8 controls

Live data, updated as integrations collect evidence

Common questions.

See your security posture in minutes.

Connect your tools, run the assessment and know exactly where you stand. No commitment required.

Platform overview