CyberGrape – cyber security certification and GRC platform for small business

P · Protection

Every technical control, connected and continuously validated.

All your security tools integrated into one platform, automatically monitored, assessed and mapped to SMB1001 controls. No manual exports. No stale spreadsheets. Just live evidence.

See all services

Technical integrations

Nineteen integrations. One platform.

Every tool in your security stack, endpoint to email to backup to vendor risk, connects once and then reports continuously. The platform evaluates health, validates controls and collects evidence, all without your team lifting a finger.

Platform-driven protection

Connect once. Validate continuously.

The protection dashboard shows every integration's live status: health score, last sync time, active alerts and which SMB1001 controls each tool automatically validates. When something changes, you know about it before it becomes a compliance gap.

app.cybergrape.com/protection/integrations

Integrations

19 connected · 1 warning
INTEGRATIONMETRICSTATUSCONTROLS
CrowdStrike Falcon logo
CrowdStrike Falcon47 endpointsConnected3 ctrls
Bitdefender GravityZone logo
Bitdefender GravityZone31 protected devicesConnected2 ctrls
Arctic Wolf logo
Arctic Wolf24/7 SOC activeConnected2 ctrls
Microsoft Entra ID logo
Microsoft Entra ID98% MFA enabledConnected4 ctrls
NinjaOne logo
NinjaOne52 devices managedConnected2 ctrls
Suped logo
Suped6 domainsConnected2 ctrls
Qualys VMDR logo
Qualys VMDRLast scan 2h agoConnected3 ctrls
CheckRed logo
CheckRed2 findingsWarning1 ctrl
Cisco Meraki logo
Cisco Meraki3 networksConnected2 ctrls
Cisco Umbrella logo
Cisco Umbrella8 threats blockedConnected2 ctrls
Cisco Duo logo
Cisco Duo100% MFA coverageConnected2 ctrls
Bitwarden logo
Bitwarden100% enrolledConnected1 ctrl
Cloudflare logo
Cloudflare4 zonesConnected2 ctrls
KeepIt logo
KeepItLast test passedConnected1 ctrl
Proofpoint logo
Proofpoint12 blocked (7d)Connected2 ctrls
Microsoft Defender logo
Microsoft Defender47 devicesConnected1 ctrl
uSecure logo
uSecure94% completedConnected1 ctrl
Google Workspace logo
Google Workspace100% MFA enabledConnected2 ctrls
Black Kite logo
Black Kite9 vendors ratedConnected1 ctrl
CS

CrowdStrike Falcon

Last sync 4 min ago

47

Endpoints

2 low

Active alerts

4 min

Last sync

SMB1001 Controls Validated

1.5.1.0 Endpoint Detection & Response
1.12.1.0 Managed Detection & Response
1.11.1.0 Threat Hunting Activity

Evidence auto-collected and attached to controls

Syncing every 15 minutes

Connect once, validate continuously

Each integration authenticates once. From that point, the platform continuously polls for health data, alert counts and control evidence, with no manual exports or spreadsheet updates.

Automatic SMB1001 control mapping

When an integration reports healthy status, the platform automatically marks the corresponding SMB1001 controls as evidenced. Your certification posture updates in real time as your security tools change.

Evidence collected, not chased

Every integration generates its own evidence trail: sync logs, health snapshots and control validations are stored automatically and attached to the relevant control in your compliance register.

Additional controls

Beyond the core integrations.

Three controls that are often overlooked, but that carry significant weight in SMB1001 assessments and real-world incident scenarios.

Password vaults

Centralised credential management for all privileged accounts and shared passwords. Platform can ingest vault compliance reports and validates credential hygiene controls. Directly satisfies SMB1001 privileged access management requirements (controls 1.2.x) across Bronze through Platinum tiers, one of the highest-impact, lowest-effort controls to implement.

Live integration: Bitwarden. Also supports 1Password, Keeper, LastPass via manual evidence.

Visitor register

Digital visitor management for physical site access, recording arrivals, departures, host sign-off and NDA acknowledgement. Platform maintains a searchable visit log for compliance evidence. Supports SMB1001 physical security controls and provides an auditable trail for any site access queries.

Works across single and multi-site organisations

Privacy monitor

Continuous dark web monitoring for exposed credentials, leaked data and breach alerts associated with your domains and email addresses. Platform surfaces findings as cases for investigation and tracks remediation. Supports breach notification obligations under the Australian Privacy Act and NZISM.

Covers domains, email addresses and executive names

Technical controls across every SMB1001 tier.

The Protection bundle scales with your certification target. Bronze starts with the highest-impact controls (password vault, basic EDR); Diamond adds 24/7 SOC coverage. Each tier builds on the last, and the platform validates each layer automatically as tools are connected.

Learn about SMB1001 certification →
BronzePassword vault + basic EDR
SilverMFA via Entra ID + email security
GoldPatch management + vulnerability scanning
PlatinumFull MDR + network controls
Diamond24/7 SOC (Arctic Wolf / CrowdStrike)

Common questions.

Inside Protection

What's included.

The day to day defending. Someone is watching your systems around the clock, so a problem at two in the morning gets handled at two in the morning rather than discovered on Monday.

Monitoring and response running 24 hours a day
Protection on every laptop, server and phone
Email and domain security, so nobody can send mail pretending to be you
Backup for your cloud applications, and testing to find the holes first

Delivered with CrowdStrike, Arctic Wolf and other established partners.

Explore the full GRAPE platform

Ready for real protection?

Book a free consultation and we will assess your current environment, identify which integrations you already have and map the fastest path to your target certification tier.

See all services