CyberGrape – cyber security certification and GRC platform for small business

R · Risk

Know what could hurt you, and what it would cost.

A complete risk management platform: live register, structured assessments, AI-powered SWOT, configurable heatmaps, treatment plans, and continuous supplier monitoring via Black Kite.

Platform overview

Everything in the Risk bundle.

Cyber risk management is not one thing. The platform covers the full lifecycle: identify, assess, treat, monitor.

Risk register

A live canonical register of every identified risk: likelihood, impact, owner, treatment plan and lifecycle status. Risks are ranked by potential incident cost so you focus on what matters. Exportable to Excel, Word and PDF.

Risk assessments

Structured questionnaire-based assessments with document upload and AI-powered analysis. Responses feed directly into the risk register. Assessment history is retained for audit purposes.

SWOT analysis

AI-generated SWOT analysis specific to your business and security context. Weaknesses and threats automatically generate suggested risk register entries, so your strategic and cyber risk views are connected.

Risk heatmap

A 5×5 configurable heatmap that visualises your risk register by likelihood and impact. Likelihood and impact scale labels are customisable per tenant. Cell thresholds (Low/Moderate/High/Extreme) can also be adjusted.

Treatment plans and Action Hub

Every risk can have a structured treatment plan with individual actions, owners and due dates. The Action Hub surfaces all open actions across the register in one place, with overdue alerts and progress tracking.

Supplier risk (Black Kite)

Continuous outside-in monitoring of your supplier ecosystem. Black Kite generates risk scores, ransomware susceptibility ratings and financial impact estimates for every supplier, updated as threat intelligence changes, with no questionnaires to chase.

app.cybergrape.io/risk/register
Risk Register+ Add Risk
18
Total
5
Critical/High
7
Open Actions
Ransomware via vendor access
Extreme · IT Lead
Phishing: finance team
High · HR
Unpatched endpoints
High · IT Lead
SaaS data residency breach
Moderate · Legal
Staff password reuse
Moderate · IT Lead
Business continuity gap
Low · CEO
Ransomware via vendor access
ExtremeSupplier Risk · Ransomware
Edit
Treat
LikelihoodHigh
ImpactSevere
Treatment planTreating
Enforce MFA for all vendor portal access
Rotate vendor credentials quarterly
Review vendor access scope
Segment vendor network access
ISO 27001 Controls Mapped
5.22 Monitoring supplier services5.19 Information security in supplier relationships

Risk register

Every risk. Owner assigned. Treatment tracked.

The register shows every identified risk in priority order. Click a risk to see its full detail: likelihood and impact scores, treatment plan with individual actions, linked ISO 27001 and SMB1001 controls, and the full audit history.

  • Ranked by financial impact, not just score
  • Treatment plans with per-action owners and due dates
  • ISO 27001 and SMB1001 control mapping
  • Export to Excel, Word or PDF for board reporting

Risk heatmap

See your whole risk landscape at a glance.

The 5×5 heatmap plots every risk in your register by likelihood and impact. Cells are colour-coded Low through Extreme using a scoring model you can configure. Each dot in the grid is a real risk: click it to open the full detail.

  • Likelihood and impact scale labels are configurable
  • Cell colour thresholds adjustable per your risk appetite
  • Risks plotted live from the canonical register
  • SWOT threats generate suggested register entries with one click
app.cybergrape.io/risk/heat-map
Register
Heat Map
SWOT
Scenarios
Reports
Negligible
Minor
Moderate
Major
Severe
← Impact →
Almost Certain
Likely
P
R
Possible
W
E
Unlikely
S
Rare
low
moderate
high
extreme
Risks by level
Extreme1
High2
Moderate2
Low1
Custom labels
Likelihood & impact scales configurable per tenant

SWOT Analysis

Strategic risk, connected to your cyber register.

Most risk registers are a list of technical vulnerabilities with no connection to business strategy. CyberGrape connects them. The AI-generated SWOT analysis is built from your company context, security posture and assessment results. Threats flow directly into the risk register as suggested entries.

The result: a risk register that reflects both technical exposure and strategic risk, without maintaining two separate documents.

01

Build the context profile

The platform builds a company and security context profile from your SMB1001 assessment, asset register and existing risk data.

02

AI generates the SWOT

Claude analyses your profile and generates a SWOT specific to your business: not a generic template, but a view built from your actual posture.

03

Threats become risks

Each weakness or threat in the SWOT can be converted to a suggested risk register entry with pre-populated likelihood, impact and control mapping.

Third-party risk

Your suppliers are part of your attack surface.

Most breaches don't start with you. They start with a supplier who has poor controls, and access to your systems. The Risk bundle includes continuous supplier monitoring via Black Kite, so you know when a supplier's exposure changes, before it becomes your incident.

Black Kite scores suppliers from the outside: public signals, dark web monitoring, technical fingerprinting. No questionnaires to send. No chasing for responses. Just a live dashboard of supplier risk, ranked by financial impact to you.

Continuous risk ratings

Supplier scores update as threat intelligence changes, not just at your annual review.

Ransomware susceptibility

Know which suppliers are most likely to be hit with ransomware, and what the financial cost to your business would be.

Digital trust programme

Build the formal programme required for SMB1001 Diamond (control 4.9.0.1): supplier classification, risk thresholds and monitoring cadence.

Vendor risk in the register

Supplier risk findings flow directly into the canonical risk register as register items, with owner assignment and treatment plans.

No questionnaires to chase

Black Kite's outside-in methodology means your suppliers don't need to do anything. No forms, no emails, no waiting.

Required for SMB1001 Diamond: control 4.9.0.1.

A formal digital trust programme, including supplier risk classification, monitoring and evidence of ongoing oversight, is required for SMB1001 Diamond certification. The Risk bundle is designed to satisfy this control and provide the auditable evidence your certifier needs.

Learn about SMB1001 certification

What is inside Cyber Risk.

Everything included when you subscribe to the Risk bundle on the CyberGrape Platform.

A live risk register, ranked by what an incident would cost you
Continuous supplier monitoring with no questionnaires to chase
Vulnerability scanning across the systems you already run
Early warning when a supplier's exposure changes

Common questions.

Know every risk. Own every action.

Get started and have your first risks assessed and plotted on the heatmap within your first week.

Platform overview