EVIDENCE IN. CLARITY OUT.

A clearer picture.
A stronger
conversation.

Cyber posture your board can read.
Evidence your auditor can check.

Connect the tools you already own. Understand your exposure. Make the next decision with confidence.

Explore the product ↘
Built for the people behind the board report.
01 / FROM SIGNAL TO DECISIONScroll to see the whole picture ↓
YOUR ESTATE. ONE CONNECTED VIEW.NORTHWIND · SYNTHETIC DEMO

Every number.
A paper trail.

From the boardroom question to the evidence behind it. Follow the thread.

See what makes it credible ↗
◈
Connected to the sourceQuery · collection time · formula
↗
● ● ●CYBERMAIN / EXECUTIVE OVERVIEW↗
Northwind demonstration executive overview, showing posture, financial exposure and decisions.
↳ Evidence you can follow.

Your tools.
A shared picture.

Keep the investments you’ve made.
Bring their evidence into one conversation.

Live validated

Run against a live customer tenant.

Microsoft Defender XDRMicrosoft IntuneMicrosoft Entra ID

Available for customer validation

Built and tested on synthetic data. The first customers to connect them validate them with us.

CrowdStrike FalconTenableMicrosoft SentinelServiceNowSentinelOne SingularityQualys VMDRSplunk Enterprise SecurityJiraElastic SecurityAzure Arc

Detection & SIEM

  • CrowdStrike Falcon
  • SentinelOne Singularity
  • Elastic Security
  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Google Security Operations

Vulnerability & exposure

  • Tenable
  • Qualys VMDR
  • Rapid7 InsightVM
  • RoboShadow
  • CISA KEV + EPSS

Cloud, patching & inventory

  • AWS Security Hub
  • Azure Arc & Update Manager
  • Patch My PC Cloud
  • ServiceNow CMDB
  • Authoritative inventory (CMDB)

Ticketing

  • ServiceNow ITSM
  • Jira
  • TOPdesk

A report that can
answer back.

The context behind the colour.
The evidence behind the decision.

PROVENANCE

Where did that number come from?

In a spreadsheet: typed in by hand.

In Cybermain: trace it to the source, query and collection time. Open the figure and follow the evidence.

CONFIDENCE

What aren’t we seeing?

In a spreadsheet: a green cell can outlive its evidence.

In Cybermain: a gap is grey, with a reason. Missing evidence lowers the confidence shown beside the score.

BUSINESS CONTEXT

What could this actually cost?

In a spreadsheet: an amber rating.

In Cybermain: named scenarios, a loss range and your stated appetite. Assumptions stay visible.

22 control domains41 versioned metric definitions4 executive indices

Less translating.
More understanding.

A connected view of your cyber posture,
from the headline to the next action.

The whole picture, at a glance.

Posture, confidence and the decisions waiting for you. A shared starting point for leadership and security.

EXECUTIVE OVERVIEW / FOCUSED VIEWNorthwind · synthetic demonstration
Executive overview — Northwind synthetic demonstration

Posture with contextThe score is accompanied by its confidence and any binding caps.

Exposure in business termsThe largest approved scenario carries a range and stated limitations.

A clear next stepDecisions are surfaced with their owner and urgency.

Seven more views, each connected to the evidence behind your posture.

All product screens show Northwind, a synthetic demonstration organisation. No customer data is pictured.

Trust is in
the detail.

Useful answers begin with being clear
about what you know — and what you don’t.

SCORE→FORMULA→SOURCE
01

Follow any number.

Trace a score to its source, query, collection time and formula. Source reliability is recorded too. If a number cannot be traced, it is not shown as a score.

—
Not yet assessableMissing evidence stays visible
02

Make the gaps visible.

Missing or stale evidence appears as unknown, with a reason. Contradictory data is explicit too. Confidence is shown separately, so a reassuring score cannot hide weak evidence.

↳
Owned. Evidenced. Reviewed.Attestations with an expiry
03

Give judgement a name.

Manual controls have named owners, evidence references and a review trail. They expire and require second-line sign-off. An attested control tops out below a measured one: a supported claim still carries less weight than a measurement.

Cyber risk.
Priced in pounds.

Named scenarios. FAIR-based loss modelling.
Your appetite, alongside the uncertainty.

Northwind demonstration
POTENTIAL ANNUAL LOSS RANGE£0 – £1.23m

A range around a central estimate, because the inputs carry uncertainty.

CENTRAL ESTIMATE / ONE-IN-TEN SEVERE YEAR≈ £253k / ≈ £1.2m

Two different views of the same scenario. The severe year is shown alongside the central estimate.

APPETITE SET BY THE ORGANISATION£750k

This scenario’s severe year exceeds the stated appetite. A decision is due within 30 days.

Estimate limited: calibration. Every figure states what limits it. When inputs are too weak to price, the scenario says so.

Every scenario, in context.

A register brings together annual loss range, likelihood, severe-year exposure and the verdict against appetite. Scenarios are not added into a single total.

The story before the sum.

Each scenario says what happens, who would do it, which service it affects and who owns it, before showing a single pound.

Connected to the controls that drive it

Backup and recovery · Privileged access · Network segmentation · Server EDR coverage. Follow each driver through to its score and evidence.

A practical
place to start.

Start with the services you depend on. Adopt relevant scenarios, record the owner’s assessment and take each one to a decision.

Sector starting points
A curated library for public services, further and higher education, and general organisations. Templates, not measured probabilities.
Named owner assessments
Professional judgement stays labelled as attested.
Connected evidence
Collection time and scope remain inspectable throughout the journey.

Depth where
it matters.

Built for the questions that come
after the headline number.

01 / EXECUTIVE CONTEXT

Four indices beside the headline.

Exposure, control effectiveness, governance health and evidence confidence roll up from the same domain scores as overall posture. Governance and technical exposure remain visible side by side.

02 / EVIDENCE QUALITY

Confidence is a number too.

A weighted geometric mean of completeness, freshness and source reliability. A zero in any component pulls confidence down instead of being averaged away.

03 / PRIORITISATION

Exploitability first.

KEV listing and EPSS determine which findings inherit the seven-day SLA. Severity, exploitability, asset criticality and age inform vulnerability posture.

04 / COLLECTION HEALTH

Every source accountable.

Inspect connector health, collection time, duration, record count, failures and run history. The reconciliation queue sits beside the sources it depends on.

05 / REPRODUCIBILITY

History you can follow.

Recomputations append a new row linked to the one they replace, with a reason. Formula and profile versions stay pinned so earlier scores remain explainable.

06 / GOVERNANCE

Review between attestations.

Signed attestations every 90 days and unsigned operational reviews every 30 keep emerging drift visible while signatures retain their meaning.

Trust deserves
an explanation.

These controls are built into the product. Our residual-risk register records what is not yet mitigated, and why.

Ask for the detail ↗
01

Hash-chained audit log

Database triggers refuse updates and deletes. Auditors can verify the chain.

02

Envelope-encrypted credentials

A separate key for each connector credential. Secrets are never returned by an endpoint, and every read is audited.

03

Single sign-on and MFA

OpenID Connect sign-in, ready for Entra ID and configured per organisation, with multi-factor authentication.

04

Segregation of duties

Attestation submitters cannot approve their own submission. Risk acceptances require a justification, approver and expiry.

Bring the questions.
We’ll bring the evidence.

Book a walkthrough ↗

Thirty minutes. A demonstration estate. A conversation about yours.

Product preview