cyberenforced.io

Products

What you can run in one login

Scanning is the core every organization gets. GRC, Vendor Security, and Training & Awareness are paid add-ons on Pro, sold separately, enabled when you need them.

Security Scanning

The free core: continuous external checks on the things questionnaires and insurers actually ask about.

  • DNS, SPF, DMARC, TLS, HTTP security headers (HSTS/CSP), open ports, SSH banners, WHOIS expiry, and subdomain discovery
  • Per-domain security score, findings you can open / acknowledge / resolve, and plain-English remediation guidance
  • CSV/PDF export and revocable shareable report links, no login required for the recipient
  • Free for up to 2 domains and 2 public IPs (subdomains stay free and uncounted); Pro adds unlimited domains, 25 IPs, daily scans, a change digest, extra mail/web checks, IP CSV/PDF export, and CISA.gov KEV correlation

GRC

Lightweight controls, policies, and a risk register: enough structure to answer the questionnaire without an enterprise GRC contract.

  • 1,102 controls across 12 frameworks: ISO 27001, SOC 2, PCI DSS, NIST CSF, HIPAA, GDPR, CCPA/CPRA, NIST 800-53, CIS Controls, COBIT, FedRAMP, and CMMC
  • Policies with versioning and member acknowledgment; risk register with likelihood × impact, treatment, owners, and documents
  • Evidence is a manual notes field, a deliberate simplicity and price tradeoff, not automated cloud-integration collection
  • Sold as one add-on on Pro, tiered by how many frameworks you need

Vendor Security

A third-party inventory you can actually keep current when a customer asks who you rely on.

  • Vendor name, criticality tier, review status, and next-review date with an overdue badge
  • Optional link from a vendor to a single Risk Register entry
  • Sold separately from GRC. Add it only if vendor questionnaires are part of how you buy or sell

Training & Awareness

Staff-authored courses and quizzes so you can show that people were trained, not just told.

  • Shared catalog you assign to the whole organization, with an optional due date
  • Multiple-choice quiz graded server-side; completion roster for follow-up
  • Flagship course: “Spot It. Stop It. Report It.” plus Phishing Awareness Basics
  • Useful when a cyber-insurance form or customer questionnaire asks for security-awareness training
Products | CyberEnforced