Risk and exposure

Prioritise cyber risk with the asset evidence behind it.

Cyobik combines business impact, asset knowledge, vulnerability context, internal exposure and control posture into explainable asset and organisation-level views.

Three connected scores

Summaries for leaders. Evidence for operators.

Visibility Score85%

Measures the completeness and usability of asset knowledge.

Protection Score78%

Evaluates supported security, compliance, exposure, vulnerability, authentication and certificate factors.

Asset Risk Score30%

Uses Impact × Likelihood and can be aggregated to organisation level.

Illustrative values only.

Vulnerability assessment

Correlate vulnerability evidence to the assets that carry it.

Offline CPE/CVE assessment

Compute CPEs from maintained inventory and match them against a local CVE database.

Vulnerability database updates

Maintain the local vulnerability database using authoritative upstream data including NVD, with offline update support.

Nessus integration

Retrieve scheduled results from multiple Nessus instances and assign findings to corresponding Cyobik assets.

Internal attack surface

See exposure inside the managed environment.

Internal ASM analyses exposure for assets managed by Cyobik. It is deliberately distinct from external discovery of unknown internet assets.

Open ports

Review ports, protocols, services and available process or connection context.

Internet-facing connections

Review inbound, outbound or full-duplex context where collected.

Endpoint and service exposure

Review USB devices, shared files and permissions, and detected web applications and servers.

Dashboards

Move from posture to cause

Drill-down

Default dashboards include Overview, Vulnerability Scan, Scan History Overview, Inventory Software, Vulnerability Map, ASM and Compliance Assessment.

Home dashboard and favouritesSelect a default dashboard, favourite views and reorder them.
Dark ModeUse a dark dashboard interface where preferred.
Reporting

Deliver evidence on schedule

Email delivery

Schedule reports and deliver them by email for recurring management and operational review.

Asset-level evidenceTrace the factors contributing to risk and protection.
Organisation-level measuresUse overall Visibility, Protection and Organisation Risk Scores.

Priority is not automated remediation

Cyobik supports risk-based identification and ordering of higher-risk assets. The current product does not claim automated remediation recommendations, attack-path prioritisation or AI-generated recommendations.

Connect risk evidence to control reporting.

See how asset and technical data is mapped to predefined CIS, PCI DSS and ISO/IEC 27001 controls.

Compliance