Measures the completeness and usability of asset knowledge.
Prioritise cyber risk with the asset evidence behind it.
Cyobik combines business impact, asset knowledge, vulnerability context, internal exposure and control posture into explainable asset and organisation-level views.
Summaries for leaders. Evidence for operators.
Evaluates supported security, compliance, exposure, vulnerability, authentication and certificate factors.
Uses Impact × Likelihood and can be aggregated to organisation level.
Illustrative values only.
Correlate vulnerability evidence to the assets that carry it.
Offline CPE/CVE assessment
Compute CPEs from maintained inventory and match them against a local CVE database.
Vulnerability database updates
Maintain the local vulnerability database using authoritative upstream data including NVD, with offline update support.
Nessus integration
Retrieve scheduled results from multiple Nessus instances and assign findings to corresponding Cyobik assets.
See exposure inside the managed environment.
Internal ASM analyses exposure for assets managed by Cyobik. It is deliberately distinct from external discovery of unknown internet assets.
Open ports
Review ports, protocols, services and available process or connection context.
Internet-facing connections
Review inbound, outbound or full-duplex context where collected.
Endpoint and service exposure
Review USB devices, shared files and permissions, and detected web applications and servers.
Move from posture to cause
Default dashboards include Overview, Vulnerability Scan, Scan History Overview, Inventory Software, Vulnerability Map, ASM and Compliance Assessment.
Deliver evidence on schedule
Schedule reports and deliver them by email for recurring management and operational review.
Priority is not automated remediation
Cyobik supports risk-based identification and ordering of higher-risk assets. The current product does not claim automated remediation recommendations, attack-path prioritisation or AI-generated recommendations.
Connect risk evidence to control reporting.
See how asset and technical data is mapped to predefined CIS, PCI DSS and ISO/IEC 27001 controls.