What is the CoreCyber platform?
CoreCyber is a cybersecurity risk management and analytics platform that lets founders, CISOs, and security leaders continuously assess, quantify, and manage cyber risk in one place. It combines sector‑specific assessments, advanced risk models (including FAIR‑style financial impact), dashboards, POAM tracking, and reporting so you can move from ad‑hoc spreadsheets to a repeatable, data‑driven program.
What makes CoreCyber different from other risk tools?
CoreCyber is built to serve both small teams and large enterprises with the same underlying risk engine. We cover all 16 U.S. critical infrastructure sectors plus 10 additional commercial sectors (26 in total), and tailor the user experience by persona: entrepreneurs get guided, jargon‑free workflows; CISOs get deep analytics, ROI models, and board‑ready reports; GSOCs and MSSPs get multi‑tenant monitoring, connector integrations and supply‑chain aggregation.
What are the key features available today?
Today, CoreCyber includes guided sector‑specific assessments, dashboards with risk scoring and trends, FAIR‑style financial impact models, POAM and compliance gap tracking, supply‑chain risk aggregation across vendors, and connectors for common security and IT systems. Reporting templates generate executive summaries, board views, and technical remediation details in minutes.
How does CoreCyber's in-app guidance help my team?
CoreCyber includes a built-in Help Center, a plain-language security glossary, contextual tooltips, and guided product tours that explain security concepts as you work. On the analytics side, SHAP-style driver views explain in plain language why a risk score changed and which factors moved it most. Together these keep busy founders and non‑security stakeholders moving quickly while still letting security teams dive into the underlying detail when needed.
How does CoreCyber handle supply chain and vendor risk?
Our supply‑chain module aggregates risk across vendors, contracts, and services so you can see concentration risk and critical dependencies at a glance. You can import vendor data, capture questionnaire results, link penetration tests or third‑party attestations, and roll everything up into enterprise‑level views.
How does CoreCyber notify my team when risk changes between assessments?
CoreCyber includes a flexible notification system for risk events, assessment milestones, connector changes, and vendor activity. You can configure which events trigger alerts, who should receive them, and how frequently digests are sent. This keeps security, IT, and leadership aligned without flooding inboxes with noise.
Which systems can I integrate with CoreCyber?
CoreCyber offers connectors for common cloud, identity, security, commerce, and logging platforms. Today, the live connectors include Shopify, Splunk, Bitdefender, and CoreCyber vPenTest, along with integrated endpoint and vulnerability-scanning vendors that are already wired into the platform. AWS, Microsoft 365, and Google Workspace connectors are marked as "Coming Soon" in the portal and will be available shortly. Additional connectors for other cloud providers, commerce platforms, SIEM tools, and security products are on our roadmap so you can see what's planned next. These integrations enrich your assessments with real telemetry and reduce the amount of manual data entry required. For Enterprise customers, we can also scope and deliver additional or custom integrations as part of your onboarding or expansion roadmap.
How do vendors and suppliers share evidence or complete questionnaires?
Vendors receive secure, time-bound invitations to the CoreCyber vendor portal, where they can answer tailored security questionnaires, upload evidence, and acknowledge requirements. Their responses are normalised into your supply-chain views so you can compare vendors consistently, track outstanding items, and feed high-risk findings directly into POAM and risk views.
How is access to the CoreCyber portal secured for my team?
Access is protected using modern authentication with support for multi-factor authentication, backup codes, and granular roles. Administrators can manage users centrally, enforce strong sign-in requirements, and audit access and activity. Combined with strict role-based access and data isolation in the backend, this ensures that only the right people can see the right data.
How does CoreCyber handle differences across sectors or industries?
CoreCyber ships with specialized modules for each critical infrastructure and commercial sector. Question sets, scoring logic, and analytics are tuned for your vertical—so a healthcare provider, a financial institution, and an energy operator see controls and risks that match their reality. Sector modules also drive tailored benchmark views and reporting, so you can compare your posture against peers instead of a one-size-fits-all baseline.