AI-Powered Cyber Risk Assessment

Know Your Vulnerabilities Before Attackers Do

CoreCyber combines AI-driven compliance expertise with expert-led vulnerability and penetration testing so you can see, quantify, and reduce cyber risk. Log in or create a free account to start your first assessment and get an executive-ready risk view in minutes.

Risk Assessments

Stepwise workflow, sector-specific security questionnaires, and asset mapping automate data collection, minimizing manual entry

Actionable Dashboards

Visual risk scores, top risk rankings, trend analysis, and drill-downs by unit or geography, illustrated in executive reports for board or investor meetings

Compliance and POAM

Dynamic compliance gap analysis and task management, complete with reporting templates and remediation tracking for major frameworks

Built for Modern Security Teams

Industry-leading rigor meets simplicity for entrepreneurs, CISOs, and GSOC executives

up to 98% Accuracy

Risk Assessments

Stepwise workflow with sector-specific security questionnaires and asset mapping that automate data collection, minimizing manual entry

Actionable Dashboards

Visual risk scores, top risk rankings, trend analysis, and drill-downs by unit or geography, illustrated in executive reports for board or investor meetings

Compliance and POAM

Dynamic compliance gap analysis and task management with reporting templates and remediation tracking for major frameworks including NIST CSF 2.0, ISO 27001:2022, and more

Real-Time

Supply Chain Innovation

Four-layer risk aggregation and vendor evaluation clarify enterprise exposure in real time across your entire supply chain

24/7

Continuous Monitoring

Automated threat intelligence and alerting ensure ongoing protection and enable rapid response to emerging incidents

AI-Powered

Specialized Modules

Dedicated modules tackle key challenges including AI and cloud security risks, secure software development, and insider threats. Each gap has been remediated for regulatory alignment

Simple, Transparent Pricing

Choose the plan that fits your organization's security needs

Pricing for US/EU

Showing prices for US/EU.Somewhere else?

Starter

Essential risk visibility for small teams

Free

No credit card required

  • 1 Organization
  • Up to 3 Users
  • Summary Dashboard(Summary view only)
  • Phase 1 Assessment — the security basics (~50 questions)
  • Email Support
  • Basic PDF Report
  • Full Risk Analysis & Financial Impact
  • Compliance & Gap Management
  • Connector Integration(1 connector)
  • API Access & SSO
Get Started Free
Most Popular

Professional

Complete risk management for growing organizations

$299.00/mo

$2,990.00/yr (17% off)

  • 1 Organization
  • Up to 25 Users
  • Full Dashboard & Analytics
  • All Assessment Phases (1–3) — full technical deep-dive
  • Priority Support
  • All Report Formats (PDF, DOCX)
  • Full Risk Analysis & Financial Impact
  • Compliance & Gap Management
  • All Connector Integrations
  • API Access
Upgrade to Professional

Enterprise

Advanced security for large enterprises

$1,499.00/mo

$14,990.00/yr (17% off)

  • Unlimited Organizations
  • Unlimited Users
  • Full Dashboard & Advanced AI
  • All Phases (1–3) + team collaboration
  • 24/7 Dedicated Support
  • All Report Formats + Scheduled Reports
  • Full Risk Analysis & Financial Impact
  • Compliance & Gap Management
  • All Connector Integrations
  • Full API Access, Webhooks & SSO/SAML
Upgrade to Enterprise

Not sure which plan fits?

New to this?

Connectors are configured on request. After purchase, our team sets up and verifies each integration with you — they are not enabled automatically.

Security Assessment Add-On

Our expert security team delivers comprehensive external network reviews through vulnerability assessments, penetration testing, or both. In just a few simple steps, gain clear visibility into your cyber risk posture and take control of your security.

Cancel or change plans anytime.

Frequently Asked Questions

Everything you need to know about CoreCyber – from the live platform experience to penetration testing services and ongoing compliance coverage.

Platform

What is the CoreCyber platform?

CoreCyber is a cybersecurity risk management and analytics platform that lets founders, CISOs, and security leaders continuously assess, quantify, and manage cyber risk in one place. It combines sector‑specific assessments, advanced risk models (including FAIR‑style financial impact), dashboards, POAM tracking, and reporting so you can move from ad‑hoc spreadsheets to a repeatable, data‑driven program.

What makes CoreCyber different from other risk tools?

CoreCyber is built to serve both small teams and large enterprises with the same underlying risk engine. We cover all 16 U.S. critical infrastructure sectors plus 10 additional commercial sectors (26 in total), and tailor the user experience by persona: entrepreneurs get guided, jargon‑free workflows; CISOs get deep analytics, ROI models, and board‑ready reports; GSOCs and MSSPs get multi‑tenant monitoring, connector integrations and supply‑chain aggregation.

What are the key features available today?

Today, CoreCyber includes guided sector‑specific assessments, dashboards with risk scoring and trends, FAIR‑style financial impact models, POAM and compliance gap tracking, supply‑chain risk aggregation across vendors, and connectors for common security and IT systems. Reporting templates generate executive summaries, board views, and technical remediation details in minutes.

How does CoreCyber's in-app guidance help my team?

CoreCyber includes a built-in Help Center, a plain-language security glossary, contextual tooltips, and guided product tours that explain security concepts as you work. On the analytics side, SHAP-style driver views explain in plain language why a risk score changed and which factors moved it most. Together these keep busy founders and non‑security stakeholders moving quickly while still letting security teams dive into the underlying detail when needed.

How does CoreCyber handle supply chain and vendor risk?

Our supply‑chain module aggregates risk across vendors, contracts, and services so you can see concentration risk and critical dependencies at a glance. You can import vendor data, capture questionnaire results, link penetration tests or third‑party attestations, and roll everything up into enterprise‑level views.

How does CoreCyber notify my team when risk changes between assessments?

CoreCyber includes a flexible notification system for risk events, assessment milestones, connector changes, and vendor activity. You can configure which events trigger alerts, who should receive them, and how frequently digests are sent. This keeps security, IT, and leadership aligned without flooding inboxes with noise.

Which systems can I integrate with CoreCyber?

CoreCyber offers connectors for common cloud, identity, security, commerce, and logging platforms. Today, the live connectors include Shopify, Splunk, Bitdefender, and CoreCyber vPenTest, along with integrated endpoint and vulnerability-scanning vendors that are already wired into the platform. AWS, Microsoft 365, and Google Workspace connectors are marked as "Coming Soon" in the portal and will be available shortly. Additional connectors for other cloud providers, commerce platforms, SIEM tools, and security products are on our roadmap so you can see what's planned next. These integrations enrich your assessments with real telemetry and reduce the amount of manual data entry required. For Enterprise customers, we can also scope and deliver additional or custom integrations as part of your onboarding or expansion roadmap.

How do vendors and suppliers share evidence or complete questionnaires?

Vendors receive secure, time-bound invitations to the CoreCyber vendor portal, where they can answer tailored security questionnaires, upload evidence, and acknowledge requirements. Their responses are normalised into your supply-chain views so you can compare vendors consistently, track outstanding items, and feed high-risk findings directly into POAM and risk views.

How is access to the CoreCyber portal secured for my team?

Access is protected using modern authentication with support for multi-factor authentication, backup codes, and granular roles. Administrators can manage users centrally, enforce strong sign-in requirements, and audit access and activity. Combined with strict role-based access and data isolation in the backend, this ensures that only the right people can see the right data.

How does CoreCyber handle differences across sectors or industries?

CoreCyber ships with specialized modules for each critical infrastructure and commercial sector. Question sets, scoring logic, and analytics are tuned for your vertical—so a healthcare provider, a financial institution, and an energy operator see controls and risks that match their reality. Sector modules also drive tailored benchmark views and reporting, so you can compare your posture against peers instead of a one-size-fits-all baseline.

Compliance & Standards

Which frameworks and regulations does CoreCyber support?

CoreCyber is aligned to NIST CSF 2.0 and ISO 27001:2022, and supports mappings to GDPR, PCI‑DSS 4.0, HIPAA, SOC 2, CMMC and other sector‑specific regulations. Our compliance and POAM views let you run dynamic gap analyses, assign remediation tasks, and generate evidence for audits directly from your assessment data.

How is my data protected in CoreCyber?

Security and privacy are first‑class requirements. CoreCyber is designed to be SOC 2 and ISO 27001 aligned, with strong encryption in transit and at rest, strict role-based access controls, and audit logging. Each tenant's sensitive data is encrypted with its own dedicated encryption key, so one organization's data can never be decrypted with another's. Assessment data stays within your secured tenant, and we provide controls to help you meet GDPR/CCPA and contractual obligations.

Can CoreCyber generate compliance reports directly from our data?

Yes. CoreCyber can generate compliance-ready reports using the same data that powers your risk assessments and POAMs. You can produce evidence packs and summary reports aligned to frameworks such as NIST CSF 2.0, ISO 27001:2022, GDPR, PCI-DSS, HIPAA, SOC 2, and sector-specific regulations—without exporting everything to spreadsheets. Filters let you focus on a specific business unit, geography, or time window, and you can export reports for auditors, regulators, or internal review.

What is a POAM and why is it important in cybersecurity?

A Plan of Action and Milestones (POAM) is a structured list of security gaps, the steps you will take to fix them, and when those fixes are due. In cybersecurity and compliance, POAMs are used to show auditors, regulators, and executives that you understand your risks and have a concrete remediation plan. CoreCyber turns assessment findings into POAM items you can prioritize, assign to owners, track to completion, and report on over time—so you can demonstrate progress instead of managing everything in spreadsheets.

Analytics & Reporting

What advanced analytics does CoreCyber provide beyond basic risk scores?

CoreCyber goes far beyond a single risk score. You can drill into temporal risk trends, model different loss scenarios, explore SHAP-style drivers that explain why a score moved, benchmark your posture against sector peers, and evaluate the ROI of specific controls. These analytics are built directly from your assessment, connector, and vendor data—no spreadsheets required.

Can I generate reports for executives, boards, or regulators?

Yes. CoreCyber includes prebuilt report templates for executives, boards, regulators, and technical teams. You can generate PDF and DOCX reports that summarize risk, financial impact, POAM status, and compliance coverage, then customize filters by business unit, geography, or time period. Many customers use these reports directly in board decks and audit responses.

Can reports be scheduled or automated?

You can configure scheduled reports to run on a recurring cadence—monthly, quarterly, or aligned to your board and audit cycles. Reports are generated automatically from the latest assessment, connector, and vendor data, so stakeholders receive an up-to-date view of risk and remediation progress without manual effort.

Pen Testing

Can I order penetration testing directly through the platform?

Yes. External vulnerability assessments and penetration tests can be requested from within the CoreCyber portal. You choose scope and timing, complete a short intake, and track engagement status and reports alongside your broader risk and compliance program.

What is an external penetration test?

An external penetration test simulates a real‑world attacker operating from the internet. Our team targets your public‑facing assets—web applications, VPNs, email gateways, and other exposed services—using the same techniques adversaries rely on to identify exploitable weaknesses before they are abused in the wild.

How is an internal penetration test different from an external one?

Internal penetration testing assumes an attacker has already obtained some level of access to your internal network or an employee account. Rather than testing your perimeter, it focuses on lateral movement, privilege escalation, data access paths, and how far an attacker can progress once they are inside.

Do you support internal penetration testing now that CoreCyber is live?

Yes. After launching the platform, we enabled both external and internal penetration testing through the same workflow. You can scope internal tests to specific networks, identity stores, or business units and have findings automatically flow into your risk register and POAM views.

Why do we still need penetration testing if we use the platform?

Automated assessments and analytics help you understand control maturity and financial impact, but penetration testing validates how those controls behave under real attack conditions. Regular pen tests are often required for compliance, support cyber‑insurance underwriting, and give you concrete exploit chains that can be plugged directly into CoreCyber for prioritised remediation.

Post‑Launch & Onboarding

What happens after we subscribe to CoreCyber?

After you subscribe, you receive access to the portal immediately and can start your first assessment within minutes. Our team schedules an onboarding session (typically within a few business days), helps you configure sectors, connectors, and user roles, and works with you to define an initial assessment and reporting cadence.

Latest Cybersecurity News

Stay informed with real-time updates from trusted security sources

View All Articles
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.

AI/ML Security
Malware
Threat Intelligence
The Hacker News
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java.

AI/ML Security
Authentication
Threat Intelligence
Vulnerability
The Hacker News
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update.

Data Breach
Vulnerability
The Hacker News
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an…

AI/ML Security
Authentication
Phishing
Threat Intelligence
The Hacker News
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.

AI/ML Security
Authentication
Cloud Security
Ransomware
Threat Intelligence
The Hacker News
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.

AI/ML Security
Ransomware
The Hacker News