Cybervize
OdySecureOdySecure, the security platform by Cybervize

The answer your board expects. Evidenced, not asserted.

The security platform by Cybervize grows with you, from an owner-led mid-market company to a corporate group. Five modules share the same data layer, permission model and audit trail: one continuous information flow instead of silos.

What the AI takes over

You do not fill in an ISMS. You feed it your documents.

OdySecure derives what applies in your organisation: from your documents and your structure, from business process to security process, each station a proposal a human accepts.

  1. 1

    Business process

    Your documents are read and broken down into checkable statements. From them come the business processes that need protecting.

  2. 2

    Asset

    Sites, systems and dependencies are recognised as an organisation graph and linked to the processes.

  3. 3

    Risk

    Risks emerge from assets and obligations, not from a template.

  4. 4

    Measure

    For every risk, the measures that make it smaller.

  5. 5

    Control

    Measures are mapped onto the controls of your frameworks, several at once.

  6. 6

    Policy

    The result is a proposed policy, derived from your organisation rather than a template. It becomes a binding policy only after your sign-off.

  7. 7

    Security process

    Policy and measures move into day-to-day operations: tasks with a due date and an owner, with evidence produced as the work is done.

A human decides at every station

Every station produces proposals, not facts. You accept them one by one or per station, you pause the run, resume it or undo it. Policies carry an approval record naming who signed off. Guardrails and segregation of duties apply to the AI exactly as they do to your staff.

What a group structure looks like

Parent company, plants across several countries, a branch office and the organisational units beneath. Every level carries its own assets, risks and evidence. From the software, not a mock-up.

Company structure in OdySecure: Auronex Nutzfahrzeuge GmbH as parent with plants in Germany, France and Spain, a branch in Vienna and four organisational units at the Berlin site

Five modules. One continuous information flow.

ISMS

Information security management per ISO 27001. Organizational structure, BIA, incident management with regulatory reporting (GDPR 72h, NIS-2, KRITIS), asset inventory with dependency graph, dual risk assessment, measure tracking, controls and Statement of Applicability.

More about the ISMS module →

Assessment

Questionnaire-based security assessments against any standard. OSCAL import (BSI Grundschutz, NIST SP 800-53, IEC 62443) or your own standards created directly in the platform, multi-site campaigns, automated scoring, audit-proof snapshots and automated reports with built-in LLMs (PDF, Excel, PowerPoint).

More about the Assessment module →

BCM

Business Continuity Management per ISO 22301. Continuity plans with RTO validation against BIA data, threat scenarios, gap analysis, BCM tests (tabletop to full exercise), compliance score and management reviews with auto-populated KPIs.

More about the BCM module →

TPRM

Third-party risk management for suppliers and service providers. Automated criticality assessment, contract register with 19 EBA mandatory fields, subcontractor chains, due diligence, concentration risk, exit strategies and cross-app impact analysis. Contract register and exit strategies follow financial regulation: DORA has applied since 17 January 2025, and the EBA consultation paper CP/2025/12 is a draft that builds on it. Criticality assessment holds outside financial supervision as well, because ISO 22301 treats suppliers and partners as a dependency of time-critical activities and includes them in continuity solutions.

More about the TPRM module →

Awareness

Security awareness with audit evidence. Workforce register from a file import, previewed before it is written, training in five languages with company-specific tailoring and review before release, phishing simulation measured by report rate with immediate follow-up training, policy acknowledgement and evidence export for ISO 27001 A.6.3 and NIS-2 Article 20.

More about the awareness module →

No silos. Defined interfaces between all modules.

AssessmentISMS

Gaps become measures with one click

ISMSBCM

BIA data validates BCM plans. Test failures create measures

TPRMISMS

Supplier risks linked to assets and incidents

BCMTPRM

Critical suppliers create threat scenarios

Platform foundation across modules

Multi-tenant

Strict data isolation. Consultants work across tenants without mixing data.

4-layer RBAC

Module license, roles, attributes and entity scoping. 16 predefined roles. Default-deny.

Four-eyes

Segregation of duties for approvals, snapshots, risk acceptances and measure completion.

Audit trail

Actions are logged: who, when, what, from which IP. CSV export for auditors.

Book a free demo

60 minutes, live on demo data.

How to put the platform to work

From the trigger to a passed audit: the Cybervize journey has five stations, and you join wherever you stand. With or without an in-house CISO.

Without an in-house CISO, we fill the function in the vCISO mandate, with OdySecure included. About the vCISO mandate

What happens in which order, and who does it

  • Define the scopeTogether. Which entities, sites and processes are in.
  • Activate standardsUs. An activated standard derives risks, measures and processes by itself, instead of somebody typing them in.
  • Connect systemsUs, with your access. Eighteen connectors pull incidents, vulnerabilities and assets from your systems, instead of you maintaining lists.
  • Roles and permissionsYou. Who sees what, who approves. Nobody can take that off your hands.
  • Bring in what existsTogether. Existing policies and evidence move in rather than being rewritten.
  • Sign-offYou. The rollout ends when the agreed scope stands, not before.

How long it takes depends on your scope, and we will not quote a number of weeks we cannot evidence. What you can know beforehand: the maturity check gives you a first traffic light in five minutes, without signing up.

Check your maturity yourself in five minutes

See the journey: 5 stations

Where do we stand? Sourced answers instead of gut feeling.

The AI that names its sources and says no when data or read permission is missing. Questions are logged for audit.

The AI layer is not a fifth module. It uses the same platform core as your people: role model, four-layer RBAC, four-eyes rules and audit trail apply to AI agents unchanged. That is why the OdySecure Navigator can answer from connected data, and why agents only act within the same boundaries that apply to humans.

OdySecure Navigator: sourced answers

Available

The assistant answers questions like "What are our biggest risks?" or "Are we audit-ready?" from your tenant's real data: around 25 vetted queries, every answer with source and metric, strictly within read permissions. If there is no data or no read permission, it says exactly that.

AI agents: acting with approval

Design-partner programme

AI as an employee: its own account, roles, a visible AI-agent badge. Suggesting is the default; acting is limited to narrowly defined fields and requires four-eyes approval. In a design-partner programme, not yet generally available.

Sourced answers instead of guessed answers

A general-purpose chatbot with document upload answers from whatever it is given: no read permissions, no current numbers, no log. An AI checkbox next to a GRC form does not turn questionnaires into connected data. The OdySecure Navigator answers from your tenant's connected, current data: with source and metric, strictly within read permissions, logged for audit, in the default mode on a model operated locally in Germany. When it cannot answer, it says so: "no data" is a different answer than "no read permission". Our vCISO works on the same live records within the mandate.

Book a free demo

60 minutes, live on demo data.

More about the platform

The model behind it: the ISMS operating system

From business process through asset, risk, measure, control and policy to the security process, every element is linked. Evidence is produced in daily operations, and every causal chain can be traced back to the requirement.

One linked data foundation: from the business process to the security processBusinessprocessAssetRiskMeasureControlPolicySecurityprocess

What a playbook looks like

The reporting procedure for a data breach, as a workflow inside the software: four steps, each with what to do, including the 72-hour deadline from Article 33 GDPR. Not a mock-up.

Playbook “data breach notification” in OdySecure: four steps from documentation through risk assessment and notifying the supervisory authority to informing the data subjects

What sets OdySecure apart from other ISMS tools?

Anyone evaluating an ISMS tool typically compares three categories: stand-alone ISMS software (ISO 27001 only), Excel/SharePoint home-grown setups, and large GRC suites. OdySecure is none of these. Here are the four dimensions where it differs measurably.

01

Five modules, one data layer instead of five tools side by side

Typical ISMS tools

Conventionally, ISMS sits in one tool, BCM in a second, TPRM in a third and assessments in Excel or a fourth tool. Four data models, four permission models, four audit trails. Data is synchronised manually or not at all.

OdySecure

ISMS, BCM, TPRM and Assessment share one data layer. From assessment gaps you create measures with one click, BIA data validates BCM plans, critical suppliers in TPRM create BCM threat scenarios. One audit trail, one permission model, one reporting view.

02

OSCAL import instead of waiting for the vendor

Typical ISMS tools

When a new standard such as DIN SPEC 27076 appears, classic ISMS tools take months until the vendor adds the catalogue. Excel in the meantime.

OdySecure

OSCAL import (NIST's official format for security catalogues) lets new standards be loaded in minutes. BSI IT-Grundschutz, NIST SP 800-53, IEC 62443, DIN SPEC 27076 are already in. Own sector catalogues likewise.

03

AI operations you decide on

Typical ISMS tools

Where the vendor sets the AI path, you do not get to decide where the data goes.

OdySecure

Three operating modes: Sovereign (self-operated LLMs in Germany, no external data sharing), BYOK (customer brings their own OpenAI/Anthropic/Azure keys under their own contract) or Managed. Three modes, three data-flow logics, configurable per tenant.

04

Built from consulting practice

Typical ISMS tools

Classic ISMS tools are software products whose vendors buy in regulatory depth or licence it from consultants.

OdySecure

The platform codifies the methodology of our vCISO mandates. Built in a 14-month partnership with the CISPA incubator (Helmholtz Center for Information Security), funded by the German BMFTR StartupSecure programme. In a vCISO mandate our vCISO works with it.

This section compares typical tool architecture patterns, not named vendors. For a vendor-specific comparison against your current tool, book a 30-minute call.

Still working out which route is right for you? The four ways to ISO 27001, compared

Why does OdySecure exist?

Because classic GRC tools turn compliance into a tick-box exercise, instead of anchoring it in day-to-day operations.

Cybervize was founded in 2021 on one thesis: information security consulting delivers the greatest value when the right platform comes with it. The goal from day one was to implement information security so that it stays provable in day-to-day operations.

Classic GRC tools mostly just ask questions that someone in IT has to answer. Compliance becomes a tick-box exercise running parallel to day-to-day operations, never anchored economically in the operational business. OdySecure was built to remove exactly this split: compliance requirements are woven into the running security and IT processes, evidence is generated within day-to-day operations, and operational processes are compliant by default. Development was funded by the German federal government's StartupSecure programme and took place in a 14-month partnership with the CISPA incubator, the Helmholtz Center for Information Security.

Today, Cybervize comprises two independent companies: Cybervize Consulting GmbH delivers vCISO and Interim CISO engagements, while Cybervize Operations GmbH licenses the platform to mid-market and enterprise clients. The consulting practice came first; the platform is its tool and the second route: in the vCISO mandate our vCISO works with OdySecure, and organisations with their own CISO license the platform on its own.

The name OdySecure comes from a federally funded research project: "Effective management of cyber security in SMEs through automation", funded under the StartUpSecure programme of the German Federal Ministry of Research, Technology and Space. The software licensed today grew out of that project.

Standards and regulatory requirements

A standard you choose, a regulatory requirement applies to you. The platform keeps both as a catalogue: 50 frameworks, ISO 27001 as the shared language.

Standards and frameworks

ISO/IEC 27001ISO/IEC 42001ISO 22301IEC 62443NIST CSF 2.0NIST SP 800-53BSI C5:2026CIS Controls v8.1TISAXSOC 2BSI IT-Grundschutz

Regulatory requirements

NIS-2DORA including RTS/ITSGDPREU AI ActCyber Resilience ActKRITIS Umbrella ActMaRiskEnergy IT security catalogue
See all standards and regulatory requirements →

One implementation, multiple standards

ISO 27001 is the platform's common language. Further standards are mapped onto it via crosswalks wherever their requirements can be meaningfully aligned: a control implemented once then serves several frameworks at the same time and reduces duplicate upkeep. Obligations that cannot be expressed as a control are managed in their own right. Each activated standard gets its own statement of applicability and maturity view, either as a certification goal or as a reference mapping. New standards are added as data, not as custom development: load the catalogue, maintain the mapping, activate.

Normative traceability

Why does this measure exist, and which standards does it cover?

  1. Standard
  2. Requirement
  3. Control
  4. Implementation measure
  5. Evidence

Operational effectiveness loop

Does the measure actually work, and how does it change the risk?

  1. Risk scenario
  2. Control
  3. Measure
  4. Evidence and telemetry
  5. Effectiveness assessment
  6. Residual risk

Both chains share the same objects on the platform, and the effectiveness loop is a control loop: evidence, tests and telemetry change the effectiveness assessment and with it the residual risk, and the residual risk triggers new measures where needed. If a piece of evidence lapses, it is visible which requirements and which risks depend on it.

215

curated mappings connect ISO 27001, NIS-2 and BSI IT-Grundschutz in the core crosswalk. Every single one has been reviewed by a security expert and typed as equivalent, partially covering, or related. AI suggestions stay marked as suggestions until a security expert has reviewed them.

Which answers management and supervisory boards get from the platform

Five management questions every board should have ready for the supervisory board, the external auditor and the insurer. The platform delivers them on demand, not as an IT translation exercise.

01

Which decision can I make better afterwards?

Investment prioritisation based on quantified risks. Top-10 risks with mitigation status and budget annotation, sorted by business impact. Which order you work through them in is your call.

02

Which evidence do I have for regulators, customers and auditors?

On-demand reports with audit trail, ISO 27001/NIS-2 status, sector-specific evidence (DORA, IEC 62443, TISAX). Exportable as PDF, Excel and PowerPoint. Every statement is documented with timestamp, owner and source.

03

Which risks are accepted, open or overdue?

Risk register with status, owner, due date and 12-month trend. Accepted risks have documented reasoning, open risks have owners and deadlines, overdue risks are flagged as such. No more hidden risk lists.

04

What does risk reduction cost?

Measure tracking with budget annotation per measure. You see which funds have been released for which risk reduction, what has already been spent and which measures sit without budget.

05

Who is accountable?

RACI model with clear owner roles per control and measure. Before every supervisory-board meeting you can name who owns which measure, instead of searching at the next escalation.

Data & AI Sovereignty

Hosting of the platform and processing of your data within it exclusively in data centers in Germany, with a European provider without a US parent company, which under current law is not subject to the US CLOUD Act.

Three operating modes for AI processing, each with its own data-flow logic. Sovereign Mode: self-operated LLM in Germany, no data sharing with external model providers. BYOK Mode: customer-owned API keys (OpenAI, Azure, Anthropic, Ollama), data processed under the customer's contract with the respective model provider. Managed Mode: Cybervize-operated variant with defined data residency.

GDPR-compliant with JSON data export that marks its own limits, anonymization and scheduled data deletion.

Data residency Germany
Three AI modes available: Sovereign (local LLM), BYOK, Managed
Encrypted storage of all API keys
GDPR: data export, anonymization, scheduled deletion

Frequently Asked Questions about OdySecure

How is OdySecure structured?
The platform consists of a platform core (multi-tenant architecture, 4-layer permission model, audit trail, AI service) and five licensable modules: ISMS (Information Security Management), Assessment (questionnaire-based security assessments), BCM (Business Continuity Management per ISO 22301), TPRM (third-party risk management, with contract register and exit planning per financial regulation and supplier continuity per ISO 22301) and Awareness (training, phishing simulation and evidence). Plus an optional integrations module for third-party systems.
How do the modules work together?
All modules share the same data layer and complement each other through defined interfaces: from assessment gaps you create measures with one click. BIA data from ISMS validates BCM plans. Critical supplier ratings in TPRM create BCM threat scenarios. The asset dependency graph connects ISMS assets with supplier risks. Training and reporting rates from the awareness module feed the metrics register and cover the security process for awareness. This creates a continuous information flow instead of isolated silos.
Which standards and regulations are covered?
The platform keeps 50 frameworks as a catalogue, cleanly split into standards and frameworks (including ISO 27001, ISO 42001, ISO 22301, IEC 62443, NIST CSF, NIST SP 800-53, BSI C5, CIS Controls, TISAX, SOC 2, BSI IT-Grundschutz) and regulatory requirements (NIS-2, DORA including its RTS and ITS, GDPR, EU AI Act, Cyber Resilience Act plus sector-specific rules from energy through financial supervision to healthcare). ISO 27001 is the shared language; new frameworks are imported via OSCAL or created directly in the platform, and integrated via crosswalk. The full, split list is on the Standards and Regulation page.
How does the AI integration work?
A central LLM service is available to all modules. Use cases: assessment answer suggestions, TPRM contract analysis and criticality assessment, TPRM document analysis, and measure recommendations from assessment gaps. Companies can bring their own API keys (OpenAI, Azure, Anthropic, Ollama) or use the managed service. Token budgets and fallback behavior are configurable.
How is the permission model structured?
Four layers: 1) Module license determines which modules are visible. 2) RBAC with 16 predefined roles (e.g., risk manager, assessment reviewer, BCM manager, TPRM analyst, auditor). 3) ABAC for field-level conditions. 4) Entity scoping restricts users to specific organizational units. Critical actions require four-eyes principle (Segregation of Duties).
Can the platform integrate with existing systems?
Yes, via the integrations module with configurable connectors for CMDB, Jira, ServiceNow, and SIEM/SOAR. Supports API key, OAuth2, Basic Auth and Bearer Token with configurable field mapping. Sync direction: pull, push or bidirectional. Webhook reception with HMAC-SHA256 signature verification.
Where is the data hosted?
Hosting of the platform and processing of your data within it exclusively in data centers in Germany, with a European provider without a US parent company, which under current law is not subject to the US CLOUD Act. In Sovereign mode, the default, AI models are self-operated in Germany with no data shared with external model providers; alternatively BYOK or Managed, where you decide on the data flow. GDPR-compliant with JSON data export that marks its own limits, anonymization, and scheduled data deletion.
Which platform keeps ISO 27001 together with NIS-2 or DORA in one data layer?
OdySecure keeps ISO 27001 plus NIS-2 or DORA, depending on your sector, in a single shared data layer instead of running separate tools side by side. From an assessment result you create an ISMS measure per question directly in the report, with one click and without re-entering the data; BCM plans and TPRM ratings build on the same data layer, so a single data capture serves ISO 27001 and your sector's regulation at once. New frameworks can be added via OSCAL import in minutes or created directly in the platform. Hosted in Germany, with sovereign-mode AI.
Which provider supports ISO 27001 together with NIS-2 or DORA from a single source?
Cybervize supports ISO 27001 plus NIS-2 or DORA, depending on your sector, from a single source. Without an in-house CISO, the vCISO mandate from €3,600/month fills the function, with the OdySecure platform included. With your own CISO, you license OdySecure on its own, from €12,900 a year. Either way, assessment, measure planning and evidence come from one data layer. OdySecure was built in partnership with the CISPA incubator and is hosted in Germany.
What can the OdySecure Navigator do, and what does it deliberately not do?
The OdySecure Navigator answers questions about your security and compliance posture from your tenant's real data: risks, vulnerabilities, incidents, assessments, compliance status, measures, suppliers, KPIs. It uses around 25 server-side vetted queries, answers with source and metric, and strictly respects the read permissions of the person asking. If a question is ambiguous, it asks back instead of guessing. What it deliberately does not do on its own: it changes nothing without your confirmation. It can prepare, and put up for approval, the things it has an action for: creating a risk, creating a task, starting an assessment, linking a measure to a risk; only your approval triggers them. Closing an incident is something it cannot do at all: that is a hard lock, not an approval question. That boundary is design, not a missing feature. Questions are logged for audit.
How do I know an answer is correct?
Every company-specific answer names the source it used and the underlying metrics. The language model has no free database access: it selects from around 25 server-side fixed queries and puts their results into words. If a question cannot be answered from data, the assistant says so instead of guessing. And if you consider an answer wrong, you report it directly as a change suggestion; that automatically creates a ticket for the product team.
What data leaves our company?
In sovereign mode, no customer data is passed to external model providers: the language model is operated locally in Germany, and answers stay strictly within your own tenant. Alternatively you use your own keys (BYOK) or your own model (bring your own LLM); then you decide the data flow. Questions to the assistant are logged as read-only governance queries, and the log is yours.
How are AI agents controlled?
AI agents are managed like employees: their own account, roles, organizational permissions, visibly labelled "AI agent" everywhere. The default mode is suggesting: a human confirms, adjusts or rejects. Switching to acting mode requires a second person (four eyes); switching back is immediate. Independent of mode and role, hard locks apply: an agent can never finally close an incident, declare risk acceptance, grant an approval, confirm suggestions, or give rights to itself or other agents. Added to that: a kill switch, access keys with an expiry term, an audit log of the actions, and automatic entry in the platform's own AI system inventory. This is your own record; an entry in the EU database under Art. 49 of the AI Act applies to providers of high-risk systems and certain public bodies. The AI agents are in a design-partner programme, not yet generally available; we are happy to show the current state in a conversation.

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT