Forsidebilde av Cyrigo - Take control of your security risks
Cyrigo - Take control of your security risk

Cyrigo - Take control of your security risk

Programvareprodukter for datasikkerhet

Gjøvik, Innlandet 1 957 følgere

Risk-driven governance for security, privacy, and regulatory compliance

Om oss

Take control of your security risks. Cyrigo helps organizations achieve compliance, strengthen operational resilience, and protect the systems and processes they depend on to deliver products and services. Built by Governance, Risk, and Compliance experts. Developed and operated in Scandinavia.

Nettsted
https://www.diri.ai
Bransje
Programvareprodukter for datasikkerhet
Bedriftsstørrelse
2–10 ansatte
Hovedkontor
Gjøvik, Innlandet
Type
Privateid selskap
Grunnlagt
2026
Spesialiteter
Risk management, Cybersecurity, Cyberrisk, Information security, Infosec, Privacy, GDPR, GRC

Produkter

Beliggenheter

Ansatte i Cyrigo - Take control of your security risk

Oppdateringer

  • Why use Bowtie instead of a conventional risk register? A traditional risk assessment usually flattens each scenario into a separate row: Event → Likelihood → Consequence → Controls. But real risks are rarely that tidy. One unwanted event may have several causes, several consequences and controls that affect multiple parts of the scenario. In a spreadsheet, this creates repetitive rows. The same event, controls and descriptions are copied again and again. Updating one element means finding every place it appears, and the relationships quickly become difficult to see. Bowtie models the structure directly: • The unwanted event sits in the centre • Causes and preventive controls sit on the left • Consequences and consequence-reducing controls sit on the right This shows not only the risk level, but how the scenario actually works. It also reveals which controls have the greatest effect across several causes or consequences. In Cyrigo, these components can be reused, analysed individually and connected to the risk matrix, risk register and cost-benefit analysis. A spreadsheet gives you rows. Bowtie gives you the system behind them. Read more: https://lnkd.in/eJtRivvK

  • Information security, IT security, cybersecurity or digital security? The terms are often used interchangeably, but they do not describe exactly the same thing: • Information security protects information in any form — digital, physical or verbal. • IT/ICT security protects the technology itself, including hardware, software and networks. • Cybersecurity protects everything that can be affected through ICT — from business systems to vehicles, telecommunications and power supplies. • Digital security is increasingly used as an overarching term covering all or parts of these areas. The distinction depends largely on what we are protecting and which vulnerabilities can be exploited. In practice, the boundaries are blurred. Almost everything now depends on digital technology, which means cybersecurity is no longer only an IT concern. It is closely connected to operational risk, societal security and safety. And why has “cybersecurity” become the dominant term? Probably because “cyber” sounds more exciting. The conceptual model is based on Von Solms and van Niekerk’s 2013 paper, From information security to cyber security. https://lnkd.in/eXpUH2m4

  • The control you cannot write your way out of. Almost every risk assessment identifies the human factor: someone clicks the link, approves the invoice or sends information to the wrong person. The usual response is «security awareness training», supported by a policy and an attendance list. That proves the training happened. It does not prove that it worked. That is why Cyrigo has partnered with Moxso. Moxso provides adaptive micro-learning and phishing simulations based on each employee’s actual behaviour and risk level. More importantly, it produces measurable results: • Phishing click rates • Reporting rates • Completion rates • Improvement over time These measurements can be connected directly to the risks and controls managed in Cyrigo. Instead of documenting an intention to improve security awareness, organisations can demonstrate whether the control is actually reducing risk. The training also supports requirements in #ISO27001, #NIS2 and the Norwegian Digital Security Act (#digitalsikkerhetsloven). Moxso security awareness training is now available to Cyrigo customers. Learn more or contact us: https://lnkd.in/eBV_SxPs

  • Cyrigo - Take control of your security risk la ut dette på nytt

    Til og med leder for bygging av Mjøssykehuset sier det: «Reduksjon av gjennomføringsrisiko» Og hvilke gjennomføringsrisikoer står vi egentlig overfor ved bygging av Mjøssykehuset? Det er neimen ikke få. Både operasjonelle, fysiske og digitale. Og hvilke risikoer må vi jobbe med underveis for å være forberedt på hendelser som kan oppstå ‘etterpå’? Når alt skal være ferdig. Dette gjelder vel alle involverte organisasjoner 🧐 Spennende å delta på næringskonferanse for Mjøssykehuset i dag 👌 Kjersti Lysne Sanden Ringsaker kommune Sykehuset Innlandet Cyrigo - Take control of your security risk

    • Ingen alternativ tekstbeskrivelse for dette bildet
  • Små virksomheter trenger også god informasjonssikkerhet. Vi har utviklet et unikt og praktisk rammeverk for virksomheter som ønsker å få kontroll på informasjonssikkerheten og oppfylle personvernkravene – uten å begynne med hundrevis av kontroller og flere år med konsulentarbeid. Dette er basert på erfaringer fra å ha jobbet med små virksomheter gjennom flere år. Cyrigo gir dere: ✅ En tydelig oversikt over hva dere må gjøre ✅ Praktiske kontroller tilpasset mindre virksomheter ✅ Klare ansvarsområder, oppgaver og frister ✅ Dokumentasjon og bevis samlet på ett sted ✅ Risikovurderinger knyttet direkte til kontrollene ✅ Dashboards og rapporter for ledelsen, kundene og revisor Rammeverket har tre nivåer. Dere kan starte med det mest nødvendige og utvikle sikkerhetsarbeidet i takt med virksomheten. Et ferdig styringssystem for sikkerhet og personvern – for virksomheter som er lei av regnearkene, men ikke trenger kompleksiteten i et stort GRC-system. Systemet kan videreutvikles til et sertifiseringsløp senere. Ta kontroll på sikkerhetsrisikoen med Cyrigo - kontakt@cyrigo.com

  • We are happy to announce that we have partnered with Moxso to make human risk management measurable! Your risk register says “human error.” You’ve rolled out awareness training. Is it working? Together, Cyrigo and Moxso connect risk management with adaptive awareness training, linking measurable results to the risks you need to reduce. See where training is making a difference—and where to focus next.

    Viser organisasjonsside for Moxso

    9 264 følgere

    We've partnered with Cyrigo - Take control of your security risk. From today, Cyrigo customers can get Moxso human risk management through adaptive awareness training directly through the platform where their risks already sit. Most risk registers put the human factor near the top. Very few can show whether it improved. The control is usually a training policy and an attendance list, and neither tells you if anything actually changed. Moxso adds the data. Click rate, reporting rate, improvement over time, per person and per department, attached to the risk it's meant to mitigate. That makes it a control you can measure. That's the point of the partnership.

    • Ingen alternativ tekstbeskrivelse for dette bildet
  • Blir med på gratis webinar om Digital sikkerhet med vår egen Grethe Østby!

    Hva skjer når virksomheten faktisk blir satt under press? Det er én ting å kjenne kravene. Noe annet er å vite hva som er kritisk, hvordan virksomheten skal håndtere en hendelse og om organisasjonen faktisk er forberedt. I første webinar gikk Gaute Bjørklund Wangen, Ph.D. gjennom krav, risikovurderinger og tiltak. I del 2 flytter vi oppmerksomheten videre til hvordan bygge beredskap og håndtere hendelser 🛡 9. september kl. 09.00 går Grethe Østby, PhD, konkret gjennom hvordan virksomheter kan arbeide med: – Kritikalititetsvurderinger – Ulike beredskapsplaner – Håndtering av kriser – Opplæring og øvelser Webinaret er særlig relevant for ledere og andre med ansvar for IT, informasjonssikkerhet, risiko, beredskap og etterlevelse. Følg lenken i kommentarfeltet og meld deg på webinar i dag! Rune Andre Tveit Per MC Svarstad Cyrigo - Take control of your security risk Opplæringskoden AS #digitalsikkerhetsloven #informasjonssikkerhet #NIS2

  • Closing off a big month of development in Cyrigo! A lot has shipped in August. Some highlights from our latest release: Reuse evidence across frameworks Already documented something for ISO 27001 that also satisfies a DORA or another framework requirement? Cyrigo can now identify that overlap and let you reuse the evidence instead of doing the same compliance work twice. A growing framework library Cyrigo already supports GDPR, Digitalsikkerhetsloven, ISO 27001 and DORA, alongside our own Security & Privacy for Small Businesses — a practical workplan designed to make security and privacy manageable for smaller organizations. And we're not stopping there. More frameworks, mappings and ready-to-use compliance content are on the way. Better policy governance Clearer ownership, visibility and access across organizations — making policies easier to manage as part of the wider GRC process. Smarter notifications New notifications for comments and framework ownership, with organization-level defaults and improved administration. Security & UX A substantial round of security hardening, plus improvements to the archive, organization switching, templates, navigation and general performance. The direction is pretty simple: less duplicate compliance work, better overview, and more GRC in one platform. More coming in September.

  • Big updates hitting production in Cyrigo in August! The summer has been busy, working on one of our larger product updates so far. A few highlights: 🔹 Frameworks is out of beta Our Governance & Compliance functionality is now generally available, with control ownership, maturity, evidence status, review cycles, attestations, comments, activity history and improved framework management. Framework updates can also be distributed to customers while preserving existing evidence and customer-specific work. Support for compliance frameworks, such as ISO27001, NIS2, AI-act, GDPR, and the Norwegian Digital Security Act are becoming available. 🔹 Excel & CSV bulk import A big one for organizations moving from spreadsheets to structured GRC. You can now bulk import and update IT systems, vendors, treatments, tasks, DPIAs and risk assessments. For risk assessments, existing flat risk registers can be brought into Cyrigo and transformed into our Bowtie-based risk assessment structure. 🔹 Major Policy Editor improvements Policies now support images, colours, document headers, classification fields and manual page breaks, together with a number of usability improvements. 🔹 Better sharing, reports and dashboards We've improved record-level sharing and permissions, introduced automatically seeded report templates, and made several improvements to dashboards and widgets. 🔹 Security and stability The release also includes security hardening, dependency updates and a long list of fixes across access control, notifications, tasks, tables, framework imports and general application stability. 🔹 And finally: Diri → Cyrigo The soft rebrand has started making its way into the application. More to come on that front. A lot shipped in the first half of August — and there's plenty more in the pipeline.

  • What if your old Excel risk assessments could become interactive Bowties? Most organizations already have years of risk assessments. The problem is that they are scattered across Excel sheets, Word documents and PDFs — static documents that are difficult to maintain, aggregate and actually work with. With Cyrigo, you don't have to start over. We can take existing, risk assessments in various formats and import them into Cyrigo's Bowtie-based risk engine — transforming fragmented risk management into living risk assessments and structured risk registers. From there you can work with causes, threats, vulnerabilities, consequences and treatments, assign responsibilities, track progress and see how treatments actually affect risk. Your existing risk assessments aren't legacy data. They're your starting point. Have a pile of old risk assessments you'd like to bring to life? Talk to us.

    • Ingen alternativ tekstbeskrivelse for dette bildet

Tilsvarende sider