CyberFit — the platform

The work a security team does, running whether you have one or not.

Most organisations under a thousand people end up with four or five security tools, nobody who owns them, and no honest answer when someone asks how exposed they are. CyberFit replaces that with one platform and a standing set of jobs that get done on a schedule.

WHAT YOU GETCYBERFIT
One contractSix functions, one renewal, one support line.
See results in minutesInstall the agent, enter your domain, hit scan — assets and exposure show up immediately, not after a week of onboarding.
Evidence by defaultEvery action logged in the form an auditor asks for.
THE SIX

What is included, in plain terms

01
Attack-surface monitoringRuns continuously

We map what of yours is reachable from the internet — domains, subdomains, cloud storage, forgotten staging boxes, exposed admin panels — and keep watching as it changes. Findings arrive ranked by how quickly an attacker could actually use them, not by generic severity score.

External asset discoveryCertificate and DNS driftShadow IT detection
Also sold standalone as Exposure
02
Endpoint protectionAlways on

Detection and response on Windows, macOS and Linux, deployed with a single universal installer per platform and managed from one console. When something trips, you get the device, the user, what ran, and what we did about it — in one screen, without needing to read raw telemetry.

Windows, macOS, LinuxUniversal installerDevice isolationPlain-language alerts
03
PatchingWeekly cycle, emergency out-of-band

Operating systems and third-party applications updated on a cycle you set, with staged rollout so a bad vendor patch does not take out the whole fleet at once. What is outstanding, and why, is visible at all times — including the machines someone keeps postponing.

Third-party app patchingStaged ringsException tracking
04
Ransomware-tested backupRehearsed monthly

Immutable backups are the easy part. The part most organisations skip is proving they restore. We run scheduled restore rehearsals against your real data and give you a measured recovery time — a number you can put in front of your board instead of a hope.

Immutable storageScheduled restore drillsMeasured RTO
05
AI governancePowered by Nudger

Your staff started using AI tools before anyone wrote a policy. CyberFit inventories which assistants and models are actually in use, applies the rules you set about what data can go where, and shows you where day-to-day practice has drifted away from the policy on paper.

AI tool inventoryData-boundary rulesDrift reporting
06
Compliance evidenceCollected as you operate

Controls are mapped to the frameworks your customers ask about, and the evidence is gathered while the work happens. When a security questionnaire or an audit lands, you export what already exists rather than spending three weeks reconstructing the last twelve months.

ISO 27001, SOC 2, Cyber EssentialsQuestionnaire exportControl owner tracking
RUNS ACROSS ALL SIX

A-Monk: the adviser layer, not a seventh function

A-Monk isn't a chatbot bolted onto the platform — it's the expert-assistance layer that operates across all six functions above. It can explain a finding, prioritise what to act on, help generate remediation and patch scripts, support your policy and compliance work, and act on the platform's automation subject to the permissions and approval guardrails you've configured.

Security analystExplains what a finding actually means and how it was triaged, in language that doesn't require a security background to follow.
Patch engineerHelps prioritise what to patch first and can generate remediation and patch scripts, subject to the approvals you've configured.
Compliance adviserMaps findings and evidence back to the frameworks you're tracking, and helps close the gaps it identifies.
AI governance adviserSurfaces where Nudger's policy and day-to-day AI use have drifted apart, and what to do about it.
Recovery adviserTalks you through the supported recovery workflow when something goes wrong, rather than leaving you to read a runbook alone.
FIRST FIVE DAYS

What onboarding actually looks like

DAY 1ConnectIdentity provider and cloud accounts linked, agent pushed through your existing device management.
DAY 2DiscoverAssets, endpoints and exposed services enumerated. Expect surprises here — everyone has some.
DAY 3–4Set the schedulePatch windows, backup targets, AI rules and control owners agreed with you, not assumed.
DAY 5First posture reportA written baseline: what is exposed, what is unprotected, what we are fixing first.
Runs alongside what you have

CyberFit connects to Microsoft 365, Google Workspace, Okta, AWS, Azure, Google Cloud, Jamf and Intune. If you already have a tool you are contractually stuck with, we read from it rather than insisting you rip it out.

Ask about your specific stack
Want people, not just software?

Some teams want the platform run for them, an incident retainer, or a one-off assessment before they commit. That is what our services line is for.

See services

Bring your worst assumption about your own estate

Thirty minutes, your environment, no slideware. We would rather show you the gaps than describe the product.

Book a demo