Skip to content

Resilience Platform

Agentic Cyber Security Workspace
for Compliance Teams.

KaitoSec brings risk, compliance, resilience, BCMS and data protection into one Resilience Platform for compliance teams. Agentic cyber security workflows connect ISO 27001, BSI IT-Grundschutz and NIS2 to the risks, actions and audit-ready evidence your team steers by.

One control, end to endCapture

Evidence captured once

Control · A.5.19

Supplier & third-party due diligence

Owner
Head of Procurement
Artefact
Stripe review · signed
Next review
12 Oct 2026

Mapped where the substance matches

ISO 27001
A.5.19
NIS2
Art. 21(2)(d)
DORA
Art. 28
ISO 42001
A.6.2

Requirements answered from the same record

ISO 27001 · A.5.19
Satisfied
NIS2 · Art. 21(2)(d)
Satisfied
DORA · Art. 28
Satisfied
ISO 42001 · A.6.2
Satisfied

Audit pack assembling

ISO 27001 · Stage 2 evidence0 pages
0:00 / 0:18

The actual bottleneck

Your team is not the problem. Three spreadsheets and a shared drive are.

The obligations grew, the tooling did not. Three questions we hear every week.

Information security officer

„Our information domain lives in three Excel files. Which requirement is actually still open?“

Head of IT

„NIS2 expects the early warning within 24 hours. Where do I get the facts when it counts?“

Reporting deadlines run in hours, not weeks.
Directive (EU) 2022/2555 (NIS2), Art. 23

Managing director

„I have to approve the measures and oversee the implementation, and I can be held liable for it. How do I see where we actually stand?“

Management approves, oversees and is liable.
Directive (EU) 2022/2555 (NIS2), Art. 20

The tool-category comparison

Import & check

Bring everything you have. The agent finds the gaps.

KaitoSec reads your current state: Excel, CSV, exports from verinice, HiScout or eramba, plus documents from SharePoint, Confluence and Jira. The agent maps it, checks it against the method and turns every gap into a task with an owner and a date.

Sources on the left, KaitoSec in the middle, structured artefacts on the right: Strukturanalyse, protection needs, register, evidence.

What holds the state today

  • Excel · CSV
  • verinice
  • HiScout
  • eramba
  • SharePoint
  • Confluence
  • Jira
  • Microsoft Entra ID
  • Own source · API

KaitoSec

Reads everything in

What it becomes

  • Strukturanalyse
  • Schutzbedarf
  • Register
  • Nachweise
From current state to working stateImport

Four chapters: a Grundschutz register is imported from Excel. The agent checks the information domain along the Grundschutz phases. Findings appear: protection needs not assessed, Bausteine not modelled, evidence missing. The register is adopted, 38 Bausteine are assigned, and findings become tasks with owners and dates.

0:00 / 0:20

Measured, not estimated

38 to 49 person-days become 14 to 23.

38–4914–23

Person-days, summed over six steps

And the BCMS runs on a head start: the same data carries emergency management.

Every person-day saved is budget. Run your own numbers

  1. Create and group assets

    5–8 PD · manual
    2–3 PD · KaitoSec
  2. Determine protection needs

    4–5 PD · manual
    1–2 PD · KaitoSec
  3. Collect requirements

    4–5 PD · manual
    1–2 PD · KaitoSec
  4. Modelling (Grundschutz)

    5–6 PD · manual
    1–2 PD · KaitoSec
  5. IT-Grundschutz check

    10–15 PD · manual
    3–7 PD · KaitoSec
  6. Risk analysis

    10 PD · manual
    6–7 PD · KaitoSec

Measured in our tests. Varies by step and data situation.

Capabilities

One system for the work that lives in spreadsheets today.

Two capabilities, each with a view into the product. Underneath, one data model: what is captured once counts everywhere.

01 One register

Applications, processes, vendors, AI. Captured once.

Every row is classified as it is recorded and has a named owner. The same register feeds the risk register, the RoPA and the BIA.

Classification split

Restricted 34%Internal 28%Public 24%AI 14%

Asset management

Inventory · 1,284 records

Classified on discovery
Sample of the asset inventory with owner, classification and the management systems each record serves
AssetOwnerClassificationSystems served
Payments APIInternal servicePlatform EngineeringRestrictedISMS · BCMS · DSMS
Customer portalPublic web applicationProductPublicISMS · DSMS
Primary databasePostgreSQL clusterPlatform EngineeringRestrictedISMS · BCMS · DSMS
StripeVendor · payment processorFinanceDPA signedDSMS · ISMS
Support copilotAI component · embeddingsCustomer OperationsAI · high riskAIMS · DSMS

Every row feeds the risk register, the RoPA and the BIA without being re-entered.

02 Overlap

One control, several obligations.

The mapping comes from OSCAL catalogues, not from manual matching. What stands for ISO 27001 counts for NIS2 and DORA too.

Full mapping
78%

Coverage from existing controls

of ISO 27001 requirements met by controls you already run for the other systems.

ISO 27001 · NIS2 · DORA · ISO 42001

The four areas this covers

  • BCMS

    Business continuity

    ISO 22301 · DORA

  • ISMS

    Information security

    ISO 27001 · BSI · NIS2

  • DSMS

    Data protection

    GDPR / DSGVO

  • AIMS

    AI governance

    ISO 42001 · EU AI Act

Shared records: written once, read by all four · 1 record → 4 obligations

Early access feedback

“We replaced three spreadsheets and a shared drive with one system. ISO 27001 and NIS2 finally live in the same place, and the readiness view shows exactly what is still open.”
Information security lead · Early access
Systems replaced
3 spreadsheets
Time to first register
Under a week
Frameworks live
ISO 27001 · NIS2

More from the early access

“Genuinely intuitive. We started without a training session and the team found its way around immediately.”
Head of IT · Early access
“Every requirement is explained in subject terms, right at the field. For the first time the whole team understands why a control is needed.”
Information security officer · Early access
“Simple mode takes the fear out of it for the departments. For the audit I switch to expert mode, same data.”
Managing director · Early access

Free check

Does NIS2 apply to you? Check it in five minutes.

The applicability check walks through sector, size and special cases and gives you the classification with next steps. Free.

Get started

Start with a real workflow.

Bring one current process. Leave with a clearer path. We will review how your existing registers, frameworks and owners could fit KaitoSec, using one live workflow instead of a generic feature tour.

Onboarding
4 weeks, fixed scope
Migration
verinice · HiScout · eramba
Demo length
30 minutes, no slides