Resilience Platform
Agentic Cyber Security Workspace
for Compliance Teams.
KaitoSec brings risk, compliance, resilience, BCMS and data protection into one Resilience Platform for compliance teams. Agentic cyber security workflows connect ISO 27001, BSI IT-Grundschutz and NIS2 to the risks, actions and audit-ready evidence your team steers by.
Evidence captured once
Control · A.5.19
Supplier & third-party due diligence
- Owner
- Artefact
- Next review
Mapped where the substance matches
- ISO 27001
- A.5.19
- NIS2
- Art. 21(2)(d)
- DORA
- Art. 28
- ISO 42001
- A.6.2
Requirements answered from the same record
- Satisfied
- Satisfied
- Satisfied
- Satisfied
Audit pack assembling
The actual bottleneck
Your team is not the problem. Three spreadsheets and a shared drive are.
The obligations grew, the tooling did not. Three questions we hear every week.
Information security officer
„Our information domain lives in three Excel files. Which requirement is actually still open?“
Head of IT
„NIS2 expects the early warning within 24 hours. Where do I get the facts when it counts?“
Reporting deadlines run in hours, not weeks.
Managing director
„I have to approve the measures and oversee the implementation, and I can be held liable for it. How do I see where we actually stand?“
Management approves, oversees and is liable.
Import & check
Bring everything you have. The agent finds the gaps.
KaitoSec reads your current state: Excel, CSV, exports from verinice, HiScout or eramba, plus documents from SharePoint, Confluence and Jira. The agent maps it, checks it against the method and turns every gap into a task with an owner and a date.
What holds the state today
Excel · CSV
- verinice
- HiScout
- eramba
SharePoint
Confluence
Jira
Microsoft Entra ID
Own source · API
KaitoSec
Reads everything in
What it becomes
- Strukturanalyse
- Schutzbedarf
- Register
- Nachweise
Four chapters: a Grundschutz register is imported from Excel. The agent checks the information domain along the Grundschutz phases. Findings appear: protection needs not assessed, Bausteine not modelled, evidence missing. The register is adopted, 38 Bausteine are assigned, and findings become tasks with owners and dates.
Measured, not estimated
38 to 49 person-days become 14 to 23.
38–4914–23
Person-days, summed over six steps
And the BCMS runs on a head start: the same data carries emergency management.
Every person-day saved is budget. Run your own numbers
Create and group assets
5–8 PD · manual2–3 PD · KaitoSecDetermine protection needs
4–5 PD · manual1–2 PD · KaitoSecCollect requirements
4–5 PD · manual1–2 PD · KaitoSecModelling (Grundschutz)
5–6 PD · manual1–2 PD · KaitoSecIT-Grundschutz check
10–15 PD · manual3–7 PD · KaitoSecRisk analysis
10 PD · manual6–7 PD · KaitoSec
Measured in our tests. Varies by step and data situation.
Capabilities
One system for the work that lives in spreadsheets today.
Two capabilities, each with a view into the product. Underneath, one data model: what is captured once counts everywhere.
01 One register
Applications, processes, vendors, AI. Captured once.
Every row is classified as it is recorded and has a named owner. The same register feeds the risk register, the RoPA and the BIA.
Classification split
Restricted 34%Internal 28%Public 24%AI 14%
Inventory · 1,284 records
Classified on discovery| Asset | Owner | Classification | Systems served |
|---|---|---|---|
| Payments APIInternal service | Platform Engineering | Restricted | ISMS · BCMS · DSMS |
| Customer portalPublic web application | Product | Public | ISMS · DSMS |
| Primary databasePostgreSQL cluster | Platform Engineering | Restricted | ISMS · BCMS · DSMS |
| StripeVendor · payment processor | Finance | DPA signed | DSMS · ISMS |
| Support copilotAI component · embeddings | Customer Operations | AI · high risk | AIMS · DSMS |
Every row feeds the risk register, the RoPA and the BIA without being re-entered.
02 Overlap
One control, several obligations.
The mapping comes from OSCAL catalogues, not from manual matching. What stands for ISO 27001 counts for NIS2 and DORA too.
Full mappingCoverage from existing controls
of ISO 27001 requirements met by controls you already run for the other systems.
The four areas this covers
BCMS
Business continuity
ISO 22301 · DORA
ISMS
Information security
ISO 27001 · BSI · NIS2
DSMS
Data protection
GDPR / DSGVO
AIMS
AI governance
ISO 42001 · EU AI Act
Shared records: written once, read by all four · 1 record → 4 obligations
Early access feedback
“We replaced three spreadsheets and a shared drive with one system. ISO 27001 and NIS2 finally live in the same place, and the readiness view shows exactly what is still open.”
- Systems replaced
- Time to first register
- Frameworks live
More from the early access
“Genuinely intuitive. We started without a training session and the team found its way around immediately.”
“Every requirement is explained in subject terms, right at the field. For the first time the whole team understands why a control is needed.”
“Simple mode takes the fear out of it for the departments. For the audit I switch to expert mode, same data.”
Free check
Does NIS2 apply to you? Check it in five minutes.
The applicability check walks through sector, size and special cases and gives you the classification with next steps. Free.
Get started
Start with a real workflow.
Bring one current process. Leave with a clearer path. We will review how your existing registers, frameworks and owners could fit KaitoSec, using one live workflow instead of a generic feature tour.
- Onboarding
- Migration
- Demo length



