Skip to content

Know what to do next.
Show that it works.

Customers, insurers and regulators expect solid answers about your security. What is usually missing is the overview, the time and the specialist knowledge to give them. KaitoSec shows what matters for your business, what to do next, and how to evidence progress, without building a compliance department for it.

One control, end to endCapture

Evidence captured once

Control · A.5.19

Supplier & third-party due diligence

Owner
Head of Procurement
Artefact
Stripe review · signed
Next review
12 Oct 2026

Mapped where the substance matches

ISO 27001
A.5.19
NIS2
Art. 21(2)(d)
DORA
Art. 28
ISO 42001
A.6.2

Requirements answered from the same record

ISO 27001 · A.5.19
Satisfied
NIS2 · Art. 21(2)(d)
Satisfied
DORA · Art. 28
Satisfied
ISO 42001 · A.6.2
Satisfied

Audit pack assembling

ISO 27001 · Stage 2 evidence0 pages
0:00 / 0:18

Standards your auditors and customers ask about

ISO 27001Information security
ISO 22301Business continuity
BSI IT-GrundschutzGerman baseline
NIS2EU directive
DORAFinancial resilience
GDPR / DSGVOData protection
ISO 42001AI management

Before and after

It is rarely the will that is missing. It is the overview, the time and the expertise.

What consumes time today
What changes with KaitoSec
Every application, vendor and requirement gets equal weight, because nobody can say which of them actually carries the business.
You can see which areas are critical, what they depend on and where an outage costs most. Time and budget go there first.
Requirements arrive as catalogue text. Where to start, what is urgent and who has to act is written down nowhere.
Each requirement becomes a concrete task with an owner and a date, in the order that matters for your business.
A customer questionnaire or an audit sets off days of searching through documents, mail threads and responsibilities.
Evidence accumulates while the work happens. When the request arrives, progress, decisions and results are already on record.
ISO 27001, NIS2, data protection, business continuity and AI governance are worked through one after another, each on its own.
The overlaps are recognised. What has already been delivered counts toward the next obligation.
The expertise sits with the consultant. Once the project ends, the next invoice begins.
The tool explains, proposes and records the reasoning. The knowledge grows inside the team.

What carries your business

Know what actually puts your business at risk.

01 Criticality

Start where an outage actually hurts

The impact analysis sets how long each process may be down before it gets expensive. The recovery is rehearsed and the exercise record proves it, so the time back to normal is measured rather than estimated.

Business continuity

Operating capability

Exercise passed

DisruptionRestored · 2h 40mRTO budget 4h

Critical processes

Payments
Met · 2h 40m
RTO 4h
Order handling
Met · 5h 10m
RTO 8h
Customer support
Met · 9h
RTO 24h

02 Dependencies

Know what the critical areas run on

One register for applications, processes, vendors and AI components, classified as it is recorded and owned by a named person. Each row shows which parts of the business hang off it.

Classification split

Restricted 34%Internal 28%Public 24%AI 14%

Asset management

Inventory · 1,284 records

Classified on discovery
Sample of the asset inventory with owner, classification and the management systems each record serves
AssetOwnerClassificationSystems served
Payments APIInternal servicePlatform EngineeringRestrictedISMS · BCMS · DSMS
Customer portalPublic web applicationProductPublicISMS · DSMS
Primary databasePostgreSQL clusterPlatform EngineeringRestrictedISMS · BCMS · DSMS
StripeVendor · payment processorFinanceDPA signedDSMS · ISMS
Support copilotAI component · embeddingsCustomer OperationsAI · high riskAIMS · DSMS

Every row feeds the risk register, the RoPA and the BIA without being re-entered.

03 Risk

Where an outage would cost the most

One scoring model for every obligation, so what to treat first stays comparable instead of being judged separately per standard.

Risk management

Risk matrix · 52 tracked

Impact

12343356412453123321221

Likelihood

Hover a cell to read the band

Treatment pipeline

Identified12
Assessed9
Treating4
Treated27

The next step

Know what to do next, at any time.

Where do we start? What is urgent? Who has to act? And what is actually enough? KaitoSec turns requirements into concrete tasks and walks the team through delivering them.

Open tasks · ordered by impact

Requirements, the tasks derived from them, their owners and dates
RequirementWhat that means you doOwnerBy when
Supplier securityISO 27001 · A.5.19Request review reports for the six critical service providers and file them against the contract.Head of ProcurementThis week
Incident reporting pathNIS2 · Art. 21Name the reporting chain and settle who is reachable outside office hours.Head of ITThis month
Record of processingGDPR · Art. 30Add the five new processing activities introduced by the customer portal.Data Protection OfficerThis month
Recovery rehearsalISO 22301Exercise the payments recovery plan against its four-hour target.Platform EngineeringThis quarter
Human oversightEU AI Act · Art. 14Decide who reviews the support copilot's output, and how often.Customer OperationsThis quarter

The order follows the criticality established above, not the numbering in the catalogue.

Answering

Answer customers and auditors faster.

Questionnaires, customer reviews and audits ask for the same facts in different shapes. None of them should set off a search through documents, mail threads and responsibilities.

Evidence current
97%18 items ageing
Controls mapped
312Across 12 frameworks
Open findings
4All assigned
Last reviewed
12 OctApproved

What comes out

The answer, with its evidence attached, straight from the register. No round of emails asking who holds what.

Overlap

Meet several obligations with the same work.

Choose the standard your customer, auditor or insurer is asking about. The controls behind it mostly exist already, because they satisfy an obligation you have met before.

ISO 27001 requirements and the controls that satisfy them
RequirementSatisfied byAlso serves
A.5.7Threat intelligenceMITRE ATT&CK, CAPEC, OWASP and BSI catalogues indexed and mapped to assetsNIS2 · DORA
A.5.19Supplier & third-party due diligenceVendor register with DPAs, criticality rating and evidence of reviewNIS2 · DORA · 42001
A.5.30ICT readiness for continuityRTO targets from the BIA, rehearsed recovery plans, exercise recordsISO 22301 · DORA
A.8.16Monitoring activitiesAlerting anchored to the asset inventory, findings routed to named ownersNIS2 · SOC 2

Coverage from existing controls

78%

of ISO 27001 requirements met by controls you already run for the other systems.

Full mapping

The four areas this covers

BCMS

Business continuity

BIA, recovery plans, exercises and RTO tracking against a rehearsed plan.

ISO 22301 · DORA

ISMS

Information security

Controls, risks, threat catalogues and monitoring on one register.

ISO 27001 · BSI · NIS2

DSMS

Data protection

RoPA, DPIA, subject requests and processor agreements, kept current.

GDPR / DSGVO

AIMS

AI governance

AI inventory, model risk, logging and human oversight.

ISO 42001 · EU AI Act

Shared records: written once, read by all four

1 record → 4 obligations
Assets
1,284 in inventory
Processes
One map, four purposes
Risks
Same scoring model
Controls
Mapped, not duplicated
Vendors
DPAs and criticality
Evidence
Signed, timestamped

Why KaitoSec

Capability that stays inside the company.

01

The knowledge stays with you

Consultants can speed up the start. After that the knowledge belongs in the building. KaitoSec explains each requirement in plain terms, proposes the next step and records why you decided as you did. Your team learns while it delivers.

Decisions stay traceable

02

No compliance department required

This work usually sits with people who also have another job. So the tool leads through the delivery instead of presenting empty fields, and says for each requirement what is actually enough.

No full-time function needed

03

Built and hosted in Germany

Runs on ISO 27001-certified infrastructure in Germany, under EU law. GDPR requirements are built into the data model rather than a policy PDF, and support works in German or English.

Data stays in the EU

The result

Understand security. Act on it. Evidence it at any time.

  1. 01

    You spot your most important risks earlier.

  2. 02

    You know what to do at any point.

  3. 03

    You answer customer and auditor questions faster.

  4. 04

    You meet several obligations with the same work.

  5. 05

    You do not need a compliance department of your own.

Early access feedback

“We replaced three spreadsheets and a shared drive with one system. ISO 27001 and NIS2 finally live in the same place, and the readiness view shows exactly what is still open.”
Information security lead · Early access
Systems replaced
3 spreadsheets
Time to first register
Under a week
Frameworks live
ISO 27001 · NIS2

Get started

Start with a real workflow.

Bring one current process. Leave with a clearer path. We will review how your existing registers, frameworks and owners could fit KaitoSec, using one live workflow instead of a generic feature tour.

Onboarding
4 weeks, fixed scope
Migration
verinice · HiScout · Eramba
Demo length
30 minutes, no slides