Skip to content
Cyber Horizon
The unified GRC + Security platform

Automate GRC.
Quantify risk.
Stay compliant.

One platform to automate compliance, quantify cyber risk in financial terms, and run security operations — across 71 frameworks, built for CISOs and the teams behind them.

71 frameworks First framework live in two weeks Data stored in the EU
horizon // preview
82posture
+6 this quarter
Open risks
9
Controls
142
Frameworks
71
Threat feedsample
  • Critical CVE · remote code executionCritical
  • IOC match · C2 beacon activityHigh
  • Lookalike domain · brand impersonationMedium

Illustrative product preview.

ISO 27001ISO 22301ISO 27017SOC 2ISO 42001ISO 27005ISO 20000ISO 27032ISO 27035ISO 27701ISO 27018GDPRCCPA/CPRANIST PrivacyLGPDPIPEDAPOPIAPIPLAPPIAU Privacy ActCH FADPTH PDPAUK GDPRUK CAFOWASP ASVSOWASP SAMMNIST 800-63ISO 27031ISO 27034ISO 27036AU ISMDORANYDFS 500SWIFT CSPSOX ITGCGLBAFFIECPCI 3DSCMMCFedRAMPNIST 800-53SOC 1NIST 800-171NIST AI RMFEssential EightMAS TRMSG PDPAIndia DPDPAPRA CPS 234Korea ISMS-PCSA STARCSA CCM 4BSI C5ISMAPFISMAStateRAMPHITRUSTHIPAANHS DSPTHITECHCIS ControlsNIST CSFNIS2COBITISO 31000ISO 9001ITIL 4Cyber EssentialsEU AI ActTISAXPCI DSSISO 27001ISO 22301ISO 27017SOC 2ISO 42001ISO 27005ISO 20000ISO 27032ISO 27035ISO 27701ISO 27018GDPRCCPA/CPRANIST PrivacyLGPDPIPEDAPOPIAPIPLAPPIAU Privacy ActCH FADPTH PDPAUK GDPRUK CAFOWASP ASVSOWASP SAMMNIST 800-63ISO 27031ISO 27034ISO 27036AU ISMDORANYDFS 500SWIFT CSPSOX ITGCGLBAFFIECPCI 3DSCMMCFedRAMPNIST 800-53SOC 1NIST 800-171NIST AI RMFEssential EightMAS TRMSG PDPAIndia DPDPAPRA CPS 234Korea ISMS-PCSA STARCSA CCM 4BSI C5ISMAPFISMAStateRAMPHITRUSTHIPAANHS DSPTHITECHCIS ControlsNIST CSFNIS2COBITISO 31000ISO 9001ITIL 4Cyber EssentialsEU AI ActTISAXPCI DSS
71
Frameworks supported
23
Tool integrations
99.5%
Uptime SLA
24/7
Automated monitoring

// Inside the platform

See it work — not just hear about it.

Click through the surfaces your team lives in every day. One platform, one evidence trail, every workflow connected.

// How it works

From connected to audit-ready.

A single workflow takes you from raw infrastructure to board-ready reporting — no spreadsheets in sight.

1

Connect

Link your cloud, identity, and ticketing stack in minutes — no agents, no rip-and-replace.

2

Automate

Evidence is collected continuously and mapped across all 71 frameworks at once.

3

Quantify

Cyber risk is translated into financial impact your board actually understands.

4

Report

Generate audit packs and live executive dashboards with a single click.

// One platform, eight modules

Everything your GRC team needs, unified.

From threat intel to audit-ready compliance — every module works from one shared evidence trail.

Threat Intelligence

Live CVE and IOC feeds mapped to your actual stack, CISA KEV tracking, and MITRE ATT&CK context on 25 tracked threat actors — so you patch what attackers are exploiting, not just what scanners list.

Incident Response

Case management with kanban boards, AI enrichment, playbook automation, containment actions, root-cause analysis and lessons-learned — integrated with your GRC evidence trail.

Compliance Centre

Multi-framework compliance across ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, Cyber Essentials & more. Track controls, map evidence, and generate audit packs instantly.

Questionnaire AI

Auto-respond to security questionnaires using your existing controls and policies. Save hours on customer due diligence with AI-powered answer suggestions.

Vendor Risk Management

End-to-end vendor assessments, automated questionnaires, contract tracking, risk scoring, supply-chain breach intelligence, and domain impersonation alerts per vendor.

AI Risk Advisor

AI-powered gap analysis, control effectiveness scoring, and compliance reporting. CISO Copilot for instant GRC advice, and financial risk quantification.

Tabletop Exercises

Run realistic cyber incident simulations with AI-generated scenarios, track participant responses, measure team readiness, and generate post-exercise reports.

Compliance Automation

Automate evidence collection, continuous control monitoring, policy attestation, and audit workflows — dramatically reducing manual effort across every framework.

// Built differently

Faster, clearer, smarter than legacy tools.

AI-First Architecture

  • Automated evidence collection cuts audit-prep effort
  • Continuous control monitoring reduces compliance risk
  • Threat intelligence mapped to MITRE ATT&CK surfaces risk early

Enterprise Grade, Startup Speed

  • Weeks to value, not months
  • Cloud-native, zero legacy baggage
  • 99.5% SLA with zero-downtime deployment

Business Language, Not Jargon

  • Executive reports translate risk to financial impact
  • Board-ready metrics without extra work
  • Risk quantification ties security to outcomes

Compliance as Code

  • Multi-framework automation (ISO, SOC 2, NIST, PCI)
  • Version control for policies and controls
  • Audit-ready documentation, always current

Built to integrate with your stack

AWSAzureGoogle CloudOktaEntra IDCrowdStrikeSentinelOneDefenderSnykTenableQualysGitHubGitLabJiraSlackCloudflareIntuneJamfKnowBe4Google WorkspaceM365 Secure ScoreBambooHRHiBob

23 integrations across cloud, identity, endpoint, vulnerability, code and HR — each running automated checks against your live environment.

// Trust & security

Trust what you can verify.

We hold ourselves to the standards we help you achieve — and publish our posture so you can check it, not take our word for it.

GDPRActive

UK ICO registered (no. ZC237332), with a public DPA and subprocessor list.

ISO 27001Aligned

Controls aligned, certification targeted Q3 2027 — run on the same Compliance Centre we sell.

Vulnerability disclosurePublished

A public policy with safe harbour for good-faith security researchers.

AES-256 + TLS 1.3Enforced

Data encrypted at rest and in transit; MFA available to every user on every plan, and enforced on our own platform-administrator accounts.

EU data storageAll plans

Your data is stored in the EU (AWS eu-west-1, Ireland) on every plan. Some processing — hosting, identity, AI features, email and backups — happens in the US under the transfer safeguards in our DPA. Tenant isolation throughout.

99.5% uptime SLAContractual

A published SLA with service credits — not a marketing number.

We name every sub-processor and the region it processes your data in, rather than summarising it as one badge — see the full sub-processor list.

Free self-assessment

See exactly where your SOC 2 / ISO 27001 gaps are.

Answer 20 quick questions and get an instant, scored read-out across ten control areas — the strengths to lean on and the gaps worth fixing first, each mapped to the SOC 2 and ISO 27001 controls an assessor would check. A directional starting point, not a formal audit. Free, ~3 minutes, no signup to see your score.

  • Instant readiness score across every key control area
  • A prioritised gap list your team can act on this week
  • Benchmark your posture before you ever talk to an auditor
~3 minutes No signup to see your score Directional, not a formal audit
readiness check // coverage
20
questions
~3
minutes
2
frameworks
SOC 25 Trust Services Criteria
SecurityAvailabilityProcessing IntegrityConfidentialityPrivacy
ISO 27001:20224 control themes · 93 controls
OrganizationalPeoplePhysicalTechnological

The check is built around SOC 2 and ISO 27001:2022. Free — no signup to see your score.

// Get started

Built for security practitioners.

Everything you need to run governance, risk, and compliance — included from day one, with hands-on onboarding to get your team live fast.

Straightforward Pricing

Core platform included from day one — clear tiers, no per-module upsells, no surprise add-ons.

Built With Practitioners

Shaped by working security teams, with a roadmap driven by real-world needs.

Dedicated Onboarding

We set up your first framework, import your controls, and train your team.

Questions we get asked

Including the ones with awkward answers. If something here is not clear, ask us directly.

What is Cyber Horizon Intelligence?

Cyber Horizon Intelligence is a UK governance, risk and compliance (GRC) platform for security and compliance teams. It automates evidence collection across 71 compliance frameworks, quantifies cyber risk in financial terms, and runs vendor risk, incident response and threat intelligence from one shared evidence trail. It is built and operated by Cyber Horizon Intelligence Ltd, registered in England and Wales, company number 17327222, and registered with the UK Information Commissioner's Office under number ZC237332.

Who is Cyber Horizon built for?

Companies of roughly 30 to 250 people that have a compliance obligation but no dedicated compliance department — typically B2B SaaS, fintech, healthtech and managed service providers in the UK and EU. The common trigger is a customer asking for ISO 27001 or SOC 2, or a regulation such as DORA or NIS2 coming into scope, before anyone has been hired to own it.

Which compliance frameworks does Cyber Horizon support?

71 frameworks, including ISO 27001, SOC 2, GDPR, UK GDPR, NIS2, DORA, Cyber Essentials, NIST CSF, HIPAA, PCI DSS, CMMC and the EU AI Act. They are not all at the same depth and we would rather say so: 10 are verified control-by-control against the published standard, and the remaining 61 are curated crosswalk catalogues — control sets mapped from those verified libraries, useful for gap analysis and evidence reuse but not independently reconciled clause by clause. Every framework is labelled with its status inside the product.

How much does Cyber Horizon cost?

Prices are published rather than quoted. Start is £600 a month or £6,000 a year for 5 users; Grow is £1,500 a month or £15,000 a year for 15 users; Scale is £3,000 a month or £30,000 a year for 50 users. Enterprise is custom-priced with the seat count agreed in the Order Form. Paying annually is twelve months for the price of ten, a saving of 17%.

Does Cyber Horizon charge extra for additional frameworks?

No. Every module, every framework and every integration is included on every plan, with no per-framework, per-integration or per-module fee. Adding a framework in month six does not change the invoice. Plans differ by the number of included seats, by service level, and by single sign-on: MFA on every plan; SSO/SAML on Scale and Enterprise. This matters because the usual industry model charges per framework, so a team that buys ISO 27001 and is later asked for SOC 2 and then DORA pays three times.

Is Cyber Horizon Intelligence ISO 27001 certified?

No, and it is worth being exact about this. Cyber Horizon's own controls are aligned to ISO 27001 and certification is targeted for Q3 2027, but the company does not hold the certificate today. It is not SOC 2 certified and not Cyber Essentials certified either. The platform helps customers achieve those standards; it does not currently hold them. The full position, including what has and has not been independently tested, is published in the Trust Centre.

Where is customer data stored?

Customer Data is stored in the European Union by default, on Supabase in eu-west-1 (Ireland), on every plan. Some processing takes place outside the EU — application hosting and serverless compute, identity management, AI features, transactional email, malware scanning of uploaded files, and encrypted off-site backups. Every sub-processor, the service it provides, the region it processes in and the transfer mechanism relied on are listed publicly. Per-organisation regional residency in the United States, the United Kingdom and APAC is available on request, with no tier condition attached.

What does Cyber Horizon integrate with?

23 integrations, covering the systems that already hold the evidence: Amazon Web Services, Microsoft Azure and Google Cloud; Okta, Microsoft Entra ID and Google Workspace for identity; CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Jamf Pro and Microsoft Intune for endpoints; Tenable.io, Qualys VM and Snyk for vulnerabilities; GitHub, GitLab and Jira for code and tickets; BambooHR, HiBob and KnowBe4 for people; Cloudflare and Slack. Integrations are included on every plan rather than sold as an add-on.

What support and uptime commitments come with it?

The published Service Level Agreement targets 99.5% monthly uptime with service credits. Critical (S1) response targets are 8 business hours on Start, 4 on Grow and 2 on Scale, with custom targets on Enterprise. These are measured against UK business hours (09:00–17:00 UK time, Monday to Friday); there is no staffed round-the-clock desk, and the SLA says so — outside business hours, S1 incidents are monitored on a best-efforts basis via an alerting channel.

How do I find out where my compliance programme currently stands?

There is a free readiness check on the site: 20 questions, about three minutes, no signup wall and no call required. It scores your current position against SOC 2 and ISO 27001, shows which controls you would presently fail, and maps each gap to the clause it belongs to.

More detail in the pricing FAQ, the Trust Centre and our published legal documents.

Ready to transform your
GRC programme?

Replace manual spreadsheets with automated compliance, quantified risk, and live security intelligence.

Plans from £600/month, or £6,000/year — every framework, module and integration included on every plan.