The Frameworks module is now generally available, introducing a comprehensive workspace for managing compliance frameworks, controls, evidence, and ongoing compliance activities.
¶ Framework and Control Management
- New framework overview with an improved visual layout and detailed framework information.
- Controls can be tagged and connected from either side of the relationship.
- Controls now support owner, maturity level, evidence status, and aggregate status.
- New control review cycle with review cadence, attestation, and automated reminders.
- Inline comments can be added directly to controls.
- Framework-specific activity logs provide an overview of changes and activity.
- Improved control search and hierarchy navigation.
Framework templates can now be updated centrally and distributed to organizations while preserving customer work.
When a framework is updated:
- Changes are presented with wording differences and recommended actions.
- Existing evidence and customer-specific work are preserved.
- Removed controls with existing evidence are highlighted for review.
- The most recent import can be undone if required.
Moving existing GRC data into Cyrigo just became significantly easier.
A new bulk import engine allows organizations to import and update large amounts of existing data from Excel or CSV instead of registering records manually.
Bulk import is available for major parts of the platform:
- IT Systems
- Vendors
- Treatments
- Tasks
- Risk Assessments / Bowtie - in the work surface full cause, event, consequence, and treatment import.
- Asset, threats, vulnerabilities
- Policy records
The importer supports both creating new records and updating existing data, making it useful for initial migration as well as ongoing bulk maintenance.
To make migrations easier, the import workflow includes:
- Downloadable Excel templates.
- Automatic mapping and validation of imported data.
- Clear identification of errors before data is committed.
- Support for references such as users and vendors.
- Support for both Excel and CSV files, including common European CSV formats.
- Create, update, and upsert workflows depending on the type of import.
This makes it considerably faster to move from existing spreadsheets and registers into structured GRC workflows in Cyrigo.
The policy editor has received several new document-authoring capabilities.
- Add images and text colours to policies.
- Add a document header containing policy metadata and classification.
- Insert manual page breaks.
- Improved policy visibility options.
- A new sharing experience makes it easier to manage access to individual records.
- Improved overview of users with access.
- Permissions can be changed directly from the sharing panel.
- Access can be revoked directly.
- Current permission levels are clearly displayed.
Starter report templates are now automatically made available when entering an empty report workspace for the first time.
- Numerous improvements have been made to framework management and distribution.
- Improved framework package distribution and version management.
- Improved handling of framework updates across organizations.
- Better tracking of control changes and evidence history.
- Improved support for sub-organizations.
- Framework controls are displayed in their intended framework order.
- Improved export and import of risk assessments, treatments, threats, taxonomy, maturity information, and recurring activities.
- The editor toolbar now remains visible when scrolling through long documents.
- Improved image handling and persistence.
- Improved document layout and sidebar presentation.
- Improved handling of report and widget templates.
- Starter widgets are now independent of the active dashboard.
- A confirmation is required before clearing a dashboard containing widgets.
- Improved recurring task handling.
- The first column of new taskboards is now named "Not started".
- Notifications are now sent when users assign tasks, treatments, or policies to themselves.
- Improved incident notification handling.
Several usability improvements have been made across tables and forms.
- Dropdowns, lookups, and multi-select fields can now be cleared reliably.
- Table actions no longer overlap other content.
- Improved handling of large and overflowing tables.
- Added a resize option to the table menu.
- Failed saves now display an error instead of failing silently.
- API errors are surfaced more consistently to users.
¶ Rebranding
The first stage of the Diri → Cyrigo rebranding has started.
- Initial Cyrigo branding introduced throughout the frontend.
- Updated getting-started experience.
- New loading screen.
- Updated workspace styling and visual consistency.
Fixed newly added framework controls not reaching organizations that had already activated a framework.
Fixed issues with recurring activities after framework export/import.
Fixed control tagging across organizations.
Fixed errors when marking controls as not applicable or adding justifications.
Fixed control references when controls are renamed.
Fixed duplicate threats during framework import/export.
Fixed risk assessment templates being incorrectly combined during import.
Fixed module information not being preserved correctly during import/export.
Fixed duplicate treatments during repeated imports.
Fixed framework page sorting and loading issues.
Several security hardening measures have been implemented.
- Strengthened authentication protections.
- Improved protection of authentication tokens in server logging.
- Strengthened access controls on application routes.
- Audit logs are correctly enforced as read-only for relevant roles.
- Updated frontend and backend dependencies to address known security vulnerabilities.
- Fixed images disappearing after saving and reopening a policy.
- Fixed image updates interfering with undo history.
- Fixed Kanban column sizing.
- Fixed recurring task behaviour.
- Fixed incident notifications.
- Improved incident registration and validation.
¶ Organization & Iteration Handling
- Fixed stale iteration information appearing when switching between organizations.
- Improved organization isolation and iteration handling.
- Improved authentication session preservation and error handling.
- Fixed several table layout and scoring display issues.
- Improved handling of empty or cleared reference fields.
- Improved application compatibility and dependency stability.
- Numerous additional performance, stability, and usability improvements.
Introduced several fixes on the 18.08.26
Frameworks
- Superadmin can now override the display name of a framework (PR #3043)
- Framework main page now shows the correct title
- Evidence linking fixes from testing
- Risk assessments module filtering fixed; back navigation now returns to the correct control
- Task control locales fixed
- SIKPERSMAA exported as a framework package (reverted and re-landed)
- Minor review fixes and adjustments (PR #3045)
- Barebones Diri AI Act module scaffolded
Policy Editor
- Zoom and resizing support added
Tasks
- Migration and fix for duplicate re-occurring tasks
Security hardening
- Sanitize untrusted HTML before rendering it (XSS prevention)
- Escape user input before building email lookup regexes (ReDoS prevention)
- Improved rate limiting added to credential authentication endpoints (brute force protection)
- Generic error message for unknown account and wrong password (prevents account enumeration)
Content Security Policy
- Established initial Content Security Policy (CSP) baseline
- Strengthened security headers and violation reporting
- Refined third-party service and external resource allowlists
- Improved environment-specific CSP configuration
- Added support for required PDF/WASM resources
- Expanded monitoring and telemetry endpoint support
- Improved CSP handling for third-party integration edge cases
- Updated trusted domain configuration in preparation for domain migration
Performance
- Database indexes added to collections that were doing full scans
- RBAC organization tree now fetched by level instead of by node
Bug fixes
- Bad tag ID on a task no longer causes update failures or breaks the task list
- Duplicate
previewHtml declaration removed in policies