A new Annual Wheel gives you a 12-month overview of recurring governance and compliance activities across the organization.
It brings together recurring and one-time tasks, system reviews, DPIA reviews, policy revisions and treatment deadlines in one view.
- Filter activities by module or framework.
- See upcoming, overdue and ongoing activities.
- Drill down into each month and open the underlying activity directly.
- Navigate between years to review past or upcoming obligations.
- Export the annual wheel to PDF or data format.
The Annual Wheel provides a practical overview of what needs to happen, when, and where attention is required.
- New dependency analysis with an interactive system map, criticality matrix and what-if simulation to identify downstream impact if a system becomes unavailable or compromised.
- Supplier criticality and concentration analysis shows which suppliers operations depend on most, combining system dependencies, business impact and supplier assessments.
- Dependency mappings can now also be imported from Excel, with several improvements to mapping and data-quality handling
- Improved data-flow analysis for privacy work. Data flows can now be analysed from processing activities, with interactive diagrams showing how personal data moves between systems.
The Risk Registry has been substantially rebuilt to provide a consolidated view of risks across the organization.
- See inherent and residual risk side-by-side.
- View cause → consequence relationships and connected Bowties.
- See risk ownership and acceptance status directly in the register.
- Accept or escalate risks without opening the underlying assessment.
- Search, filter and export the register to CSV.
- Acceptance criteria are visualized directly in the risk matrix.
Cyrigo now provides a dedicated register of accepted risks, creating a traceable record of management risk decisions.
Risk acceptance is recorded from risk assessments and security assessments, including:
- Who accepted the risk and who owns it.
- Risk level at the time of acceptance.
- Acceptance criteria and justification.
- Expiry and review information.
- Superseded and withdrawn decisions.
Acceptance thresholds can also be configured — or disabled — per organization.
The risk treatment and approval workflow has received a major upgrade.
- Improved treatment plan showing responsibilities, deadlines and expected risk reduction.
- Cost-benefit information available when reviewing treatments.
- Assessments can be formally sent for signing.
- Signing establishes risk ownership and the review period.
- Expired reviews are automatically identified and owners notified.
- Signing adapts to Risk Assessments, DPIAs and Incidents.
Activated frameworks can now generate a printable Audit Evidence Report, providing a consolidated view of:
- Control coverage and Statement of Applicability.
- Excluded controls and justifications.
- Accepted compliance gaps.
- Supporting policies.
- Risk assessments and treatment plan status.
Frameworks can also have their ISMS scope documented directly in Cyrigo.
Our framework library continues to expand. GDPR is now available, alongside updates to ISO 27001 and NIS2 and further additions to our framework catalogue.
- Incidents and business processes can now be imported from Excel, in addition to the registers already supported.
- Import templates can include reference data such as valid system names, reducing errors when preparing larger imports.
Bowtie assessments now provide better support when determining probability and consequence.
- Improved recommendations based on connected threats, vulnerabilities and assets.
- Recommendations now explain how the suggested value was derived.
- Apply recommendations directly to the assessment.
- Improved asset, threat and vulnerability selection.
- Improved Bowtie infographic export.
Evidence can be reused between controls that address the same underlying requirement across different frameworks.
This reduces duplicate compliance work when implementing multiple standards and regulations, while keeping evidence status synchronized across frameworks.
- Stronger cross-framework mapping and traceability. Framework mappings can now document their source, rationale and approval history, making it easier to understand why one control is considered to satisfy another.
- Published crosswalks can be imported and used as the basis for mappings, with new review and approval workflows around mapping quality.
The control mapping view now provides a more accurate picture of how requirements overlap across frameworks.
Mappings can show both fully and partially satisfied controls, making it easier to identify where existing controls and evidence can be reused — and where additional work is still required.
New filters and layout improvements also make larger cross-framework mappings easier to explore.
- Clearer policy ownership and visibility.
- Notifications when assessment reviews expire.
- Notifications for comments and framework ownership.
- Organization-level notification defaults.
- Improved notification administration.
- Improved organization switching across assessments, policies and reports.
- More helpful empty-state guidance.
- Redesigned template browser.
- Improved navigation and table behaviour.
- Significant security hardening across authentication, access control and organization isolation.
- Fixed permission handling when switching organizations.
- Improved settings reliability and concurrent editing.
- Fixed several Bowtie scoping and recommendation issues.
- Improved risk acceptance and signing reliability.
- Numerous stability, performance and usability improvements throughout the platform.
- Several fixes to roles and permissions, organization settings and inheritance between parent and sub-organizations.
- Improved reliability when working with organization trees, system/vendor forms and module settings.
- Iterations have been renamed to Task Boards, and task creation and assessment actions are now more consistent across the application.