Home / How it works

How CyberContext reaches a recommendation.

It starts with what's at stake, reads every source you have against it, weighs how far each one can be believed, and only counts what it can trace back to the page.

Risk, from every angle

Risk is how you know what to do first.

A gap in a payroll vendor holding employee bank data is not the same as a gap in your print shop. Every recommendation starts from how much is at stake, and the list is ranked by what is left once the evidence is weighed.

No single document tells you how exposed you are. A contract says what was promised, an audit says what was tested, a survey says what the vendor claims, and a rating says what the outside world can see. CyberContext reads them together, against the risks you care about, and notices when they disagree.

What they signedContracts and agreementsTerms, obligations, notice periods, audit rights
What they show and sayVendor evidenceAudit reports, trust centers, policies, completed surveys
What others seeIndependent viewsSecurity ratings, news and events
What you knowYour own contextYour assessments, procurement data, how you use them
Risks · Vessimor Payroll
Data protectionHigh→High
Operational resilienceMedium→Low
Governance & risk allocationHigh→Medium
Sources disagreeSurvey says quarterly access reviews. The rating sees exposed admin services.
Inherent → residual
Do next
  1. Verify Require an independent audit before renewal
  2. Remediate Add a 72-hour breach notice term
  3. Strengthen Ask about the exposed admin services
  • Ranked by risk, not by count. Fifty open gaps become the three that matter most this week.
  • Fills in where one source is blind. A rating can't see governance; a contract can't see patching. Each source counts where it can see.
  • Flags where sources disagree. A conflict between what a vendor says and what others see is a finding in its own right.
  • Says when it isn't sure. Thin evidence lowers confidence instead of pretending. "Collect evidence" is sometimes the right advice.
How much to believe it

Separate the vendors with a problem from the ones you just can't prove yet.

Most risk registers treat a self-reported "yes" the same as an audited one. CyberContext weighs every piece of evidence by who produced it, and tells you which work each vendor needs.

  • Remediate when the evidence shows a real shortfall.
  • Verify when the claim is there and the proof is not.
  • Nothing to do is a valid answer. A blank row means settled.
Third-Party Risks and Coverage
VendorInherentAssuranceBest evidenceTrustNeeds
Vessimor PayrollHigh
92
Self-Attest
28
Verifystrong on paper, unproven
Wickerby DocsHigh
58
Audit (SOC 2)
88
Remediateurgent actions open
Ferrostead Data CentersMedium
88
Audit (SOC 2)
86
Glenvarra NetworksMedium
66
Self-Attest
35
Verifyrests on thin evidence
Quarrybrook CloudMedium
31
Self-Attest
42
Remediatecontrols below the bar
Example data · vendor names are fictional
Report · Wickerby DocsAudit (SOC 2) · FY2026
Incident response · requirement 4.2
Notify affected customers of a confirmed security incident within 72 hours.
MetSupported by passage · page 41
"Upon confirmation of a security incident affecting customer data, the Company notifies affected customers within seventy-two (72) hours via the designated security contact."
Access control · requirement 2.7
Privileged access is reviewed quarterly.
No creditNo supporting passage in the source, so this counts as a gap
Example data · document text is illustrative
Every answer shows its source

If it can't show you the sentence, it doesn't count.

Each requirement is checked against the document it rests on. Click any result and you're looking at the passage, the page and the report it came from. Results that can't be traced back get no credit, so a made-up answer shows up as a gap, not a pass.

  • Hand an auditor the trail, not a summary.
  • Challenge any number on the screen and see the arithmetic behind it.
Who covers each requirement · Ferrostead Data Centers
Your requirementWho covers itWhat we found
Encryption of data at restVendorTested in their audit report
User access reviews for your accountsYouHanded to you by their report. Not on your control list: request an access review with sign-off
Passwords for application sign-inYouHanded to you by their report. Covered, per your scoping profile
Monitoring of admin actions in your tenantNobodyGap: not in their report, not on your control list
Example data
Start from what's already published

Less chasing. More of the picture on day one.

Much of what you'd send a questionnaire for is already out there. CyberContext collects it and counts each piece for what it is worth.

Trust centersRead and collected for you
Audit reportsSOC 1 and SOC 2, read in full
Completed surveysCounted as the vendor's own word
Security ratingsUsed for what they can see

Audit reports often hand some controls back to you. CyberContext shows, for each of your requirements, whether the vendor covers it, you do, or no one does, and for the ones handed to you, what evidence to request. How you use the vendor's product decides which requirements apply in the first place.

Results you can measure

Five measures that show whether assurance is working.

These are the numbers that tell you a program is working, not just busy.

Time to action

From new evidence arriving or a vendor's risk changing, to the right person acting on it.

1Evidence arrivesA new SOC 2, an amended contract, a rating drop
2Risk read againThe result and the priorities update
3Owner toldIn Needs you, and by email to the people who follow the area
4Action openedAssigned, tracked and closed with a reason

Residual risk, with trust in the evidence

For every vendor in the portfolio: how much risk is left, and how far you can rely on what that rests on.

Good
Residual risk · 80
Trust 81Audited evidence

Priorities by risk, tracked to closure

By vendor and across the portfolio. Without a risk model, every gap looks equally important.

  1. 1Access reviews · Wickerby DocsIn progress
  2. 2Breach notice · Thalwick HealthOpen
  3. 3Recovery testing · Larchmere HRClosed

Analyst hours per vendor

The time that goes into each vendor, and the work CyberContext takes off the list.

Reconciling sources
Chasing evidence
Re-reviewing after changes
Following up on findings

Findings traced and closed with a reason

Every finding points to the passage it came from, and closes as resolved, risk accepted or no longer applies.

"…notify Customer within twenty-four (24) hours…" · page 4
Finding→Closed · Resolved

Example data · names are fictional

See it on your own documents.

Bring a few you're unsure about: a vendor's audit report, a customer contract, an application's policies or a new rule. We'll show you what needs fixing, what needs proof, and what you can stop worrying about.

We'll use your details only to arrange the walkthrough. See our privacy policy.