nD3FENSE Request a demo

Continuous threat exposure management

Find what’s exposed.
Fix it. Prove it.

Any scanner’s output, one triage queue. Answer your controls once and CMMC, NIST CSF, ISO 27001, CIS and more than 240 other frameworks all report from that same record.

1,500+

Controls you answer, once

69,700+

Published mappings doing the translation for you

~250

Frameworks you can report against

Always

Human attestation

Frameworks

  • CMMC 2.0 Level 2
  • NIST SP 800-171
  • NIST CSF 2.0
  • NIST SP 800-53
  • ISO 27001
  • ISO 27002
  • SOC 2
  • CIS Controls v8
  • PCI DSS 4.0
  • HIPAA Security Rule
  • FedRAMP
  • GDPR
  • NIST AI RMF
  • NERC CIP
  • CJIS Security Policy
  • TISAX
  • SOX
  • CCPA

Security posture

Scored against your own target, with an owner and a date it comes back.

AST-02 · Asset inventory

Approved

Maturity Level 3, target 4
Owner Compliance Manager
Revalidate Annually, next 14 March
History Level 2 → 3 on 9 Feb, by a named assessor

Vulnerability management

Any scanner. One format in.

SCAP and STIG results, SARIF and cloud posture findings, normalized into one triage queue. Grouped by condition, not by host or by tool.

Triage · by condition

13 outstanding

CAT I WN11-00-000030 BitLocker not enforced 2 hosts
CAT I CVE-2017-0144 SMBv1 remote code execution, known exploited KEV 1 host
CAT II WN11-CC-000295 Legacy protocols permitted 11 hosts
CAT II WN11-AU-000500 Audit policy size set aside, by design 2 hosts

Risk management

Scored, priced, and owned.

R-014 · Ransomware

Authorized

Inherent 3 by 5, scored 15
Residual 2 by 3, its own entry
Priced SLE 1,470,000 · ALE 367,500

Security roadmap

Initiatives carry an owner, a target date and the resources they need. The same record a POA&M is built from, not a separate spreadsheet.

INIT-014 · MFA for legacy protocols

In progress

Owner IT Manager
Target 31 Oct
Linked 3 findings, 2 controls

Policy and governance

Every domain’s policy, standard, procedure and guideline. Owned, reviewed on the cadence you set, and versioned when it changes.

Access Control Policy

Approved

Version 4
Owner Compliance Manager
Reviewed Annually, next 12 Feb
Linked 41 controls

Compliance reporting

One answer, read by every framework.

AST-02

Asset inventory

Assets are inventoried, owned and kept current.

Level 3 · target 4
CMMC L2 CM.L2-3.4.1 System baselining
NIST CSF ID.AM-01 Hardware inventories are maintained
CIS v8 1.1 Establish and maintain asset inventory
ISO 27001 A.5.9 Inventory of information and other assets

Diagrams and documents

Generate them from system data or bring your own. Editable either way.

Standard formats out, too. Word, HTML, JSON, CSV and XML exports, a System Security Plan and a POA&M, built from the same record rather than a separate write-up.

Network diagram · from inventory

Editable

CUI ENCLAVE Workstations ×24 File server ERP Log platform Backup appliance VPN concentrator Cloud backup

CUI flowCrosses the boundary

System Security Plan · CUI

Editable

3.4.1

Baseline configuration

Implemented

Baselines are maintained for each system in the enclave and reviewed annually.

OwnerCompliance Manager, from the control record
Evidence3 documents linked
2.3Boundary diagram, inserted from inventory

Word · HTML · JSON

Meet Caleb.

Caleb reads your documents and your intake answers, and proposes determinations with a note tracing to the evidence. A person adopts or rejects every one.

AI can make mistakes. Check each proposal against its source before you adopt it.

CM.L2-3.4.1[a] · proposed by Caleb

Not recorded

MET

“Baseline configurations are established, documented and maintained for each system in the CUI enclave.”

Configuration Management Policy v4 · page 7

Adopt Reject Nothing reaches a report until a person chooses.

About

A continuous threat exposure management platform. One place to see what’s exposed, decide what to do about it, and prove it.

Who it is for
Security teams, consultancies and MSPs, running one organization or many.
What it replaces
Spreadsheet crosswalks, document folders, and diagrams that drift from the estate.
How it starts
Hosted, ready to use. Start with one framework and add the rest when you need them.

Contact

Tell us which framework you are assessed against and we will show it against your own estate rather than a demonstration.