Recent development in Cyberday

Subscribe for our newsletter and you'll receive a digest of new product updates weekly. Newsletter also includes a list of most important cyber security news and upcoming free webinars.
Kiitos! Klikkaa vielä saamaasi vahvistuslinkkiä (sähköposti otsikolla "Vahvista sähköpostiosoitteesi") ja uutiskirje saapuu jatkossa sähköpostiisi.
Valitettavasti jotain meni pieleen. Voit olla yhteydessä tiimi@tietosuojamalli.fi.
new feature
January 17, 2025

7 new frameworks soon available in Cyberday!

We will be publishing numerous new frameworks in the upcoming days. Here is the full list with short introductions:

  • CIS 18 controls: The CIS18 critical security controls is a comprehensive set of instructions and measures released by The Center for Internet Security. Controls are designed to fix and prevent common vulnerabilities and to offer organizations a structured way to strengthen their security.
  • DORA simplified RMF: The DORA RTS on simplified ICT risk management describes the key elements that financial entities subject to  lower scale, risk, size and complexity need to have in place to manage risks.
  • Kibernetinio Saugumo Įstatymas (Lithuania): The Cybersecurity Act "Kibernetinio Saugumo Įstatymas" implements the European Union NIS2 law in Lithuania. It sets out requirements for various organisations to strengthen their cybersecurity risk management.
  • La loi NIS2 (Belgique): The European Union NIS2 has been transposed in Belgium into national law as the NIS2 law. The law closely aligns with the EU NIS2 directive and features only minor national differences. It obligates and defines cybersecurity rules for companies registered in Belgium working in the critical sector.
  • Nacionālās kiberdrošības likums (Latvia): NIS2 has been adopted as "National Cyber Security Act" in Latvia. It improves the security of information and communication technologies, including setting requirements for the provision and receipt of essential and important services and operation of information and communication technologies.
  • NIST CSF 2.0: NIST CSF's new 2.0 edition is designed to help all organizations in any sector to achieve their cybersecurity goals with added emphasis on governance as well as supply chains.
  • Zakon o kibernetičkoj sigurnosti (Croatia): Croatian implementation of the NIS2 The Cybersecurity Act (Zakon o kibernetičkoj sigurnosti NN 14/2024) has come into account in February 2024. It defines cybersecurity rules for Croatian companies with the same criteria as NIS2 with some exceptions.
small improvement
January 17, 2025

More votes and other improvements in Development ideas forum

We're continuing improvements on the Cyberday Community's Development ideas forum.

Now each user has more votes available (20 for suggested ideas). Removing votes from ideas is now possible too - also in the situation where you have used all your available votes.

new feature
January 17, 2025

COMING UP: Cyberday Trust centers

Cyberday Trust centers let you share selected information security information with customers and other stakeholders in a professional and organized way.

You can enable your Trust center from the Reporting-page and define the wanted settings - e.g. which reports to include and will part of information will be available publicly or only by request.

We're currently doing initial testing of Trust centers and are looking to deploy this feature for customers in the upcoming weeks.

new feature
January 17, 2025

COMING UP: Improvement suggestions on Dashboard

What should we focus on next? We want to help our customers answer this question more clearly in the future.

Soon the Dashboard will offer you clear and prioritized tips on how to improve the compliance score and assurance towards your chosen primary framework. You can continue to more detailed page that presents 10 actions you can take on both categories.

We're currently finalizing the tech of prioritizing the suggestions smartly and are looking to introduce this feature in the upcoming weeks.

January 10, 2025

Risk control factor (RCF) now visible on risk cards

When you've enabled the auto-evaluation for risks, we assist you in risk evaluation by filling in base values and adjusting them according to your current risk control tasks.

Risk control factor, RCF, communicates how well your current control tasks are already mitigating the risks.

Details for counting the RCF are available always on the risk card, and more details on the related help article.

Related help articleCalculating risk level in Cyberday

small improvement
January 10, 2025

Grant a controlled support access to your account

Your account admins can now grant our team a time-limited support access to your account. This is beneficial e.g. for training purposes and solving trickier customer support cases which you might have initiated.

When the access time ends or you revoke access, all support users are automatically removed.

Related help article: Allowing support access

small improvement
December 13, 2024

More comprehensive summary and comparison across all of a user's accounts

We improved the "My Accounts" view, which is especially relevant for larger corporations (which utilize multiple Cyberday accounts) and Cyberday partners who help users with multiple accounts.

My accounts page now shows better information about the compliance scores of different frameworks and their progress.

In addition, there is a new "Compare Accounts" view, which makes it easy to compare different accounts:

  • Progress on the same frameworks
  • Activity in using the ISMS (number of activities in different periods, number of users)
  • Various key event counts (risks, incidents, deviations)
small improvement
December 13, 2024

Small improvements to vendor assessments released

We released several smaller improvements to the recently released vendor security assessments, including:

  • Viewing detailed vendor assessment results
  • Re-sending assessment requests to vendors who have not yet responded
  • Deleting assessments

In addition, existing accounts can now also complete self-assessments (e.g. for a new framework) using refreshed assessment tools.

We have already received several wishes to further improve assessments (e.g. assessments for different frameworks for different vendors, and adding your own questions) and we will continue to work on these in the near future. 👍

small improvement
November 28, 2024

Automatic user de-activation for leaving employees

If you're distributing Cyberday via Teams app setup policies, new users will get created automatically in Cyberday.

Now the same integration also handles user de-activation when you delete them from your tenant. After the de-activation, you'll be notified and can e.g. re-assign their content (if relevant) according to this help article.

small improvement
November 28, 2024

Cyberday now available in Latvian and Lithuanian

Our language selection has expanded. Latvia and Lithuania have also been active with their own NIS2 legislation, which has already been finalized in both countries. These versions of the NIS2 laws will also soon be available in Cyberday as frameworks.

small improvement
December 13, 2024

Vendor assessment improvements coming soon

We've continued with multiple smaller improvements to the recently created vendor security assessments:

  • Viewing detailed assessment results
  • Resending assessments to vendors that haven't yet answered
  • Deleting assessments
small improvement
November 15, 2024

Web app domain updated to app.cyberday.ai

Our web app domain changed to app.cyberday.ai recently. This was related to our company name update, which we communicate more in this blog post.

The change is mostly invisible (e.g. all old links will redirect properly and everything will work just the same). But if you e.g. have some specific security systems allowing our old domain, you'd need to add our new domain there too.

new feature
October 25, 2024

Sharing corporate group's task descriptions to subaccounts

In larger corporate group (i.e. groups of companies), there can be on main account responsible for sometimes setting additional requirements for subaccounts for certain tasks and sometimes offering the group-level implementation for some tasks.

Now this can be implemented better inside Cyberday. One account in a group of accounts can be assigned as the "corporate group account", which can then decide to share some task descriptions forward for sub accounts.

Sub accounts will receive the shared descriptions instantly, but need to otherwise manage the task normally and write their own "Account-specific additions" to the process description.

N.b.! This feature needs to be enabled the first time by contacting our team e.g. through the chat or at team@cyberday.ai.

new feature
October 25, 2024

CyberFundamentals framework

CyberFundamentals, maintained by Centre for Cybersecurity Belgium, has been published in Cyberday.

The Belgian NIS2 law also refers quite directly to CyberFundamentals to define measures that meet NIS2 requirements.

CyberFundamentals offers a very comprehensive perspective on information security, borrowing many elements from, among others, the NIST CSF and ISO 27001 frameworks.

new feature
October 25, 2024

Published: Security assessments for suppliers / partners

We will soon be releasing the first version of our new vendor security assessments feature.

This feature will enable you to first categorize your partners to different sets - to name which ones should get your security assessment. Then you can send assessments out based on a selected framework.

Under Partner management, you will see the summaries of assessment statuses and scores got by different vendors.

P.s. Also your own self assessments will be enabled through the new assessment flow soon.