Nine agents for one management system
Nine agents for the parts of compliance nobody owns.
Risk, continuity, incidents, suppliers, awareness, governance, assurance and the documents all of them feed. Each one does a real job. One of them you can buy today.
- Agents in the fleet
- 9
- Available to buy today
- 1
- Still in build, and labelled
- 4
The Problem
Compliance is a dozen jobs handed to one person.
Someone has to assess the risks, prove the business could survive a disruption, handle incidents against a legal clock, chase suppliers for certificates, make awareness material people remember, agree objectives with leadership, and track every finding to closure.
Usually that someone is one person who also has another job. So the work gets done as a set of documents, each written once, each going stale the moment it is filed, and each re-written from scratch the month before an audit.
Two Ideas
Everything else follows from these.
A document is a snapshot, not an artefact.
The register is the truth. A policy or a plan is rendered from it when someone needs one, then thrown away. That is why there is no document management system here and there is not going to be one: keeping the record right is the entire job.
The agent proposes. You decide.
No agent signs anything off, closes anything, or records a verdict on its own authority. Every change is shown to you first and written only when you say so. That is not a limitation we plan to remove: it is what makes the output usable as evidence.
The Roadmap
Six moves, in the order they pay off.
- 1
Quantify the risk
Stop colouring risks in. Express them as money, so a board can compare a risk against the cost of preventing it.
- 2
Generate the documents
Keep the register right and render the policy, the plan or the minutes from it whenever anyone asks.
- 3
Close the loop
Capture each finding against the audit that raised it, and come back later to ask whether the fix held.
- 4
Reach the whole organisation
Move awareness out of an annual completion percentage and into the moments where behaviour is actually decided.
- 5
Extend past your own walls
Suppliers, devices and the parts of your estate that fail quietly rather than loudly.
- 6
Make it one system
One authoritative record behind every agent, so the same fact never has to be maintained in two places.
One System
Nine agents. One graph between them.
They do not share a runtime. What keeps them consistent is the graph underneath: the live map of your assets, people, processes and controls, held to an ontology, so a supplier, an incident and a control are typed things with typed relationships.
That structure is also what keeps the agents accurate. No agent is handed the whole graph and asked to find the relevant part. Each one queries the slice its job actually needs, which is a far harder thing to get wrong.
Risk
Continuity
Incidents
Suppliers
Awareness
Endpoints
Documents
Assurance
Governance
One graph
typed by a shared ontology
The Fleet
Nine agents, labelled honestly.
- Available now
Risk Investigation Agent
Takes you from a vague sense of risk to a number. Qualitative intelligence first, then financial exposure, then a control roadmap ranked by what each control actually returns.
See the agent - Running
Business Continuity Agent
Runs a continuity exercise as a facilitated session in three acts, and leaves an auditable record behind it rather than asking someone to write the plan up afterwards.
See the agent - Running
Incident Response Agent
Walks you through every field a NIS2 or GDPR notification needs, in a conversation that works while you are under pressure. No field is silently skipped.
See the agent - Running
Supply Chain Agent
Handles the manual grind of third-party risk: certification lookups, SLA checks, questionnaire chase-ups, criticality triage and exit plans for the vendors that need them.
- Running
Documentation Agent
Renders policies, plans and review minutes from your live registers on demand, so a document is a snapshot of the record rather than a second thing to keep current.
- In build
Governance Agent
Reasons through scope, objectives and measures with your leadership team, then proposes them into the registers. It never writes your strategy for you.
- In build
Assurance Agent
Captures each finding against the audit that raised it, tracks the fix to closure, then comes back later to ask the question most registers never do: did it hold?
- In build
Awareness Training Agent
Treats awareness as understanding rather than completion. Warm, in-context prompts and honest signals about which policies are not landing, instead of a completion percentage.
- In build
Endpoint & Usage Agent
Keeps the device register trustworthy by reading what the workspace already knows, then asking each person only about the gaps it could not fill itself.
What the labels mean, honestly
- Available now
- Buy and install it today.
- Running
- Used in the compliance work we deliver, and settled in behaviour, but not sold as a standalone product yet.
- In build
- A prototype. It runs and produces real output, but its contracts may still change.
One of the nine is available to buy today. We would rather show you the whole fleet and label it accurately than list nine products and let you find out later that eight of them are not for sale.
What It Costs
Buy one, or run the whole system.
- One agent, one time
- €250
- All nine, per month
- €875
- Per-seat charges
- 0
The fleet price includes every new agent and every new version as it ships, and the graph backend as it rolls out.
Which Agent When
Start from the job, not the tool.
- Understand and quantify what a breach would actually cost
- Risk Investigation Agent
- Prove you could keep operating through a disruption
- Business Continuity Agent
- Handle an incident against the notification clocks
- Incident Response Agent
- Keep on top of suppliers and their certifications
- Supply Chain Agent
- Produce a policy, plan or set of review minutes
- Documentation Agent
- Agree scope, objectives and measures with leadership
- Governance Agent
- Track a finding to closure and check the fix held
- Assurance Agent
- Make awareness material that people remember
- Awareness Training Agent
- Keep the device register trustworthy
- Endpoint & Usage Agent
The Clause Walk
Seven clauses, and who answers each one.
The standard runs from clause 4 to clause 10. Most of it is not about security technology at all: it is about deciding what you are protecting, agreeing what you will do, doing it, and being able to show afterwards that you did.
Clause
4
Where the line is drawn
Decide what the management system covers and what it does not, and be able to defend the boundary. Everything downstream depends on it, because there is no risk assessment without something to assess.
Who Governance reasons the boundary with leadership. Documents renders the scope.
Clause
5
Leadership actually signs
Top management owns the policy rather than delegating it. The commitment is not a separate certificate: it is a named person putting their signature on the apex policy.
Who Documents renders the policy. The substance stays leadership's.
Clause
6
The hub: risks, objectives, and what you will do about them
Work out what could go wrong, what it would cost, what you are aiming for, and which controls apply. This is the largest single piece, and the one most often done badly.
Who Risk Investigation quantifies exposure. Governance sets objectives and measures. Documents renders the applicability statement.
Clause
7
The support that makes it real
People who understand what is expected of them, and records that exist because the work happened rather than because an audit is coming.
Who Awareness runs the campaigns and the acknowledgements. Endpoints keeps the device register honest.
Clause
8
Running it
The operating parts: incidents when they happen, suppliers as they change, and a continuity plan that has been exercised rather than written.
Who Incidents, Suppliers and Continuity, each writing to the register the others read.
Clause
9
Checking whether it works
Measure, audit internally, and hold a management review that reaches actual decisions. The review is where the year's evidence is supposed to add up.
Who Governance runs the review cycle. Assurance rolls up the audit findings.
Clause
10
Fixing what did not
Nonconformities tracked to closure, and the part most systems skip: going back later to check the fix actually worked.
Who Assurance, from the finding that raised it through to re-verifying the fix.
What You Get
The documents an auditor actually asks for.
Every one of these is generated from your registers, which means it is current when you produce it rather than current when someone last remembered to update it.
- Risk register, quantified in money
- Statement of Applicability inputs
- Business continuity plan and testing schedule
- Incident records aligned to the notification clocks
- Supplier register, certifications and exit plans
- Policies, procedures and intent statements
- Management review minutes and the brief behind them
- Corrective actions, tracked to closure
The Year
A management system has a rhythm.
5 to 7
hours a week
Inner rings beat faster. The outer ring turns once.
Weekly52 times a year
Log what went wrong, close open actions, keep the registers current.
Monthly12 times a year
The awareness campaign goes out, and the device register gets its gaps chased.
Quarterly4 times a year
Check the objectives and measures still hold, and re-check the suppliers that changed.
Half-yearlyTwice a year
A checkpoint: re-run risk where the business actually moved, before it is the annual one.
YearlyOnce a year
The management review, the internal audit, the continuity drill, and the external audit itself: surveillance most years, recertification every third.
Almost all of it is the weekly beat. What people picture when they think of compliance is the outermost ring, and it turns once.
The fleet is built around that shape. The fast agents keep their registers current so the slow ones have something true to read, and the annual review is where the two meet. Certification is kept, not achieved.
Only the external audit runs on someone else's calendar. The rest is the tempo this work naturally falls into rather than a schedule the standard imposes: it asks for planned intervals, not particular ones, so those are yours to set.
The Certificate
Certification is a three-year loop, not a finish line.
Year 0
Stage 1, then Stage 2
The full stand-up. Scope, risk, documents, the operating agents, then a first internal audit and management review. This is the year that is actually hard, and the certificate at the end of it reflects work your team genuinely did.
Year 1
Surveillance, sampled
A lighter audit that asks a different question: is the system run, or only documented? Risk is re-run where things changed, and a year of evidence either exists or does not.
Year 2
Surveillance, different sample
The same annual rhythm against a different slice. A continuity exercise, effectiveness re-checks on the fixes from year one, and nothing to manufacture if the registers were kept current.
Year 3
Recertification, full scope
The whole system re-audited for a fresh three-year certificate. A full risk re-assessment, the complete document set regenerated, and the cycle starts again.
Because every document renders from a live register, recertification is a re-run rather than a rebuild. The path through the standard is the same for everyone. What the fleet changes is that the work is already real, and already written down, before the auditor asks.
Under The Hood
Nine separate agents that do not drift apart.
These are separate agents with no shared runtime, which raises an obvious question: what stops them contradicting each other?
The answer is that the facts they publish are generated from one source and checked automatically on every change, rather than being copied by hand and kept in step by whoever remembers. Anything that drifts fails the build.
There is also a maintenance layer that watches the codebase itself and raises a change request when something starts to diverge. You will never interact with it. It exists so that the version numbers, capabilities and claims on this page are true because they were derived, not because someone checked.
Get Started
Begin where the value is provable.
The Risk Investigation Agent is the one you can buy today, and it is also the right place to start: the rest of the system is far easier to build once you know what your risks are worth.
Common Questions
What people ask about the fleet.
Terms on this page
Vocabulary at a glance.
Information Security Management System
The documented set of policies, procedures, and accountability that an organisation uses to manage information-security risk over time.
ISO 27001
International standard that defines the requirements for an information security management system (ISMS), including risk assessment, control selection, and management review.
Risk Register
The single source of truth recording every identified risk, its assessment, the control treatment chosen, the owner, and the review date.
Askara Exposure Model
Quantitative risk-analysis model that expresses cyber risk as financial loss exposure rather than ordinal severity scores, by decomposing it into loss event frequency and loss magnitude.
Risk Assessment
The structured process of identifying threats, estimating likelihood and impact, and producing a defensible record of which risks the organisation accepts, treats, or transfers.
NIS2
EU directive that extends cybersecurity obligations to a much wider set of organisations than its predecessor, requiring governance, risk management, incident reporting, and supply-chain security.
Glossary
Not familiar with a term?
Search the glossary for any risk, compliance or security term on this page.
Need help?
Submit a request below and we'll get back to you within one business day.
Or email us at support@askara.solutions



