CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Core modules · Compliance & risk

Controls mapped from live events — not spreadsheet archaeology.

Network and OT events auto-map to roughly seven controls each. Framework packs for IEC 62443-3-3, NERC CIP, NIST CSF 2.0, ISO 27001:2022, and SOC 2 feed auditor packets from the evidence vault. FAIR-style scenario scores help CISOs prioritize without fake precision.

What it delivers

Production path with honest PARTIAL labels.

Automatic event→control mapping (~7 controls per network event)

IEC 62443-3-3, NERC CIP, NIST CSF 2.0, ISO 27001:2022, SOC 2 packs

Per-asset risk scoring on a 0–100 scale

FAIR-style scenario models for board narrative

Evidence vault export with control mappings

Honest PARTIAL maturity labels while dashboards harden

SOC

Where every Core module lands

  • Live, partial, and roadmap labeled honestly on the platform page.
  • Detection, risk, compliance, and identity share the same incident.
  • Click a module, then come back to the operator board.
CyberDragon Unified SOC dashboard
How it works

From signal to sealed evidence.

01

Observe

Edge and connector events enter the normalized stream with zone and asset context.

02

Map

Compliance auto-mapper attaches relevant controls to each qualifying event.

03

Score

Risk engine computes asset and scenario scores for prioritization.

04

Pack

Framework packs filter views and exports for the auditor's chosen standard.

05

Report

Executive reporting generates CISO and board summaries from live evidence.

06

Export

Signed ZIP packets include mappings, scores, and chain verification.

Playbooks

SOAR module in the workspace

  • Run from the incident, not from a disconnected automation island.
  • OT guardrails stay in the path.
  • YAML for teams who version playbooks.
CyberDragon Response playbooks
Key capabilities

Built for regulated IT/OT estates.

Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Signal sources

What feeds this module.

OT protocol events

Modbus writes and DNP3 commands carry zone and asset identifiers.

Identity events

MFA, RBAC, and session issuance map to access controls.

Response decisions

Approvals and OPA denials prove operational control effectiveness.

Evidence chain

Tamper-evident records back every mapped control claim.

UEBA

User and entity behavior

  • Anomaly signals join the same kill chain as OT protocol events.
  • Useful when identity abuse starts the campaign in enterprise.
  • Not a stand-alone UEBA SKU.
UEBA dashboard
Proof points

Measured in the lab — not marketing adjectives.

~7
Controls mapped per network event
5
Framework packs
0–100
Normalized risk scores
PARTIAL
Honest maturity label
Lab-validated metrics. Proof of Value results may vary.
FAQ

Frequently asked questions.

Is compliance mapping fully automated?
Auto-mapper is PARTIAL maturity — it maps roughly seven controls per network event today. Framework packs and exports are production paths; dashboards continue to harden.
Which frameworks are supported?
IEC 62443-3-3, NERC CIP, NIST CSF 2.0, ISO 27001:2022, and SOC 2 packs are available per tenant.
Can auditors verify the mappings?
Yes. Exports include control mappings plus hash-chained evidence with Ed25519 signatures.

Generate a framework-aligned evidence packet in your trial.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.