Why CyberWave exists
The same security expectations, without the budget, the team or the GRC department.
A 60-person manufacturer is now asked the questions a 6,000-person bank is asked — by its insurer, by its largest customer, by an auditor. The expectations scaled. The staffing did not. CyberWave exists to close that gap with software a business can actually operate, plus advisory when it needs a name in the room, and training for the people doing the work.
No credit card required
- Policies18%87
- Evidence Ready18%79
- Risk Mgmt14%73
The readiness score and its composition — the product, not an illustration of it. The example workspace scores 76, which is the product’s own “Expected” band: reasonable maturity with real gaps still open. Northstar Manufacturing Ltd. is fictional.
Security expectations scaled with the threat. Budgets, teams and GRC departments did not.
Nobody in a 60-person business decided to take on a compliance function. It arrived, attached to a renewal date and a customer contract, and it landed on whoever was closest.
The mismatch
What is expected, and what is actually in the building.
This is not a gap in seriousness. It is a gap in staffing, and it is extremely common — which is why the tools built for the left-hand column keep failing the organisations in the right-hand one.
- A control register mapped to a recognised framework
- Evidence that a control operated, with a date and an owner
- A risk register that is reviewed rather than written once
- Answers to nine underwriter control questions, evidenced
- A security questionnaire returned inside a customer’s legal timeline
- A board or owner update that survives a follow-up question
- No compliance team, and no GRC platform to feed one
- One person whose job this is not, and who did not ask for it
- A shared drive, a spreadsheet, and a folder called final_v3
- Requirements arriving from outside, in four different formats
- Deadlines set by other people, none of them negotiable
- A budget that does not stretch to enterprise software or a consultant on retainer
What we built
One register the whole programme hangs off.
Not a document generator and not a consultant’s deliverable. A place where a requirement knows which control answers it, a control knows who owns it, and a piece of evidence knows when it stops being true.
- Requirements and frameworks — mapped against one register instead of one project per standard
- Controls with named owners — and the unowned ones shown in red rather than averaged away
- Evidence with status and expiry — so something going stale is flagged on screen, not in an audit finding
- Risks, actions and reporting — built from the same records, so the register and the board pack cannot disagree
Point of view
Four positions that decide how the product behaves.
Each one shows up as something the software does or refuses to do, and each one occasionally makes CyberWave look worse than a competitor on a first screenshot.
- 01
Evidence beats assertion
Anyone can write "we have MFA" on a form. What survives a challenge is the artefact — the export, the policy version, the test record — with a date on it and a note of who produced it. So evidence in Sentinel carries a status and an expiry and is attached to the control it supports, rather than living in a folder that cannot tell you when it stopped being true.
- 02
Ownership beats intent
A control assigned to "IT" is not assigned. Half of readiness work is deciding who is answerable for each requirement and letting that be visible, so an unowned control is a reported gap here rather than a blank cell nobody scrolls to.
- 03
An honest "not assessed" beats a score
A new workspace does not open on 42%. It opens on Not assessed and fills in as evidence arrives. A number invented to make a dashboard look finished is the one thing you cannot defend in front of an underwriter or a board.
- 04
A score has to show its working
Readiness is 9 weighted categories and the weights are published in the product. Evidence and policies carry the most, because they are what an auditor and an underwriter actually ask to see. A gauge nobody can take apart is a decoration.
How to work with CyberWave
Software, advisory, training — priced separately, none a prerequisite.
Most organisations start with the software and one deadline that is already in the diary. Nothing here requires you to buy the column to its right.
| Criterion | Software | Advisory | Training |
|---|---|---|---|
| What it is | Sentinel: the readiness workspace — requirements, controls, evidence, assessments, risks, actions, insurance readiness, audit workspace and reporting. | A named CyberWave advisor on a scheduled cadence, on top of the platform: risk and roadmap review, executive reporting support, someone answerable in the room. | Academy: preparation for the certifications people in these roles are asked to hold — CISSP, CISM, CISA, CRISC — plus AI governance. |
| What it costs | From $99/month (Essentials, 2 users) to $249/month (Full Platform, 5 users). | Managed vCISO Lite $999/month, including everything in Full Platform. Deeper engagements from $2,499/month against an agreed statement of work. | Priced per programme, on request. |
| When it fits | Preparing for a first cyber-insurance renewal or a first customer security questionnaire. | No internal security leadership, and a need for someone accountable in the room. | Somebody internal is becoming the security person and needs the credential their customers keep asking about. |
| Trial | 14-day free trial, no credit card, no automatic charge. | None. A cadence is not something you can sample. | None. |
| What it is not | Not a compliance guarantee and not a certification. | Not 24/7 monitoring, not emergency incident response, not insurance brokerage, not an audit opinion. | CyberWave is not a certification body and does not issue the credentials themselves. |
- What it is
- Sentinel: the readiness workspace — requirements, controls, evidence, assessments, risks, actions, insurance readiness, audit workspace and reporting.
- What it costs
- From $99/month (Essentials, 2 users) to $249/month (Full Platform, 5 users).
- When it fits
- Preparing for a first cyber-insurance renewal or a first customer security questionnaire.
- Trial
- 14-day free trial, no credit card, no automatic charge.
- What it is not
- Not a compliance guarantee and not a certification.
- What it is
- A named CyberWave advisor on a scheduled cadence, on top of the platform: risk and roadmap review, executive reporting support, someone answerable in the room.
- What it costs
- Managed vCISO Lite $999/month, including everything in Full Platform. Deeper engagements from $2,499/month against an agreed statement of work.
- When it fits
- No internal security leadership, and a need for someone accountable in the room.
- Trial
- None. A cadence is not something you can sample.
- What it is not
- Not 24/7 monitoring, not emergency incident response, not insurance brokerage, not an audit opinion.
- What it is
- Academy: preparation for the certifications people in these roles are asked to hold — CISSP, CISM, CISA, CRISC — plus AI governance.
- What it costs
- Priced per programme, on request.
- When it fits
- Somebody internal is becoming the security person and needs the credential their customers keep asking about.
- Trial
- None.
- What it is not
- CyberWave is not a certification body and does not issue the credentials themselves.
On purpose
Four things you can verify without asking us.
Not claims about culture. Four decisions with a public artefact behind each one, which is what goes here instead of a logo wall — there are no customers yet, and inventing some is not an option.
- Prices are on the website
- Every software plan, seat pack and the advisory and Submission Pack prices are published, in dollars, with the annual total stated rather than implied. Only a Custom arrangement and Academy programmes are priced on request; everything else carries a number. See pricing
- The limits are on the marketing pages
- The sentences describing what CyberWave does not do are the same sentences in the legal package, and they are on the product pages rather than only in the Terms. It is cheaper to be clear than to be found out.
- The security page says what we do not have
- No SOC 2 report, no ISO 27001 certificate, no penetration-test attestation, no single sign-on or SAML. All four are in a table with the things we do have, not three clicks deeper. Read the register
- Data location is stated exactly
- Your data is stored in Canada, in ca-central-1. Application compute runs in the United States and AI requests go to the United States — so data crosses the border to be processed even though it is stored in Canada. Worth stating plainly if you have a residency requirement. How data is handled
Fit, and the counterparty
Who this is not for.
If you already run a compliance team with internal audit, a full control-testing calendar and a GRC platform that people are paid to maintain, Sentinel is lighter than what you need. Saying so costs one deal. Discovering it in month three costs a reference — and we do not have references to spare.
And if what you actually need is somebody watching alerts overnight, that is a security operations provider, not us. CyberWave does not operate a SOC, does not provide managed detection and response, does not perform penetration testing and does not offer dark-web monitoring. Sentinel is where the governance programme lives.
- Registered name
- CYBER WAVE INC.
- Jurisdiction
- Ontario, Canada
- Registration
- Ontario Corporation Number 1000780137
- Location
- Markham, Ontario, Canada
- Trading as
- CyberWave
The registered name is two words and the brand is one. That difference is real and is preserved exactly as registered, because the party to an agreement is the company and not the logo. CyberWave publishes its corporate locality rather than a service address, so legal notices under the Terms are given by email.
Published, not on request
The whole commercial model, in three numbers.
Two self-service plans and one advisory tier with a price on it. There is no tier on this site whose price you have to ask for, except the ones that genuinely need a scope conversation — and those say so.
2 users, one framework in scope, 14-day trial with no card.
5 users, multiple frameworks, audit workspace and board reporting.
Everything in Full Platform, plus a named advisor on a cadence. The advisor does not consume a seat.
Plainly
What CyberWave is not.
Four paragraphs, reproduced verbatim from the legal package rather than paraphrased into something friendlier. The friendlier version is how a marketing page and a contract end up saying different things.
Questions
Working with CyberWave.
Six questions that come up before anyone talks about price, including the one about how big we are.
Do I have to buy advisory to use the software?
Can we start with advisory and keep the workspace afterwards?
Do you take over when there is an incident?
Do you sell cyber insurance?
Can our existing MSP or consultant work in the same workspace?
How big is CyberWave?
Bring the deadline that is already in the diary.
A renewal date, a customer’s security review, a first framework. You do not need a programme to start — you need the thing that is due, and somewhere honest to put it.
No credit card required
- Published pricing on every standard plan
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required