Why CyberWave exists

The same security expectations, without the budget, the team or the GRC department.

A 60-person manufacturer is now asked the questions a 6,000-person bank is asked — by its insurer, by its largest customer, by an auditor. The expectations scaled. The staffing did not. CyberWave exists to close that gap with software a business can actually operate, plus advisory when it needs a name in the room, and training for the people doing the work.

No credit card required

The readiness score and its composition — the product, not an illustration of it. The example workspace scores 76, which is the product’s own “Expected” band: reasonable maturity with real gaps still open. Northstar Manufacturing Ltd. is fictional.

Security expectations scaled with the threat. Budgets, teams and GRC departments did not.

Nobody in a 60-person business decided to take on a compliance function. It arrived, attached to a renewal date and a customer contract, and it landed on whoever was closest.

The mismatch

What is expected, and what is actually in the building.

This is not a gap in seriousness. It is a gap in staffing, and it is extremely common — which is why the tools built for the left-hand column keep failing the organisations in the right-hand one.

What is now expected of you
  • A control register mapped to a recognised framework
  • Evidence that a control operated, with a date and an owner
  • A risk register that is reviewed rather than written once
  • Answers to nine underwriter control questions, evidenced
  • A security questionnaire returned inside a customer’s legal timeline
  • A board or owner update that survives a follow-up question
What you actually have
  • No compliance team, and no GRC platform to feed one
  • One person whose job this is not, and who did not ask for it
  • A shared drive, a spreadsheet, and a folder called final_v3
  • Requirements arriving from outside, in four different formats
  • Deadlines set by other people, none of them negotiable
  • A budget that does not stretch to enterprise software or a consultant on retainer

What we built

One register the whole programme hangs off.

Not a document generator and not a consultant’s deliverable. A place where a requirement knows which control answers it, a control knows who owns it, and a piece of evidence knows when it stops being true.

  • Requirements and frameworks — mapped against one register instead of one project per standard
  • Controls with named owners — and the unowned ones shown in red rather than averaged away
  • Evidence with status and expiry — so something going stale is flagged on screen, not in an audit finding
  • Risks, actions and reporting — built from the same records, so the register and the board pack cannot disagree

See the workflowCompare plans

Example Sentinel screen, reproduced with fictional data: Control register. Of 26 controls, 18 are operating, 6 need evidence and 2 are not implemented; 24 have an owner. Each control is listed with owner, status, evidence and last test date.

Point of view

Four positions that decide how the product behaves.

Each one shows up as something the software does or refuses to do, and each one occasionally makes CyberWave look worse than a competitor on a first screenshot.

  1. 01

    Evidence beats assertion

    Anyone can write "we have MFA" on a form. What survives a challenge is the artefact — the export, the policy version, the test record — with a date on it and a note of who produced it. So evidence in Sentinel carries a status and an expiry and is attached to the control it supports, rather than living in a folder that cannot tell you when it stopped being true.

  2. 02

    Ownership beats intent

    A control assigned to "IT" is not assigned. Half of readiness work is deciding who is answerable for each requirement and letting that be visible, so an unowned control is a reported gap here rather than a blank cell nobody scrolls to.

  3. 03

    An honest "not assessed" beats a score

    A new workspace does not open on 42%. It opens on Not assessed and fills in as evidence arrives. A number invented to make a dashboard look finished is the one thing you cannot defend in front of an underwriter or a board.

  4. 04

    A score has to show its working

    Readiness is 9 weighted categories and the weights are published in the product. Evidence and policies carry the most, because they are what an auditor and an underwriter actually ask to see. A gauge nobody can take apart is a decoration.

How to work with CyberWave

Software, advisory, training — priced separately, none a prerequisite.

Most organisations start with the software and one deadline that is already in the diary. Nothing here requires you to buy the column to its right.

Software
What it is
Sentinel: the readiness workspace — requirements, controls, evidence, assessments, risks, actions, insurance readiness, audit workspace and reporting.
What it costs
From $99/month (Essentials, 2 users) to $249/month (Full Platform, 5 users).
When it fits
Preparing for a first cyber-insurance renewal or a first customer security questionnaire.
Trial
14-day free trial, no credit card, no automatic charge.
What it is not
Not a compliance guarantee and not a certification.
Advisory
What it is
A named CyberWave advisor on a scheduled cadence, on top of the platform: risk and roadmap review, executive reporting support, someone answerable in the room.
What it costs
Managed vCISO Lite $999/month, including everything in Full Platform. Deeper engagements from $2,499/month against an agreed statement of work.
When it fits
No internal security leadership, and a need for someone accountable in the room.
Trial
None. A cadence is not something you can sample.
What it is not
Not 24/7 monitoring, not emergency incident response, not insurance brokerage, not an audit opinion.
Training
What it is
Academy: preparation for the certifications people in these roles are asked to hold — CISSP, CISM, CISA, CRISC — plus AI governance.
What it costs
Priced per programme, on request.
When it fits
Somebody internal is becoming the security person and needs the credential their customers keep asking about.
Trial
None.
What it is not
CyberWave is not a certification body and does not issue the credentials themselves.

On purpose

Four things you can verify without asking us.

Not claims about culture. Four decisions with a public artefact behind each one, which is what goes here instead of a logo wall — there are no customers yet, and inventing some is not an option.

Prices are on the website
Every software plan, seat pack and the advisory and Submission Pack prices are published, in dollars, with the annual total stated rather than implied. Only a Custom arrangement and Academy programmes are priced on request; everything else carries a number. See pricing
The limits are on the marketing pages
The sentences describing what CyberWave does not do are the same sentences in the legal package, and they are on the product pages rather than only in the Terms. It is cheaper to be clear than to be found out.
The security page says what we do not have
No SOC 2 report, no ISO 27001 certificate, no penetration-test attestation, no single sign-on or SAML. All four are in a table with the things we do have, not three clicks deeper. Read the register
Data location is stated exactly
Your data is stored in Canada, in ca-central-1. Application compute runs in the United States and AI requests go to the United States — so data crosses the border to be processed even though it is stored in Canada. Worth stating plainly if you have a residency requirement. How data is handled

Fit, and the counterparty

Who this is not for.

If you already run a compliance team with internal audit, a full control-testing calendar and a GRC platform that people are paid to maintain, Sentinel is lighter than what you need. Saying so costs one deal. Discovering it in month three costs a reference — and we do not have references to spare.

And if what you actually need is somebody watching alerts overnight, that is a security operations provider, not us. CyberWave does not operate a SOC, does not provide managed detection and response, does not perform penetration testing and does not offer dark-web monitoring. Sentinel is where the governance programme lives.

Who you would be contracting with
Registered name
CYBER WAVE INC.
Jurisdiction
Ontario, Canada
Registration
Ontario Corporation Number 1000780137
Location
Markham, Ontario, Canada
Trading as
CyberWave

The registered name is two words and the brand is one. That difference is real and is preserved exactly as registered, because the party to an agreement is the company and not the logo. CyberWave publishes its corporate locality rather than a service address, so legal notices under the Terms are given by email.

Published, not on request

The whole commercial model, in three numbers.

Two self-service plans and one advisory tier with a price on it. There is no tier on this site whose price you have to ask for, except the ones that genuinely need a scope conversation — and those say so.

$99/mo
Essentials

2 users, one framework in scope, 14-day trial with no card.

$249/mo
Full Platform

5 users, multiple frameworks, audit workspace and board reporting.

$999/mo
Managed vCISO Lite

Everything in Full Platform, plus a named advisor on a cadence. The advisor does not consume a seat.

Compare plans

Plainly

What CyberWave is not.

Four paragraphs, reproduced verbatim from the legal package rather than paraphrased into something friendlier. The friendlier version is how a marketing page and a contract end up saying different things.

Questions

Working with CyberWave.

Six questions that come up before anyone talks about price, including the one about how big we are.

Do I have to buy advisory to use the software?
No. The two self-service plans are the product on its own, and they are not a trial of a consulting relationship. Advisory exists for organisations that want someone accountable in the room, not as a gate in front of the software.
Can we start with advisory and keep the workspace afterwards?
Managed vCISO Lite includes everything in Full Platform, so it is the same workspace either way. Your controls, evidence and history belong to your organisation and are not tied to an engagement running.
Do you take over when there is an incident?
No. Advisory is scheduled work, not an on-call service: it does not include 24/7 security operations monitoring or emergency incident response. Sentinel organises the preparation — named owners, documented plans, evidence and tracked actions. If you need someone on the phone at 3am, that is an incident-response retainer, and it is a different purchase from a different kind of company.
Do you sell cyber insurance?
No. CyberWave is not an insurer or a broker, does not bind coverage and does not place policies. What CyberWave does is get your evidence and your answers into a state your broker and underwriter can work with before the renewal date, rather than during it.
Can our existing MSP or consultant work in the same workspace?
Yes. Controls are owned by named people and users are seats, so an external adviser can hold a seat and an owner’s name like anyone else. If you are the adviser rather than the customer, the partners page is the right route in.
How big is CyberWave?
Small enough that a message to support reaches a person who can change the product, and small enough that this page does not have a headcount, a client count or a years-in-business figure on it. If a vendor’s size is a procurement criterion for you, ask directly and you will get a straight answer rather than a number chosen to clear your threshold.

Bring the deadline that is already in the diary.

A renewal date, a customer’s security review, a first framework. You do not need a programme to start — you need the thing that is due, and somewhere honest to put it.

Start your 14-day free trial

No credit card required

  • Published pricing on every standard plan
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required