← All products

Product Live

Cymph

Your Single Source of Truth for Cyber Processes

One vendor-agnostic platform that turns written security procedures into live, auditable workflows — inside and beyond your organization.

The process gap

Resilience is a mandate. Procedures are still fragmented.

+30%

Global attack volume, year over year in Q2 2024

+219%

Dark web mentions of malicious AI tools

150,000+

EU organizations exposed under NIS2 to fines of up to €10 million or 2% of revenue

Cyber resilience is now a board-to-basement mandate. But the procedures that govern a response stay fragmented. PDF and wiki playbooks sit idle in Confluence, SharePoint, and email. xDR, SOAR, and SIEM consoles stay siloed inside SecOps. Neither side forms one live process the enterprise can execute, audit, and prove.

Cymph provides that missing layer — connecting general-purpose and security tools into a single source of truth, and bringing CISO, GRC, compliance, IT, SOC, management, and PR into the same workflow.

Your single source of truth

One platform for cyber processes, teams and tools

  1. 01

    Connect

    We connect your general-purpose and cyber tools into a single, vendor-agnostic source of truth.

  2. 02

    Collaborate

    Bring stakeholders into the loop and share cyber processes across and beyond the organisation.

  3. 03

    Integrate

    Scale up and optimise operations by unifying processes across every system.

Who it serves

Built for every team that owns a response

Large enterprises

SOC teams ingest existing playbooks once and convert them automatically into any SOAR, eliminating version drift. GRC teams map controls to playbook steps with execution evidence preserved. Leadership gains direct visibility into cyber readiness and gaps.

MSSPs, consultants, and vCISOs

Manage hundreds of playbooks across dozens of client deployments from one platform, authoring vendor-agnostic playbooks that convert automatically into vendor-specific versions.

CERTs, ISACs, and regulatory authorities

Publish verified playbooks to partner organizations and revoke access at any time, with granular distribution control and mapping to NIS2, DORA, and CISA frameworks.

Core capabilities

From written procedure to executable workflow

01

Standardized playbooks

Stored in the CACAO Open Standard, with full versioning, draft management, and export for offline use or regulatory reporting.

02

No-code editor

Drag-and-drop creation, from high-level to executable, with no JSON or scripting. Auditors and non-technical stakeholders can review workflows directly.

03

Secure sharing

Share with individuals, teams, organizations, or publicly under granular permissions, with real-time co-editing and fully auditable activity.

04

Role-based access

Admin, Editor, Collaborator, and Viewer roles keep responsibilities separated across multiple teams.

05

Integrated asset management

People, places, devices, equipment, and authentication data managed inside playbooks, with permission-controlled sharing.

06

Verified community

Search and reuse content from trusted entities such as CISA and ENISA as templates for your own operations.

07

AI-assisted conversion

Import Markdown, PDFs, and images into CACAO, standardizing procedures with no vendor lock-in.

08

Write once, execute everywhere

One playbook runs across different security stacks with one-click deployment, no rewrites.

Playbook conversion

Seamless migration into CACAO

AI-supported migration from the formats and platforms you already use — with no vendor lock-in.

  1. 01

    AI-Assisted Migration

    Automate and accelerate playbook transformation with AI-powered conversion — less manual effort, higher accuracy.

  2. 02

    Multi-Format Conversion

    Import and convert existing playbooks from Markdown, PDFs and images into CACAO.

  3. 03

    No Vendor Lock-In

    Keep full control of your playbooks so they stay a consistent source of truth as tools evolve.

  4. 04

    Standardisation

    Reduce complexity and enhance interoperability under one unified, structured framework.

Deployment

Cloud or on your own infrastructure

Cloud-based SaaS

Freemium, seat-based team, and enterprise licensing.

On-premises

Containerized deployment on your own infrastructure.

Both options include feature-based integrations and professional services for onboarding, consulting, and training.

The team

Built by practitioners

Cymph is built by cybersecurity specialists with backgrounds in enterprise threat intelligence, network monitoring research, and large-scale security R&D — including active contributors to the OASIS CACAO and CTI technical committees, FIRST.org, and ENISA working groups on security operations.

Planning a network, command center, or security program? Let's talk about scope, timeline, and delivery.

Request a Consultation