Skip to main content
General

GetCybr help center FAQ

Quick answers to common questions about onboarding, frameworks, reporting, workflows, and regional considerations.

Quick answer

This FAQ covers the common questions MSPs and vCISO teams ask when evaluating or rolling out GetCybr.

Browse concise product and rollout guidance by topic, with links to detailed Help Center resources where useful.

Product fit

What capabilities does the GetCybr platform provide?

GetCybr supports assessments, compliance delivery, risk management, third-party risk, evidence, policies, remediation tracking, and client reporting. The exact workflow depends on the products and services selected.

How is GetCybr different from a traditional GRC tool?

Traditional GRC tools commonly serve one organisation and its internal compliance team. GetCybr is designed for service providers that need repeatable workflows, client-level separation, portfolio visibility, and reporting across multiple organisations.

Can a small security team scale service delivery with GetCybr?

GetCybr can reduce recurring administration across assessments, tracking, and reporting so specialists can focus on advice and client decisions. Actual team capacity still depends on client complexity, service scope, and the operating model.

What is a vCISO platform?

A vCISO platform brings the operational parts of virtual CISO delivery into one system, including assessments, risks, frameworks, policies, evidence, reporting, and ongoing monitoring. For service providers, multi-client management is a key consideration.

Who is GetCybr designed for?

GetCybr is especially relevant to MSPs, MSSPs, security consultancies, and vCISO teams delivering repeatable services. Fit for an internal team or regulated organisation depends on its scope, delivery model, and governance requirements.

Onboarding

What information is needed to onboard a client?

Start with the client entities and service line in scope, a priority framework or objective, named owners, a reporting cadence, and initial evidence sources. Perfect documentation is not required, but unclear scope will slow every later workflow.

Does the Help Center replace onboarding and scoping conversations?

No. Help articles make rollout easier, but implementation, regional fit, access boundaries, and service scope should still be confirmed with the appropriate GetCybr and client stakeholders.

How long does client onboarding take?

Timing varies with scope, access, integrations, evidence readiness, and client decision-making. A narrow first use case can move quickly, while migrations or complex requirements need more planning; confirm a realistic timeline during onboarding.

Should we onboard every possible framework at the start?

Usually not. Begin with frameworks tied to active clients, delivery commitments, pipeline, or regulatory priorities, then add secondary frameworks after the shared control and evidence workflow is working.

Should we roll GetCybr out to every client at once?

A phased rollout is normally easier to govern and improve. Start with one client segment, service model, or high-priority use case, learn from it, and standardise the workflow before expanding.

Can prospective partners run a trial or pilot?

A structured, limited-scope pilot may be available to qualified MSP and consultancy partners. Eligibility and current terms should be confirmed with GetCybr before planning a rollout.

Frameworks and evidence

Can controls and evidence be mapped across frameworks?

Yes. Shared controls can connect evidence to requirements in more than one framework, reducing repeated work. Mapping does not remove each framework’s distinct language, scope, review expectations, or evidence nuances.

Can teams add a custom compliance framework?

GetCybr can support custom controls, evidence requirements, and assessment criteria alongside its framework catalog. Check the current package and implementation requirements before committing to a bespoke framework.

How does evidence collection work in GetCybr?

Teams can organise evidence against controls and use supported connections or existing records as sources. Define ownership, refresh cadence, and acceptance criteria so collection supports remediation and reporting rather than becoming an audit-only document store.

Is evidence collection only useful during an audit?

No. Regular evidence review can support governance, stale-control detection, remediation tracking, and client reporting throughout the year, with additional audit-specific work when required.

Must every evidence source be connected before rollout?

No. Start with a small set of dependable, high-value sources, assign owners, and establish a sustainable review cadence. Expand connections after the core workflow is stable.

Which compliance frameworks does GetCybr support?

GetCybr supports multiple global, national, regional, and sector frameworks rather than a single standard. Because coverage and packaging can evolve, use the framework catalog for the current list and validate client-specific scope during onboarding.

Reporting, integrations, and TPRM

How does GetCybr integrate with existing tools?

Supported connectors bring relevant posture, evidence, and workflow data into GetCybr through secure connection methods such as APIs and delegated authentication. Connector availability, authentication, and package requirements vary, and teams can discuss additional integration needs.

Should every client report use the same metrics?

Keep a consistent core structure so reports are repeatable and comparable, then add client-specific measures only where they support the audience, agreed service scope, risks, or decisions.

How often should clients receive reports?

Choose a cadence the delivery team can sustain. Monthly reporting often suits active remediation, quarterly reporting can support strategic governance, and incidents, audits, or escalations may require additional updates.

What third-party risk management capabilities are available?

GetCybr supports vendor questionnaires, configurable requirements, risk scoring from available responses and signals, ongoing review, and client reporting. TPRM is part of the Comply workflow; confirm current product packaging on the pricing page.

Multi-client delivery and branding

How does GetCybr support multiple client organisations?

Its multi-client architecture provides portfolio-level management while keeping each client’s data, access, frameworks, and reporting within that client’s environment. Practical capacity depends on service complexity and team processes.

Can service providers deliver reports under their own brand?

White-label options can support branded reports and client-facing delivery. Availability depends on the selected package and branding requirements, so verify the current scope before promising it to clients.

Deployment and data residency

Can GetCybr support clients with data residency requirements?

In many cases, but the required hosting, processing, transfer, and access boundaries must be confirmed before rollout. Validate the proposed setup with the client’s security, privacy, legal, or compliance owners rather than treating product guidance as legal advice.

What cloud and self-hosted deployment options are available?

GetCybr offers cloud delivery and can support sovereign self-hosted deployment for qualifying Enterprise requirements, including local-model scenarios. Exact architecture, data flows, support, and package scope should be confirmed for the intended environment.

Which countries and regions can use GetCybr?

GetCybr is designed for teams serving clients across multiple geographies, not just one country. Suitability depends on the client base, deployment model, contractual terms, data handling, applicable frameworks, and available commercial support.

Pricing and practitioner services

Does GetCybr pricing include a human vCISO practitioner?

GetCybr Comply is platform software only; the human vCISO is supplied and priced separately. Practitioner fees are contracted and paid separately from GetCybr platform fees.

How is GetCybr packaged and priced?

GetCybr publishes Standard product and add-on rates in the public pricing builder. Enterprise is Talk to us because broader deployment, integration, development, training, support, or sovereignty needs require scoping.

Cost calculator

What does the public Standard pricing builder calculate?

The public Standard pricing builder shows product costs immediately without requesting contact details. After an estimate is emailed, it also reveals an emailed client-engagement business case with average GetCybr cost per client engagement per month, revenue after GetCybr fees per client engagement per month, and return on GetCybr spend.

Which inputs change the Standard estimate?

Monitor, Audit, and Comply quantities are pooled for volume discounts; billing cadence and Brand or Connect add-ons also change the estimate. Expected monthly revenue per client engagement changes only the client-engagement business case.

How does the builder calculate annual pricing?

Monthly pricing applies the active pooled volume discount to current Standard catalog rates. Annual prepay applies the current catalog discount to products and selected add-ons, and monthly figures are shown as effective estimates.

Which GetCybr costs are included in the builder?

The builder uses current public Standard rates for selected products and add-ons. Enterprise is Talk to us and does not show a self-service amount or client-engagement business-case result.

What commercial assumption is used in the client-engagement business case?

The client-engagement business case uses the expected monthly revenue per client engagement supplied for the emailed estimate. It is a planning assumption, not a required resale price, quote, or earnings forecast.

What happens to contact details entered for an emailed estimate?

No contact details are needed to use the public builder. When an estimate is requested, the supplied full name, work email, and business type are used to verify eligibility and deliver the estimate. Review the current privacy notice for full handling details.

What does the client-engagement business case exclude?

A client entered under more than one product counts once in each quantity, so the denominator is client engagements rather than unique clients. Delivery labour, overhead, tooling, tax, sales costs, and other operating expenses are excluded from revenue after GetCybr fees per client engagement and return on GetCybr spend. The remainder is not profit.

Insurance readiness

How does GetCybr’s Insurance Readiness service work?

GetCybr can surface control posture and readiness gaps and introduce suitable clients to New Dawn Risk. GetCybr is an introducer, not an insurance adviser, broker, or policy provider; New Dawn Risk handles regulated advice and placement, including discussions about new cover or an independent review of existing cover. Outcomes depend on the client and insurer.

Platform comparisons

How should an MSP choose a vCISO platform?

Start with the operating model: client separation, portfolio workflows, framework and evidence needs, reporting, branding, integrations, deployment, support, and total delivery cost. Validate each vendor against your actual client volume and requirements; comparison pages provide current product-specific detail.

Need a deeper answer?

Book a demo to see how GetCybr handles frameworks, evidence, and client reporting in practice.