Recent development in Cyberday

Subscribe for our newsletter and you'll receive a digest of new product updates weekly. Newsletter also includes a list of most important cyber security news and upcoming free webinars.
Kiitos! Klikkaa vielä saamaasi vahvistuslinkkiä (sähköposti otsikolla "Vahvista sähköpostiosoitteesi") ja uutiskirje saapuu jatkossa sähköpostiisi.
Valitettavasti jotain meni pieleen. Voit olla yhteydessä tiimi@tietosuojamalli.fi.
small improvement
June 16, 2023

Summary: Cyberday content update v46

We regularly update Cyberday's content templates so that they remain in line with different security requirements and general good practices. Now it was time for the content update v46, during which we updated our documentation templates with numerous customer-wished improvements.  

Changes are mostly "small but important". This update small summaries about the most notable changes.

Extended documentation card for system providers and personal data processors

We added the following sections:

  • Does the partner belong to the supply chain of the services we offer?
  • How critical information does the partner process?
  • Ability to influence the content of the contract? (small, average, high)
  • Kuinka vaikeaa kumppanin korvaaminen on? (helppo, vaikea, mahdoton)
  • How is the partners cybersecurity level verified? (via certifications, own monitoring actions or in no way)

The changes are intended to help identify critical partners and ensure that for important partners we have sufficient evidence gathered of their information security level.

In the future, we will create more features for monitoring partners, through which you can e.g. send information security questionnaires to desired partners.

Extended documentation card for other security requirements

We improved the management of other security requirements with the following additions:

  • Connected customers
  • What measures are taken to fulfill the requirement?
  • Connected tasks
  • Connected assets in the ISMS

With the help of these additions, it is possible to more clearly document, for example, additional commitments given to individual customers or own quality requirements - and related measures and other items in the management system.

Extended documentation card for units and sites (previously offices)

Additions were made to the documentation cards of the units and sites, which will be included in the new "Organizational structure" page in the future. Through this page, you can more precisely define which units and sites your organization is made up of. Units can also be classified according to their nature (department, team, subsidiary, etc.) and into main units vs. sub-units.

New section for joint controllers on data store documentation

Important small addition on the data store documentation cards:

  • Is the processing of the data decided together with another organization?
  • If it is, the joint controller(s) in question must then be named

New optional Support-question on data systems

We added an optional question on the data system card:

  • How do users get support for using the system?

Topics related to user support can be addressed under the question.

new feature
June 9, 2023

New frameworks: NIS2 and SOC 2

We are just publishing 2 new frameworks to Cyberday! 

NIS2 sets the baseline for cybersecurity measures, supply chain security and reporting obligations across critical industries, such as energy, transport, health, food, waste, public administration and digital infrastructure.

SOC 2 specifies how organizations should protect customer data from e.g. unauthorized access, security incidents or other vulnerabilities. It is developed by the American Institute of Certified Public Accountants (AICPA) and is especially popular in the USA.

small improvement
June 9, 2023

Choose reports included in report sharing views

Previously, when sharing reports from Cyberday, the listing was formed directly based on the selected framework and "starred" reports.

Now you can also choose another way for sharing reports, where you can freely pick the reports to be included. This method also supports all report types, i.e. you can also include list or item reports you have created yourself, as well as for example visual reports.

small improvement
May 19, 2023

Internal audits by Cyberday themes

Some organizations run their own ISMS in Cyberday based on several different requirement frameworks.

In these situations, internal auditing separately for each framework can become an unnecessarily heavy process.

Now Cyberday also supports a operating method where audits can be targeted at selected Cyberday themes. In this way it is possible to audit, for example, 4 themes per year and achieve full coverage (12/12) for the internal audit of the ISMS every 3 years. 👍

small improvement
May 12, 2023

Improvements to Cyberday Academy

We're going to be investing more and more on better help and support materials, which will guide you forward in your Cyberday usage, no matter if you're just getting started, already nicely running or an advanced ISMS admin looking for continuous improvement.

To support this, we renewed the concept in Cyberday Academy a bit. All Academy content is now categorized under topics like "risk management", "ISO 27001", "personnel security" or "getting started", so you can find just the right collection of different kind of materials you need. We also added an own left menu for the Academy, so you can easily navigate to all content. Menu lists the topics, but also the different content formats - help articles, video courses and blog articles. Academy will now regularly start getting new content updates.

So choose your topic or preferred learning type, and start learning with us. 🎓

small improvement
May 12, 2023

Small improvements to embed-type reports

We improved the usability of embed-type reports (e.g. privacy notices), which are designed to be embedded into your public websites to serve customers / other stakeholders publicly.

Now e.g. the scrollbar is more clearly visible but also matches your selected theme color, so it should nicely look like a natural part of your website.

Any wishes for further improvements are highly encouraged. 👍

new feature
April 28, 2023

See upcoming frameworks and influence

Our team will start maintaining a list of upcoming new security frameworks both within Cyberday app and on the Cyberday.ai website.

As a user of Cyberday, you can influence our priorities by upvoting the frameworks that are important for you with short justifications.

Check out the current listing >>

new feature
April 21, 2023

File linking from SharePoint

You can now pick files from your SharePoint environment related to all the items in Cyberday (tasks, guidelines, documentation). These can be, for example, policy documents related to the task, process drawings describing the connections of a data system, PowerPoint instructions related to staff guidelines, or contracts related to the system provider's card.

To start using the feature, you must fill in the appropriate SharePoint site information under Organization settings in the Settings-page so we know where to retrieve the files from. 👍

small improvement
April 21, 2023

Performance improvements for various views

We work regularly to identify views that work unnecessarily slowly in Cyberday. We recently made improvements to e.g. all views listing tasks and their assurance information and the Cyber security risks table.

We are also currently developing the speed of the app's first load. Within Teams, this also affects every tab change in the application (Guidebook, Taskbook, Dashboard).

Please feel free to contact our team if you notice points that repeatedly work too "calmly". 👍

small improvement
April 21, 2023

Better saving of used sortings and filters in tasks tables

When you work e.g. on the framework tasks table, we now better remember the selected filters and sortings you have chosen. When you navigate from a table to a task and back, you can continue directly from the same view.

The same now works better also better on the general Tasks-page.

small improvement
March 17, 2023

Data visible in printable reports expanded

When you create a report of a single documentation item (e.g. audit), we now show more extensive information on the objects linked to it in the report.

With this, for example, a final report of an internal audit can be archived, and this one document contains e.g. more detailed information on detected non-conformities and the related improvements made.

new feature
February 10, 2023

Creating internal audit reports

You can now create a one-time audit report for the defined audit scope (e.g. selected chapters of ISO 27001 standard or any other framework).

This report will help the auditor clearly see the implementation info for each requirement track he's progress - which sections he has already reviewed and which not. Non-conformities can be directly created from the audit report and they will all be summarized automatically on the audit documentation card.

small improvement
February 3, 2023

Deactivate a user - re-assign content later

Now you can also disable a user ID in the user management. This works well if, for example, a user in your core team has changed jobs, but there is no replacing person recruited yet. In this situation you can remove access rights, but still understand which contents are assigned to the user who has already been deactivated.

Re-assigning content works in identical way also for previously deactivated users.

new feature
January 27, 2023

Coming up: Community-section in Cyberday

We're building a new Community-section to Cyberday, which will enable you to easily ask help from us, collaborate with your peers from similar roles / organizations and get ideas for your work from other community content!

Left menu will get a new Community-section, where everyone will a Support forum and Cyber news feed.

In addition you can customize the community for your personal preferences by joining collaboration groups that interest you the most. We're going to be first publishing some open groups and later expand this to also semi-open and closed collaboration. Collaboration groups will have their own forum section and some news will be shared directly into certain collaboration groups.

All participation on the Community-section will be possible either publicly (with your user profile) or anonymously. All content will also be connected to requirements from frameworks or sections in Cyberday, so discussions get structure and content can later on be displayed on other parts of the app also.

Our goal in this development is to enable sharing best practices and make sure you're never alone while using Cyberday. More info coming up soon. 👍

small improvement
January 20, 2023

"Login with Microsoft" on web UI

You can now also use your own Microsoft 365 credentials to log in to our browser interface.