Everything you need to run a world-class InfoSec programme
Maiky connects every component of GRC into one platform, from framework selection to automated evidence collection and public Trust Center.
A living risk register, not a static spreadsheet
Maiky replaces your risk spreadsheet with a dynamic register that stays in sync with your controls, policies, and supplier landscape. Risks are assessed on a customisable risk matrix and re-evaluated when linked objects change.
- Multiple risk registers per domain (InfoSec, AI, Privacy, Operational)
- Visual risk matrix with colour zones
- Risks linked directly to controls, policies, processes, and suppliers
- Inherent vs. residual risk scoring with treatment tracking
- Coverage percentage and maturity scoring per risk domain
- Automatic review triggers when risk landscape changes
- Bulk risk import from existing spreadsheets
End-to-end policy and controls management
Empower your organisation to create, manage, distribute, and monitor internal policies and controls. Maiky supports full lifecycle management from authoring to periodic review with complete traceability.
- A full library of your InfoSec policies
- Direct policy-to-control linkage per framework
- Version history and controlled review workflow
- Policy approval and sign-off tracking
- Publish policies directly to your Trust Center
- Full-text search across your entire policy library
- Multi-language versions available
The use of AI systems within the organization requires prior approval. The process covers the request, a risk assessment (section 6), registration in the AI register and a security & privacy review by the CISO and DPO.
All major standards and frameworks in one platform
Define your ISMS scope, mark controls as applicable or excluded, and track your maturity control-by-control for every framework you need to comply with simultaneously.
ISO/IEC 27001:2022
Full Annex A control set with Statement of Applicability. Map policies and evidence to each control and track implementation status to certification-readiness.
CyFun 2025 (BASIC / ESSENTIAL / IMPORTANT)
Belgium's CyberFundamentals framework at all three tiers. The GRC platform purpose-built for the Belgian market with native CyFun scoring and reporting.
NIS2 Directive
Structured control mapping for NIS2 obligation domains. Built-in incident reporting workflow with the 24-hour initial notification requirement pre-wired.
GDPR
Manage your Data Protection obligations alongside InfoSec controls. Link privacy policies, DPIAs, and processing records to the relevant GDPR articles.
DORA
Digital Operational Resilience Act compliance for financial sector organisations. Pre-built process templates for incident classification and resilience testing.
ISO 27017 / SOC 2
Cloud security controls (ISO 27017) and SOC 2 Trust Service Criteria. Ideal for technology companies and cloud-first organisations needing multi-standard coverage.
Stop chasing evidence and let Maiky collect it automatically
Define automated compliance checks for your critical controls. Maiky runs them on a schedule, collects evidence, evaluates results against thresholds, and creates tasks when something needs your attention.
- Schedule automated checks per control
- Evidence automatically attached to control records
- Configurable pass/fail thresholds with alerting
- Auto-create tasks when checks fail or thresholds are breached
- Audit-ready evidence trail with timestamps and results history
- Custom workflow builder for any compliance process
Internal and external audits, end-to-end
Plan, execute, and track findings from all your audits in one place. Every finding automatically creates a remediation task, and pass rates are tracked across audit cycles to show continuous improvement.
- Visual audit calendar with scheduling and reminders
- Link audits to specific controls and frameworks
- Finding management with severity classification
- Automated corrective action tasks from findings
- Pass rate tracking and trend analysis across cycles
- Support for both internal and third-party auditors
NIS2-compliant incident response, built in
When a security incident happens, Maiky guides your team through structured response phases while automatically tracking SLAs including the NIS2 24-hour notification requirement.
- Structured 5-phase incident lifecycle (Investigate → Contain → Eradicate → Recover → Post-incident review)
- NIS2 24-hour notification SLA built-in with countdown timer
- Link incidents to processes, risks, and controls
- Severity classification with escalation logic
- Automated incident reports for regulators and management
- Post-incident review integration
Your suppliers are part of your security perimeter
Maintain a complete supplier register, send compliance questionnaires, and link each supplier to the controls and risks they affect. Know your third-party risk posture at a glance.
- Centralised supplier and vendor register
- Compliance questionnaire templates and sending workflow
- Supplier-to-control and supplier-to-risk linkage
- Risk scoring per supplier based on responses
- Review cycle management with automated reminders
- Contract and DPA document storage per supplier
Show the world you take security seriously
Your public Trust Center is the fastest way to answer "do you have an ISO certificate?" and "can I see your security policies?" Publish documents, certifications, and a live security controls overview, all with a few clicks.
- Public URL customisable to your domain
- One-click publication of approved policies and documents
- Certification showcase
- Live security controls overview widget
- Branded with your company logo and name
- Qualified access requests for NDA-gated documents
How we protect your data: certifications, controls and documents.
Know exactly what you are protecting
You cannot secure what you cannot see. Maiky gives you a living asset inventory, hardware, software, SaaS, data and people, each classified by sensitivity and linked to the risks, controls and processes that depend on it.
- Centralised inventory of hardware, software, SaaS, data and information assets
- CIA classification (confidentiality, integrity, availability) per asset
- Clear asset ownership and review responsibility
- Assets linked to risks, controls, processes and suppliers
- Bulk import from spreadsheets, MDM and discovery tools
- Review reminders so your inventory never goes stale
Map the business processes your security depends on
Compliance is about protecting what the business actually does. Maiky lets you document your critical business processes, rate their impact, and connect each one to the assets, risks and controls that keep it running: the foundation of a real business impact analysis.
- Document business and operational processes in one register
- Rate criticality and business impact
- Link processes to assets, risks, controls and suppliers
- Capture RTO and RPO for continuity planning
- See the blast radius of any risk across your processes
- Coverage and maturity scoring per process
Measure how far you are, and prove you are improving
Maiky scores your maturity control-by-control and rolls it up per framework domain, so you always know where you stand against your target level. Track progress over time and walk into any board meeting or audit with the numbers to back you up.
- Maturity scoring per control, rolled up by framework domain
- Set target maturity levels and measure the gap
- CyFun-style level scoring built in
- Trend tracking that shows improvement quarter over quarter
- Benchmark multiple frameworks from a single assessment
- Board-ready maturity reports in a few clicks
One task list. Every compliance action.
Tasks in Maiky are automatically created from automation failures, audit findings, risk reviews, and incident response steps. See everything that needs your attention in one inbox and with ITSM integration built in.
Auto-generated tasks
When an automation check fails, an audit finding is raised, or a risk review is due, Maiky creates a task automatically, no manual tracking needed.
ITSM integration
Push Maiky tasks straight into your ITSM or ticketing tool. Teams act on compliance work from the tools they already use, and nothing gets lost between systems.
Due date reminders
Set deadlines and get notified before they slip. Overdue tasks surface on the dashboard so nothing falls through the cracks during a busy audit period.
Ready to replace your GRC spreadsheets?
Book a 30-minute demo and see every feature live against your own compliance requirements.