Platform Features

Everything you need to run a world-class InfoSec programme

Maiky connects every component of GRC into one platform, from framework selection to automated evidence collection and public Trust Center.

Risk Management

A living risk register, not a static spreadsheet

Maiky replaces your risk spreadsheet with a dynamic register that stays in sync with your controls, policies, and supplier landscape. Risks are assessed on a customisable risk matrix and re-evaluated when linked objects change.

  • Multiple risk registers per domain (InfoSec, AI, Privacy, Operational)
  • Visual risk matrix with colour zones
  • Risks linked directly to controls, policies, processes, and suppliers
  • Inherent vs. residual risk scoring with treatment tracking
  • Coverage percentage and maturity scoring per risk domain
  • Automatic review triggers when risk landscape changes
  • Bulk risk import from existing spreadsheets
Learn more
maiky.io/risk
Information security
Tasks View Risks
Accepted
9 / 37
Accepted risks
Mitigated
24 / 37
Mitigated risks
Unmitigated
4 / 37
Not yet mitigated
Coverage
89%
Treatment plans
Risk Matrix
Likelihood × impact ratings
Edit Matrix
Impact ▸Likeli. ▾
Negligible
Minor
Moderate
Major
Catastrophic
Rare
7
6
3
1
0
Unlikely
5
5
2
1
0
Possible
2
2
1
0
0
Likely
1
1
0
0
0
Almost certain
0
0
0
0
0
Assessment Overview
Risks requiring review
1 Require Review
Social Engineering Medium People Review 13/05/2027
Policy Management

End-to-end policy and controls management

Empower your organisation to create, manage, distribute, and monitor internal policies and controls. Maiky supports full lifecycle management from authoring to periodic review with complete traceability.

  • A full library of your InfoSec policies
  • Direct policy-to-control linkage per framework
  • Version history and controlled review workflow
  • Policy approval and sign-off tracking
  • Publish policies directly to your Trust Center
  • Full-text search across your entire policy library
  • Multi-language versions available
Learn more
maiky.io/policies
IS28 - AI Policy
+ New Policy Tasks Reminders Saved
Search +
IS29 - HR Policy
2026-07-13
IS06 - Access Control
2026-07-02
IS28 - AI Policy
2026-05-19
IS27 - Internet Use
2026-05-19
IS26 - Cloud Services
2026-05-19
Policy IS28 - AI Policy
PROPERTIES
Control AI System Approval Process
PROPERTIES

The use of AI systems within the organization requires prior approval. The process covers the request, a risk assessment (section 6), registration in the AI register and a security & privacy review by the CISO and DPO.

Risk class
High risk
Status
Active
Compliance Frameworks

All major standards and frameworks in one platform

Define your ISMS scope, mark controls as applicable or excluded, and track your maturity control-by-control for every framework you need to comply with simultaneously.

ISO/IEC 27001:2022

Full Annex A control set with Statement of Applicability. Map policies and evidence to each control and track implementation status to certification-readiness.

CyFun 2025 (BASIC / ESSENTIAL / IMPORTANT)

Belgium's CyberFundamentals framework at all three tiers. The GRC platform purpose-built for the Belgian market with native CyFun scoring and reporting.

NIS2 Directive

Structured control mapping for NIS2 obligation domains. Built-in incident reporting workflow with the 24-hour initial notification requirement pre-wired.

GDPR

Manage your Data Protection obligations alongside InfoSec controls. Link privacy policies, DPIAs, and processing records to the relevant GDPR articles.

DORA

Digital Operational Resilience Act compliance for financial sector organisations. Pre-built process templates for incident classification and resilience testing.

ISO 27017 / SOC 2

Cloud security controls (ISO 27017) and SOC 2 Trust Service Criteria. Ideal for technology companies and cloud-first organisations needing multi-standard coverage.

ISO 27001ISO 27002ISO 27017CyFun BASICCyFun ESSENTIALCyFun IMPORTANTNIS2GDPRDORASOC 2
Automation

Stop chasing evidence and let Maiky collect it automatically

Define automated compliance checks for your critical controls. Maiky runs them on a schedule, collects evidence, evaluates results against thresholds, and creates tasks when something needs your attention.

  • Schedule automated checks per control
  • Evidence automatically attached to control records
  • Configurable pass/fail thresholds with alerting
  • Auto-create tasks when checks fail or thresholds are breached
  • Audit-ready evidence trail with timestamps and results history
  • Custom workflow builder for any compliance process
Learn more
maiky.io/automation
Automation : Notifications
Saved☰ Node library
Workflow Start
Start
example request
Flow · Response
Count elements
Collection · Count
Subtract
Minuend
Subtrahend
#Threshold 3
Number
ThresholdStore
Value
Is it bigger than threshold
Value · In range
Create task
Trigger
Send email
Trigger
End
Outcome
Audits

Internal and external audits, end-to-end

Plan, execute, and track findings from all your audits in one place. Every finding automatically creates a remediation task, and pass rates are tracked across audit cycles to show continuous improvement.

  • Visual audit calendar with scheduling and reminders
  • Link audits to specific controls and frameworks
  • Finding management with severity classification
  • Automated corrective action tasks from findings
  • Pass rate tracking and trend analysis across cycles
  • Support for both internal and third-party auditors
Learn more
maiky.io/audits
Audit Programme 2026
+ New Audit
Upcoming
3
In Progress
2
Completed
24
Pass Rate
94%
Sep 2026
ISO 27001:2022 Followup Audit
Nordic Certification · 1 finding open
Upcoming
Now
SOC 2 Type II Readiness
Evidence collection · 18 / 61 controls
In Progress
Mar 2026
CyFun ESSENTIAL - Gap Assessment
31 controls assessed · 0 findings
Pass 100%
Incident Management

NIS2-compliant incident response, built in

When a security incident happens, Maiky guides your team through structured response phases while automatically tracking SLAs including the NIS2 24-hour notification requirement.

  • Structured 5-phase incident lifecycle (Investigate → Contain → Eradicate → Recover → Post-incident review)
  • NIS2 24-hour notification SLA built-in with countdown timer
  • Link incidents to processes, risks, and controls
  • Severity classification with escalation logic
  • Automated incident reports for regulators and management
  • Post-incident review integration
Learn more
maiky.io/incidents
Data exfiltration by angry employee
NIS2 major containment Reported on 19-05-2026
Tasks Reminders
Compliance Deadlines
Early Warning Deadline
20-05-2026
Final Report Deadline
18-06-2026
Progress
38%
Stage
Containment
2 of 5
Systems
Network & DB Server
Impact
Major
Response Pipeline
Investigation
Completed
Containment
67% · Active
Eradication
Pending
Recovery
Pending
Post-Incident
Pending
NIS2 Art. 23 · Early warning within 24h NIS2 Art. 23 · Final report within 1 month
Third-Party Risk

Your suppliers are part of your security perimeter

Maintain a complete supplier register, send compliance questionnaires, and link each supplier to the controls and risks they affect. Know your third-party risk posture at a glance.

  • Centralised supplier and vendor register
  • Compliance questionnaire templates and sending workflow
  • Supplier-to-control and supplier-to-risk linkage
  • Risk scoring per supplier based on responses
  • Review cycle management with automated reminders
  • Contract and DPA document storage per supplier
Learn more
maiky.io/suppliers
Suppliers + New Supplier
Total Suppliers
24
Registered vendors
Compliant
88%
21 of 24 suppliers
Review Required
3
Awaiting assessment
Supplier Register
Assessments, ownership & questionnaire status
Send Questionnaire Questionnaires
Search suppliers... + Category + Status
Name Score Status Quest.
CyberCorp
Managed Security Provider
B
Review Required
In Progress
CloudNine BV
Cloud Hosting
A
Approved
Completed
DataFlux Ltd.
Data Processor
C
Under Review
Not Sent
Trust Center

Show the world you take security seriously

Your public Trust Center is the fastest way to answer "do you have an ISO certificate?" and "can I see your security policies?" Publish documents, certifications, and a live security controls overview, all with a few clicks.

  • Public URL customisable to your domain
  • One-click publication of approved policies and documents
  • Certification showcase
  • Live security controls overview widget
  • Branded with your company logo and name
  • Qualified access requests for NDA-gated documents
Learn more
maiky.io/trustcenter
Acme Corp
Trust Center

How we protect your data: certifications, controls and documents.

30
Frameworks
4
Public Documents
2026
Last Audited
Certifications & Compliance
ISO 27001
Valid 2026 Certified
SOC 2 Type II
Valid 2026 Attested
Compliance Documents
Information Security Whitepaper Download
ISMS Statement of Applicability Request access
Asset Management

Know exactly what you are protecting

You cannot secure what you cannot see. Maiky gives you a living asset inventory, hardware, software, SaaS, data and people, each classified by sensitivity and linked to the risks, controls and processes that depend on it.

  • Centralised inventory of hardware, software, SaaS, data and information assets
  • CIA classification (confidentiality, integrity, availability) per asset
  • Clear asset ownership and review responsibility
  • Assets linked to risks, controls, processes and suppliers
  • Bulk import from spreadsheets, MDM and discovery tools
  • Review reminders so your inventory never goes stale
Learn more
maiky.io/assets
Assets
Add Asset Import Excel
Total Assets
248
Critical Assets
12
Active Assets
236
Asset Types
9
Search assets...
Type Criticality Status
AssetTypeCriticalityStatusLinks
User Endpoints
IT Manager · People
Hardware Medium Active
Customer Database
Data Officer · Cloud DB
Data High Active
Microsoft 365 Tenant
CISO · Microsoft
Cloud High Active
Payroll System
HR Lead · ADP
Software Medium Active
Legacy File Server
IT Manager · On-prem
Hardware High Retiring
Process Management

Map the business processes your security depends on

Compliance is about protecting what the business actually does. Maiky lets you document your critical business processes, rate their impact, and connect each one to the assets, risks and controls that keep it running: the foundation of a real business impact analysis.

  • Document business and operational processes in one register
  • Rate criticality and business impact
  • Link processes to assets, risks, controls and suppliers
  • Capture RTO and RPO for continuity planning
  • See the blast radius of any risk across your processes
  • Coverage and maturity scoring per process
Learn more
maiky.io/processes
Process GDPR Incident Response
Tasks Reminders
Overview Builder Runs Analytics
Process builder
Shared flow editor with BPMN-style stages and fixed start / completed boundaries.
Detection & Assessment
Incoming flow
Next stage
Supervisory Authority
Incoming flow
Next stage
Data Subject Notification
Incoming flow
Next stage
Documentation & Review
Incoming flow
Completed
Maturity Assessment

Measure how far you are, and prove you are improving

Maiky scores your maturity control-by-control and rolls it up per framework domain, so you always know where you stand against your target level. Track progress over time and walk into any board meeting or audit with the numbers to back you up.

  • Maturity scoring per control, rolled up by framework domain
  • Set target maturity levels and measure the gap
  • CyFun-style level scoring built in
  • Trend tracking that shows improvement quarter over quarter
  • Benchmark multiple frameworks from a single assessment
  • Board-ready maturity reports in a few clicks
Learn more
maiky.io/maturity
Standards Management
Track standards implementation progress
Configuration Implementation
Total Filled
9%
Answered dimensions
Avg Maturity
0.3
Score across standards
Active
4
Standards in scope
Completed
2 / 27
Categories fully scored
CyFun BASIC 2025
6 categories · 28 controls · 34 questions
draft
1.3
Implementation33%
Filled35%
Open
ISO 27001 v2022
8 categories · 152 controls · 218 questions
draft
0.0
Implementation0%
Filled0%
Open
Tasks & Reminders

One task list. Every compliance action.

Tasks in Maiky are automatically created from automation failures, audit findings, risk reviews, and incident response steps. See everything that needs your attention in one inbox and with ITSM integration built in.

Auto-generated tasks

When an automation check fails, an audit finding is raised, or a risk review is due, Maiky creates a task automatically, no manual tracking needed.

ITSM integration

Push Maiky tasks straight into your ITSM or ticketing tool. Teams act on compliance work from the tools they already use, and nothing gets lost between systems.

Due date reminders

Set deadlines and get notified before they slip. Overdue tasks surface on the dashboard so nothing falls through the cracks during a busy audit period.

Learn more
See it in action

Ready to replace your GRC spreadsheets?

Book a 30-minute demo and see every feature live against your own compliance requirements.