The audit doesn’t ask whether you’ve carried out a risk analysis. It asks you to prove that you have.
myCREST is Rexilience’s platform that takes your risk analysis from assets to the Statement of Applicability in accordance with the ISO/IEC 27005 standard. A method that stands up to audit, without the need for a dedicated team.
Secure login · Isolated and encrypted data · European platform
You already know how it should be done. The problem is actually doing it – and being able to prove it.
You’ve got NIS2 on your desk and the deadline is fast approaching. You need to produce a compliant risk analysis, but resources are what they are: often it’s just you, with a small IT team and no dedicated compliance function. So the analysis ends up where it always does – in a spreadsheet. Risk scales that change from one year to the next, threats identified off the top of your head, the Statement of Applicability updated by hand, and no record of who decided what and why.
Then comes the audit – or worse, an incident. And the question isn’t ‘have you done a good job?’, it’s ‘can you prove it?’. Your real aim isn’t to become the ultimate expert on ISO 27005. It’s to have the process under control and not be caught out when it really matters.
A method that doesn’t exist
Every analysis starts from scratch, with no workflow and no status tracking.
Decisions that vanish
Who accepted that risk, when, and on what grounds? No trace of it in the audit.
Fragile compliance
Threats and vulnerabilities mapped on a case-by-case basis, far removed from the ISO/IEC 27005 standard.
myCREST provides the methodology. You remain in control.
myCREST guides you through each assessment along a structured and compliant process: define the primary assets, map threats and vulnerabilities to supporting assets, calculate the risk, plan the mitigation measures and generate the Statement of Applicability. Every step is tracked, every decision is documented. You don’t need a dedicated team to work rigorously, and when the audit comes around, you’ll already have everything in order.
screenshots/02-wizard-criteri.pngDesigned for those who actually carry out risk analysis.
Whether you need to secure your own business or that of your clients, myCREST is built around your work.
In-house teams
CISO · IT Manager · Security Managers
Do you want to achieve ISO/IEC 27001 certification, or are you subject to NIS2 and need to produce and maintain your risk analysis using the resources you have? myCREST provides you with a repeatable process, a dashboard that shows you what’s missing, and documentation ready to present to the auditor. Less time spent on Excel spreadsheets, more control over your decisions.
Consultants and advisory firms
Consultancy firms and firms
You manage multiple clients and currently do the same work in separate spreadsheets, one per company. With myCREST, you manage each client in their own isolated space (multi-tenant), reuse the same structured catalogue, and share read-only analyses for review and comparison, without anyone altering the data. The same method, applied to all clients.
From configuration to SOA, in a guided workflow.
Map your assets
Distinguish between business processes and information services in accordance with the ISO/IEC 27005 standard, using categories, statuses and a visual map of relationships. Bulk CSV import to populate the inventory in a single operation.
screenshots/03-asset-relationships.pngAssess the risk
A step-by-step wizard with scales that can be tailored to your organisation. Map threats and vulnerabilities from the ISO/IEC 27005 and ENISA catalogues (146 threats, 82 vulnerabilities), calculate the risk to Confidentiality, Integrity and Availability, and manage residual risk through risk treatments and explicit acceptance.
Process, approve and generate the SOA
Treatment plans with a responsible person and deadline, formal approval that unlocks the closure of the analysis, and a Statement of Applicability with the ‘Included’ and ‘Implemented’ flags managed separately. Export everything to a neatly organised Excel file.
Everything you need for an audit-ready analysis.
ISO/IEC 27005 and ENISA catalogue
Structured threats and vulnerabilities, in Italian and English, with customisable filters and entries per tenant.
5-stage workflow
Draft, In Progress, Completed, Archived, Invalidated. Every transition is tracked.
Data processing plan with approval
Actions, responsible parties, deadlines and mandatory approval note prior to closure.
Residual risk under control
Calculation by C/I/D axis, configurable thresholds, informed and explicit acceptance.
Automatic analysis invalidation
If an asset involved changes, myCREST alerts you that the results need to be reviewed.
Role-based dashboard
Tasks to complete, upcoming deadlines, profile status. Tailored to the viewer.
Multi-tenant and multi-user
Each company in its own space, with isolated and encrypted data.
Data in Europe
European platform, GDPR-compliant by design.
Data import and export
Bulk CSV import of resources and organised export to Excel.
Everyone sees what they need to see, and nothing more.
myCREST assigns permissions and dedicated dashboards based on role, so work stays organised and data remains secure.
The security manager
Creates and manages analyses, assets and treatment plans. Approves the plan and closes the analysis.
The contract contact
Manages users, the organisation profile and tenant configurations. No access to analyses.
Consultant or auditor
Has read-only access to the analyses to which they are invited, with no risk of altering the data.
More than just a spreadsheet. Built around the standard.
An Excel template just gets you to enter numbers. myCREST gets you to follow a method. It maps threats and vulnerabilities to the correct level in accordance with ISO/IEC 27005, enforces a workflow that prevents you from closing an analysis with unmanaged risks, retains the history of every decision and provides you with defensible documentation. It’s the difference between ‘we’ve carried out the risk analysis’ and ‘we can demonstrate exactly how we did it’. Built by people who provide cyber and compliance consultancy every day, with data hosted in Europe.
myCREST is launching. Sign up now.
We’re opening up myCREST to an initial group of companies and consultants. Use the platform with your real data and integrate it into your workflow, with no obligation. Your data remains isolated, encrypted and accessible only to you.
Would you like a compliant, repeatable and audit-ready risk analysis?
Sign up, and the Rexilience team will approve your access and send you instructions on how to get started.
Do you have any questions? Please email us at crest@rexilience.eu