myCREST - Analisi del rischio ISO/IEC 27001 e NIS2 | Rexilience
Coming soon myCREST is free for the first year for the first companies and consultants to join now.
ISO/IEC 27001 Risk Analysis · NIS2 Compliance

The audit doesn’t ask whether you’ve carried out a risk analysis. It asks you to prove that you have.

myCREST is Rexilience’s platform that takes your risk analysis from assets to the Statement of Applicability in accordance with the ISO/IEC 27005 standard. A method that stands up to audit, without the need for a dedicated team.

Secure login · Isolated and encrypted data · European platform

app.mycrest.is/dashboard
Dashboard myCREST con KPI e attività
Actual screenshot: Dashboard showing analytics, tasks and deadlines
The problem

You already know how it should be done. The problem is actually doing it – and being able to prove it.

You’ve got NIS2 on your desk and the deadline is fast approaching. You need to produce a compliant risk analysis, but resources are what they are: often it’s just you, with a small IT team and no dedicated compliance function. So the analysis ends up where it always does – in a spreadsheet. Risk scales that change from one year to the next, threats identified off the top of your head, the Statement of Applicability updated by hand, and no record of who decided what and why.

Then comes the audit – or worse, an incident. And the question isn’t ‘have you done a good job?’, it’s ‘can you prove it?’. Your real aim isn’t to become the ultimate expert on ISO 27005. It’s to have the process under control and not be caught out when it really matters.

A method that doesn’t exist

Every analysis starts from scratch, with no workflow and no status tracking.

Decisions that vanish

Who accepted that risk, when, and on what grounds? No trace of it in the audit.

Fragile compliance

Threats and vulnerabilities mapped on a case-by-case basis, far removed from the ISO/IEC 27005 standard.

The solution

myCREST provides the methodology. You remain in control.

myCREST guides you through each assessment along a structured and compliant process: define the primary assets, map threats and vulnerabilities to supporting assets, calculate the risk, plan the mitigation measures and generate the Statement of Applicability. Every step is tracked, every decision is documented. You don’t need a dedicated team to work rigorously, and when the audit comes around, you’ll already have everything in order.

app.mycrest.is/analisi/nuova
Wizard guidato con criteri di valutazione del rischio
Actual screenshot missingscreenshots/02-wizard-criteri.png
Actual screenshot: step-by-step wizard with configurable scales and criteria
Who is myCREST for?

Designed for those who actually carry out risk analysis.

Whether you need to secure your own business or that of your clients, myCREST is built around your work.

🛡️

In-house teams

CISO · IT Manager · Security Managers

Do you want to achieve ISO/IEC 27001 certification, or are you subject to NIS2 and need to produce and maintain your risk analysis using the resources you have? myCREST provides you with a repeatable process, a dashboard that shows you what’s missing, and documentation ready to present to the auditor. Less time spent on Excel spreadsheets, more control over your decisions.

🤝

Consultants and advisory firms

Consultancy firms and firms

You manage multiple clients and currently do the same work in separate spreadsheets, one per company. With myCREST, you manage each client in their own isolated space (multi-tenant), reuse the same structured catalogue, and share read-only analyses for review and comparison, without anyone altering the data. The same method, applied to all clients.

How it works

From configuration to SOA, in a guided workflow.

1

Map your assets

Distinguish between business processes and information services in accordance with the ISO/IEC 27005 standard, using categories, statuses and a visual map of relationships. Bulk CSV import to populate the inventory in a single operation.

app.mycrest.is/risorse/relazioni
Relazioni tra asset primari e di supporto
Actual screenshot missingscreenshots/03-asset-relationships.png
Actual screenshot: relationships between business processes and IT services
app.mycrest.is/analisi/editor
Editor a griglia degli elementi di rischio
Actual screenshot: grid editor with calculated R/I/D scores
2

Assess the risk

A step-by-step wizard with scales that can be tailored to your organisation. Map threats and vulnerabilities from the ISO/IEC 27005 and ENISA catalogues (146 threats, 82 vulnerabilities), calculate the risk to Confidentiality, Integrity and Availability, and manage residual risk through risk treatments and explicit acceptance.

3

Process, approve and generate the SOA

Treatment plans with a responsible person and deadline, formal approval that unlocks the closure of the analysis, and a Statement of Applicability with the ‘Included’ and ‘Implemented’ flags managed separately. Export everything to a neatly organised Excel file.

app.mycrest.is/analisi/soa
Dichiarazione di Applicabilità con flag Incluso e Implementato
Actual screenshot: SoA with separate ‘Included’ and ‘Implemented’ flags
Key features

Everything you need for an audit-ready analysis.

📚

ISO/IEC 27005 and ENISA catalogue

Structured threats and vulnerabilities, in Italian and English, with customisable filters and entries per tenant.

🔄

5-stage workflow

Draft, In Progress, Completed, Archived, Invalidated. Every transition is tracked.

Data processing plan with approval

Actions, responsible parties, deadlines and mandatory approval note prior to closure.

📉

Residual risk under control

Calculation by C/I/D axis, configurable thresholds, informed and explicit acceptance.

⚠️

Automatic analysis invalidation

If an asset involved changes, myCREST alerts you that the results need to be reviewed.

📊

Role-based dashboard

Tasks to complete, upcoming deadlines, profile status. Tailored to the viewer.

🏢

Multi-tenant and multi-user

Each company in its own space, with isolated and encrypted data.

🇪🇺

Data in Europe

European platform, GDPR-compliant by design.

📥

Data import and export

Bulk CSV import of resources and organised export to Excel.

Roles

Everyone sees what they need to see, and nothing more.

myCREST assigns permissions and dedicated dashboards based on role, so work stays organised and data remains secure.

Risk Owner

The security manager

Creates and manages analyses, assets and treatment plans. Approves the plan and closes the analysis.

Customer Admin

The contract contact

Manages users, the organisation profile and tenant configurations. No access to analyses.

Basic User

Consultant or auditor

Has read-only access to the analyses to which they are invited, with no risk of altering the data.

app.mycrest.is/dashboard
Dashboard del Risk Owner con scadenze delle prossime analisi
Actual screenshot: the Risk Owner’s dashboard showing the deadlines for upcoming analyses
Why myCREST

More than just a spreadsheet. Built around the standard.

An Excel template just gets you to enter numbers. myCREST gets you to follow a method. It maps threats and vulnerabilities to the correct level in accordance with ISO/IEC 27005, enforces a workflow that prevents you from closing an analysis with unmanaged risks, retains the history of every decision and provides you with defensible documentation. It’s the difference between ‘we’ve carried out the risk analysis’ and ‘we can demonstrate exactly how we did it’. Built by people who provide cyber and compliance consultancy every day, with data hosted in Europe.

app.mycrest.is/mappa-asset
Mappa delle associazioni ISO/IEC 27005 tra asset, vulnerabilità e minacce
Actual screenshot: the graph showing the relationships between assets, vulnerabilities and threats in accordance with ISO/IEC 27005
Launch offer

myCREST is launching. Sign up now.

Free for the first yearfor the first companies and advisers to join the launch phase

We’re opening up myCREST to an initial group of companies and consultants. Use the platform with your real data and integrate it into your workflow, with no obligation. Your data remains isolated, encrypted and accessible only to you.

Request access

Would you like a compliant, repeatable and audit-ready risk analysis?

Sign up, and the Rexilience team will approve your access and send you instructions on how to get started.

Do you have any questions? Please email us at crest@rexilience.eu

myCREST registration

To use myCREST, you must register by filling out the following form.
Upon completion of registration you must wait for approval by the Rexilience team.

Once your registration is confirmed, you will receive instructions for logging in via email.

Contact us

If you need further information about our services, please fill in the form below. We will get back to you as soon as possible.