The security program platform for CISOs

Run your whole security program All in one place

DeputySec brings maturity assessments, risk management, controls, assets, vendors, issues, tasks and policies together — so you can measure where you stand and drive the program forward from a single source of truth.

NIST CSF & CRA templates 5-level maturity scoring Shareable public assessments Board-ready reports

Measure. Prioritize. Improve.

DeputySec turns a scattered security program into one continuous loop — from knowing where you stand to closing the gaps.

Measure your maturity

Run maturity assessments against NIST CSF, the CRA model, or your own framework, and get a clear 1–5 score per domain.

Prioritize the real risks

Turn findings into tracked threats and risks on a live heatmap, so the biggest exposures rise to the top.

Drive remediation

Plan the work on a roadmap and push it to owners as controls, issues and tasks until the score moves.

One platform for the whole program

Nine connected modules replace a folder of spreadsheets — everything shares the same source of truth.

Core

Assessments & Maturity

Build or import questionnaires, score maturity, and share board-ready reports with radar, line and heatmap views.

  • NIST CSF & CRA templates
  • Per-option scoring & coverage
  • Public shareable assessments

Security Roadmap

Plan initiatives over time on a Gantt-style roadmap and keep everyone aligned on what's next.

  • Timeline & milestones
  • Tied to risks and tasks

Threats & Risks

Maintain a living risk register with likelihood × impact scoring and a colour-coded heatmap.

  • Threat & risk register
  • Interactive heatmap
  • Mitigations & owners

Controls

Track your control catalogue, log testing, and see coverage and effectiveness at a glance.

  • Control catalogue
  • Testing log & trend

Assets

Keep an inventory of the systems and data that matter, and link them to the risks that threaten them.

  • Asset inventory
  • Linked to risks

Vendors

Manage third parties and their risk, so supply-chain exposure never slips through the cracks.

  • Vendor register
  • Third-party risk

Issues

Capture security issues — flagged straight from an assessment — and manage them to closure.

  • Flag from assessments
  • Aging & status

Tasks

Assign remediation work with owners and due dates, and watch the workload across the team.

  • Owners & due dates
  • Workload view

Policy Management

Author and version policies with rich text, and link them to the controls and tasks they govern.

  • Rich-text policies
  • Linked to controls

Everything is connected

An assessment finding becomes a risk. That risk gets a mitigation, a roadmap slot, and a task with an owner. When the work lands, your maturity score moves — all without leaving DeputySec.

  • Flag risks and issues directly from an assessment
  • Score maturity on a 1–5 scale, rounded to the nearest level
  • Visualize progress with radar, line and heatmap charts
  • Link assets and vendors to the risks that affect them
  • Turn mitigations into roadmap initiatives and tasks
  • Share a public assessment link to generate leads
  • Export and import assessments as CSV
  • Download board-ready PDF reports

See where your security program really stands

Create an account and run your first maturity assessment in minutes — or share one publicly and start collecting results today.

9
Connected modules
2
Built-in frameworks
1–5
Maturity scoring

Frequently asked questions

The essentials about running your program on DeputySec.

DeputySec ships with NIST CSF and CRA maturity templates, and you can build your own questionnaires or import them from CSV. Scoring maps onto a 1–5 maturity scale.
Each scored question contributes points; domain and overall scores are mapped to a 1–5 scale and rounded to the nearest level, so a 4.6 reads as a 5. Optional coverage sliders let you weight partial implementation.
Yes. Any assessment can be shared as a public link. Respondents answer without signing in, see their own results, and can enter their details to get a PDF — which makes it a simple lead-generation tool.
Findings can be flagged straight into the risk register or as issues, then planned on the roadmap and pushed out as controls and tasks — so nothing gets lost between assessing and fixing.
Every assessment produces a report with radar, line and heatmap charts, and can be downloaded as a board-ready PDF.

Take control of your security program

Bring assessments, risks, controls and remediation into one place with DeputySec.