# BCyber — Australian Cybersecurity & GRC Services > BCyber Pty Ltd (ABN 67 624 307 124) is an Australian-owned cybersecurity company that helps organisations solve governance, resilience, assurance, compliance, and education challenges through the GRACE framework. We combine expert consulting services with 9 integrated AI-powered platforms. ## About BCyber - Founded by Graham Chee (Co-Founder & MD) and Karen Stephens (Co-Founder & CEO) - Based in Mascot, NSW 2020, Australia - 2025 GRC Provider of the Year — Finalist - 35+ years combined cybersecurity experience - Specialises in Australian regulatory frameworks: APRA CPS 234, Essential Eight, SOCI Act, Privacy Act, ASIC REP 798, AICD Cyber Governance Principles ## How We Help (Services) - [Cyber Policy Development](https://bcyber.com.au/how-we-help/policies): Living policy suites tailored to Australian regulations. 50+ templates, automated lifecycle management. - [Process Design & Automation](https://bcyber.com.au/how-we-help/processes): Replace spreadsheet-driven security processes with automated cyber workflows. - [Project Delivery & Implementation](https://bcyber.com.au/how-we-help/projects): End-to-end delivery of Essential Eight uplift, ISMS implementation, security tool deployment. - [Cybersecurity Education & Awareness](https://bcyber.com.au/how-we-help/education): Role-specific training from board directors to frontline staff, with behavioural profiling. - [Tabletop Exercises & Crisis Simulation](https://bcyber.com.au/how-we-help/tabletop): 500+ MITRE ATT&CK scenarios for ransomware, data breach, supply-chain, and insider threat testing. - [Boardroom Readiness & Executive Reporting](https://bcyber.com.au/how-we-help/boardroom): Director liability protection with dashboards, AICD-aligned briefings, and ASIC REP 798 compliance. - [Cyber Due Diligence](https://bcyber.com.au/how-we-help/due-diligence): Evidence-based M&A cyber risk assessment with quantified exposure and remediation cost estimates. ## Platforms (Products) - [GRACE Portal](https://bcyber.com.au/products/grace): Unified cybersecurity command centre — policy, risk, compliance, and reporting. - [Paradigm](https://bcyber.com.au/products/paradigm): AI self-learning GRC platform with 15+ framework mapping. - [Profiler](https://bcyber.com.au/products/profiler): Behavioural intelligence — 15+ cybersecurity archetypes and phishing susceptibility. - [TopSpin](https://bcyber.com.au/products/topspin): 7-year cybersecurity storage forecasting and cost optimisation. - [Triage](https://bcyber.com.au/products/triage): Incident response acceleration with NIST CSF and MITRE ATT&CK playbooks. - [Perfect Storm](https://bcyber.com.au/products/perfect-storm): Scenario intelligence — 500+ AI-enhanced threat scenarios. - [Privacy in Depth](https://bcyber.com.au/products/privacy-in-depth): Privacy impact assessments, breach response, and compliance audits. - [Cyber Fitness](https://bcyber.com.au/products/cyber-fitness): 20+ industry-tailored cybersecurity training programs. - [DeepRed](https://bcyber.com.au/products/deepred): Adversarial security validation — continuous red-team testing mapped to MITRE ATT&CK. ## Key Pages - [How We Help (Overview)](https://bcyber.com.au/how-we-help) - [All Platforms](https://bcyber.com.au/products) - [Virtual Agents](https://bcyber.com.au/virtual-agents): Seven autonomous AI cybersecurity specialists — Sentinel (vCISO), Shield (Compliance), Pulse (Risk), Forge (Policy), Spark (Education), Scout (Due Diligence), Compass (Strategy). VA-2a Explainability: each agent explains what it does in plain English, shows its reasoning transparently, collaborates with the team, and adapts to user personality. VA-2b Autonomous Activities: agents perform real data analysis, log findings with confidence scores, flag items for human review, and surface activity feeds in admin and client portals. Psychometrically calibrated, tenant-isolated, GRACE-aligned. - [Pricing](https://bcyber.com.au/pricing): Foundations $12,000/yr, Momentum $36,000/yr, Enterprise from $90,000/yr - [Get Started Free](https://bcyber.com.au/get-started): Conversational cyber readiness assessment with instant AI-generated posture score, personalised recommendations, and one-click portal activation - [Virtual Mentor](https://learn.bcyber.com.au/mentor): Succession planning instrument — Graham's brain, distributed across three role-aware modes. Advocate mode (anonymous/public visitors): promotes BCyber differentiators, suggests Free Health Check and Get Started CTAs. Operator mode (admin/super_admin staff): teaches full platform operations, workflows, staff/role/client management. Coach mode (clients/company_staff): teaches allocated modules, portal navigation, self-sufficiency. Auto-introspects 7 Virtual Agents, Knowledge Hub entries, Market Intelligence, admin navigation. Transparency Panel: users can see exactly what the mentor knows about them — active role, mode, knowledge packs loaded, live data sources, and context signals. Voice-enabled with speed control, AI avatar, Discover→Understand→Apply→Master CX methodology, progress tracking. - [Free Posture Score](https://bcyber.com.au/posture-score): 10-question GRACE self-assessment - [Stack Calculator](https://bcyber.com.au/stack-calculator): TCO comparison tool - [AI Cyber Security Maturity Index](https://bcyber.com.au/ai-maturity): Evidence-driven AI cyber maturity across 5 levels and 5 dimensions - the upside of getting it right and the risk of getting it wrong - [Blog & Resources](https://bcyber.com.au/blog) - [About Us](https://bcyber.com.au/about) - [Contact](https://bcyber.com.au/contact) ## Framework Knowledge Hub BCyber maintains a centralised Framework & Standards Registry — a single source of truth for all compliance frameworks referenced across the platform: - Each framework is enriched with: purpose, key requirements, applicable industries, organisation sizes, penalties, effective dates, review cycles, official URLs, and Australian context - Interactive FrameworkBadge components across admin/portal/presentation pages let users click any framework reference to see rich knowledge popovers - Key Australian frameworks covered: Essential Eight, APRA CPS 234/230, Privacy Act 1988 (incl. APP 1.7-1.9 ADM), SOCI Act, ASIC REP 798, AICD, ACSC ISM, IRAP, PSPF, NDB, AESCSF, DISP - International standards: ISO 27001, ISO 27002, NIST CSF, NIST 800-53/171/207/82/61/63, SOC 2, PCI DSS, GDPR, COBIT, ITIL 4, MITRE ATT&CK/D3FEND, CIS Controls v8, OWASP suite, IEC 62443, CMMC, FedRAMP, DORA, NIS 2, SWIFT CSP, TISAX, HIPAA, HITRUST - AI governance frameworks: ISO 42001:2023 (AI Management), NIST AI RMF 1.0, EU AI Act (Reg 2024/1689), OCEG IAIP ALIGN, Australia's 8 AI Ethics Principles, APS AI Policy v2.0, Australian Guidance for AI Adoption (GfAA), National Framework for Assurance of AI in Government, ASIC REP 798 AI Governance, Privacy Act APP 1.7-1.9 (ADM transparency) - API endpoint: /api/frameworks (public, supports compact mode for tooltips and single/batch/all queries) - Admin management: /admin/frameworks with three-tab editor (Details, Knowledge, Mapping) - AI-powered expansion: per-framework AI Enrich button + bulk "AI Enrich N empty" using LLM (gpt-5.4-nano) to consistently generate framework knowledge in the same structured shape as manual seeds. Idempotent — preserves manual edits unless force-overwritten. Available at /admin/frameworks (admin only). ## GRACE Framework The GRACE framework is BCyber's proprietary approach to cybersecurity: - **G**overnance — Policies, risk management, board reporting - **R**esilience — Incident response, crisis simulation, business continuity - **A**ssurance — Security validation, red teaming, due diligence - **C**ompliance — Framework mapping, evidence automation, audit readiness - **E**ducation — Training, awareness, behavioural profiling ## GRACE AI Index — AI Governance Maturity Metric The GRACE AI Index is BCyber's proprietary evidence-driven AI governance maturity scoring system — "the credit score for AI governance." - Five dimensions: Govern, Map, Measure, Manage, Australian Context - Living maturity score (Level 1 Ad Hoc → Level 5 Optimised), not a point-in-time questionnaire - Evidence-based: ingests policies, processes, controls, and audit artefacts continuously - Board-level metric: converts intangible AI governance risk into a measurable, trend-able score - Insurance impact: Level 3+ organisations can optimise cyber insurance premiums - Regulatory alignment: ISO 42001, NIST AI RMF, APRA CPS 234, Privacy Act, EU AI Act principles - Integrated into BCyber's Pitch Generator as a dedicated "Why GRACE AI Index" spotlight section - Competitive moat: no other Australian cybersecurity firm offers a comparable AI governance maturity metric ## Risk Engine 2.0 — Gated Zone Architecture BCyber's Risk Engine 2.0 uses a zone-isolated architecture with HMAC-SHA256 signed, Zod-validated bridge gates. - Zone 1 (Posture): Evaluates compliance controls, telemetry, policy/process allocations - Zone 2 (Threat Intel): CVE/KEV/EPSS ingestion from CISA, NVD & FIRST public feeds — active - Zone 3 (Scenarios): Monte Carlo simulations, FAIR-lite modelling, what-if analysis — active - Control Plane: Central orchestrator aggregating zone outputs into unified risk posture - Learning Ledger: DP-SGD inspired reversible AI insight tracking with epsilon privacy budget ## Quantified Risk Register — FAIR-lite Dollar-Loss Modelling Phase 2.2 adds a quantified risk register using Factor Analysis of Information Risk (FAIR) methodology. - Core formula: ALE = SLE × ARO (Annual Loss Expectancy = Single Loss Expectancy × Annual Rate of Occurrence) - SLE = Asset Value × Exposure Factor; Mitigated ALE factors in Control Effectiveness - Australian calibration: >$500K=critical, >$100K=high, >$25K=medium risk thresholds - AI-assisted estimation: LLM generates defensible FAIR parameter estimates from risk descriptions - Confidence intervals via simplified triangular Monte Carlo spread (±30%) - Full bridge integration: FAIR calculations logged to Learning Ledger with epsilon costs - Categories: operational, strategic, compliance, financial, reputational, third-party - Lifecycle: draft → active → mitigated → accepted → closed - Every AI-driven score change, weight adjustment, or model update is logged with before/after snapshots ## Threat Intel Zone — CVE/KEV/EPSS Intelligence Phase 2.3 adds automated threat intelligence ingestion from free public feeds. - CISA KEV (Known Exploited Vulnerabilities): Actively exploited CVEs mandated for federal patching — all severity=critical - NVD (National Vulnerability Database): CVE 2.0 API — last 7 days, CVSS v3.1/v3.0/v2.0 scoring extraction - FIRST EPSS (Exploit Prediction Scoring System): Probability of exploitation within 30 days — enriches CVE entries - Correlation engine: Text-matches threats against incident titles/descriptions and risk register entries - Bridge integration: threat-to-control bridge sends intelligence to Control Plane, logged to Learning Ledger - Status lifecycle: new → analysed → actionable → mitigated → dismissed - Admin dashboard: Feed health monitoring, severity/source breakdown, CVSS/EPSS scores, KEV alerts, one-click ingestion - One-click or batch reversal of any AI decision — full auditability for boards and regulators - Privacy budget (epsilon) caps cumulative AI drift per client per 90-day period ## Scenario Sandbox — Monte Carlo What-If Analysis Phase 2.4 adds a Monte Carlo simulation engine for FAIR-lite quantified scenario analysis. - Triangular distributions (min/mode/max) for asset value, exposure factor, and annual rate of occurrence - Default 10,000 iterations per simulation (configurable 1,000–50,000); pure-JavaScript engine, no external deps - Outputs: mean ALE, median, p10/p50/p90/p95/p99, standard deviation, 20-bucket histogram - Mitigation modelling: control effectiveness slider (0–100%) computes mitigated ALE & risk reduction percentage - Six built-in Australian-calibrated templates: ransomware-smb, data-breach-pii (Privacy Act/OAIC), insider-malicious, supply-chain-vendor, ddos-outage, phishing-bec - Eight categories: ransomware, data-breach, insider, supply-chain, ddos, phishing, physical, other - Bridge integration: scenario-to-control bridge (active) sends results to Control Plane, logged to Learning Ledger - Live preview mode: ad-hoc simulation without persistence for rapid what-if exploration - Custom templates: admins can author non-built-in templates; built-ins are protected from delete - Every run logged with epsilon cost 0.2 in the scenarios learning zone — fully reversible ## Board Pack Generator — Executive Risk Narrative Phase 2.5 completes Risk Engine 2.0 with an AI-powered board pack generator for executive reporting. - Aggregates data from all five Risk Engine zones: Posture, Risk Register, Threat Intel, Scenario Sandbox, and CyberTriage incidents - AI generates seven narrative sections: Executive Summary, Risk Landscape, Scenario Insights, Posture Analysis, Incident Activity, Recommendations, Appendix - Each section is board-ready rich HTML with Australian English, AUD currency, regulatory references (SOCI, APRA CPS 234, Privacy Act) - Point-in-time snapshot: captures risk register ALE exposure, posture grade, threat count, incident MTTR, scenario outcomes - Overall risk level derived automatically (critical/high/medium/low) - PDF export via HTML2PDF API or browser print; HTML report view opens in new tab - Client-scoped or platform-wide generation; period labelling (Q3 FY2026, May 2026, etc.) - Learning Ledger integration: each generation recorded with epsilon cost 0.3 for auditability - Designed for quarterly board meetings, audit committee reviews, insurer evidence packs, and regulatory submissions ## CyberTriage — Incident Response Platform Available at: https://triage.bcyber.com.au CyberTriage is BCyber's incident response management platform within the GRACE Resilience pillar. - NIST Incident Response lifecycle: Triage (0–4h) → Contingency (4–72h) → Continuity (1–30d) → Resumption (1–12w) - AI-powered incident triage via Synapse engine (severity, MITRE ATT&CK mapping, playbook selection) - Four-phase response guide with linked policies, processes, checklists, and playbooks - Chain-of-custody evidence management with file hash verification - Immutable audit trail for insurance and regulatory evidence - Multi-portal access: admin, client portal, staff portal, observer (role-based) - Post-incident flywheel: risk posture recalculation, GRACE remediation projects, playbook scoring - Incident analytics: MTTR, severity distributions, MITRE tactic frequency, playbook effectiveness - PDF post-incident reporting - Australian regulatory compliance: SOCI Act (12h notification), APRA CPS 234 (72h notification), Privacy Act (NDB scheme), ASIC REP 798 ## DeepDiligence — AI Forensic Cyber Due Diligence Available at: https://duediligence.bcyber.com.au DeepDiligence is BCyber's AI-powered forensic cyber due diligence platform within the GRACE Assurance pillar. - 10 forensic workstreams: Cyber Governance, Data Protection, Incident History, Third-Party Risk, IP & Source Code, Cloud & Infrastructure, Regulatory Compliance, HR & Insider Risk, Financial Controls, Legal & Contractual - AI Collation Engine for evidence synthesis, contradiction detection, and risk correlation - Risk quantification with AUD exposure figures for deal negotiation - Evidence-based Go/No-Go recommendations with documented rationale - Chain-of-custody evidence management with forensic-grade audit trail - Watermarked, digitally signed board-ready reports via secure portal - Multi-framework compliance mapping: Essential Eight, APRA CPS 234, Privacy Act, ISO 27001, SOC 2, NIST, PCI DSS, GDPR, SOX - Post-acquisition security roadmap: Day 1 priorities, 90-day integration, long-term harmonisation - Standard delivery 2–4 weeks, expedited 7–10 business days - Australian regulatory context: Privacy Act 2024 (uncapped civil penalties), APRA CPS 234, Essential Eight, SOCI Act, ASX Governance Principles ## Privacy in Depth — Comprehensive Privacy Solutions Available at: https://privacyindepth.bcyber.com.au Privacy in Depth is BCyber's end-to-end privacy management platform within the GRACE Compliance pillar. - 10 deliverable areas: PIAs, Data Mapping, Consent Management, Breach Notification, Cross-Border Compliance, AI/ADM Compliance, Privacy Policies, Privacy Checklists, AI GRACE Index Monitoring, Privacy Training - Built for Privacy Act 2024 amendments with uncapped civil penalties ($50M or 30% of turnover) - APP 1.7–1.9 automated decision-making compliance readiness (December 2026 deadline) - Notifiable Data Breach scheme playbooks and OAIC notification templates - Cross-border data transfer compliance (APP 8 and GDPR harmonisation) - AI GRACE Index for continuous privacy posture monitoring and predictive compliance alerts - Role-based privacy checklists for project managers, developers, marketers, and HR - Industry expertise: healthcare, financial services, retail, professional services, critical infrastructure - Privacy Act 2024 (APP 11 & 13, uncapped civil penalties) - Operational within 4–6 weeks from engagement start ## Profiler — Cybersecurity Behavioural Intelligence Platform Available at: https://profiler.bcyber.com.au Profiler is BCyber's behavioural intelligence platform within the GRACE Education pillar. - 22 cybersecurity personality archetypes across 3 families: Cybersecurity Professional (8), GRC (7), Risk & Threat (7) - 64-question scientifically grounded assessment instrument - Big Five personality mapping (Openness, Conscientiousness, Extraversion, Agreeableness, Neuroticism) - DISC behavioural model (Dominance, Influence, Steadiness, Conscientiousness) calibrated for security - Entrepreneurial Mindset index for shadow IT risk and innovation propensity - Phishing susceptibility analysis by psychological trigger (authority, urgency, curiosity, social proof) - Team composition analytics with archetype clustering and blind spot detection - Role-archetype matching for workforce planning and succession - Batch processing via CSV upload, secure invite links, and manual entry - 6-tab archetype detail views: Overview, Psychology, Assessment, Business, Traits, Management - Board-ready human risk posture reporting - Supports APRA CPS 234 capability-to-threat alignment, SOCI Act personnel security, Privacy Act breach prevention ## Cyber Fitness — Tailored Cybersecurity Education & Awareness Platform Available at: https://learn.bcyber.com.au Cyber Fitness is BCyber's cybersecurity education platform within the GRACE Education pillar. - Role-specific training tailored to each person's behavioural archetype, job function, and industry threats - Fully integrated with Profiler's 28 archetypes — training adapts to individual social engineering susceptibility - Progressive phishing simulations: invoice fraud, credential harvesting, CEO impersonation, QR code vectors - Board and director programs covering ASIC REP 798, AICD Cyber Governance Principles, SOCI Act obligations - Industry-specific programs for finance, healthcare, government, critical infrastructure, professional services - Learning paths with structured course sequencing and prerequisite management - Quiz and assessment engine with effectiveness tracking and knowledge transfer measurement - Completion certificates with verifiable evidence of competency for regulators and insurers - Culture measurement dashboards with quarterly behavioural change tracking - Incident lessons learned automatically feed back into training scenarios - Compliance gap analysis findings trigger targeted course creation and assignment - Supports APRA CPS 234 awareness requirements, SOCI Act personnel security, Privacy Act staff obligations ## Regulatory Expertise BCyber specialises in Australian regulatory compliance: - APRA CPS 234 (Information Security) - APRA CPS 230 (Operational Risk Management) - Essential Eight (ACSC) - SOCI Act 2018 (Security of Critical Infrastructure) - Privacy Act 2024 (APP 11 & 13, uncapped civil penalties) - ASIC REP 798 (Cyber Governance) - AICD Cyber Governance Principles - ISO 27001, NIST CSF, SOC 2, PCI DSS