Product Overview

Attacks don't break in.
They get invited.

Almost every breach begins with a person doing something entirely reasonable — opening a message, pasting some text, plugging in a drive. CyberAware covers those exact moments, and turns each one into the place where your people get stronger.

6
Scan engines on every USB
4
Simulated attack surfaces
5
Signals in every risk score
2
Languages, fully right-to-left
One Ordinary Tuesday

Four moments
that decide everything

Nobody on your team wakes up planning to cause an incident. Risk arrives inside ordinary work. Here is where, and here is what we do about it.

08:42

The browser opens

A tab, a search result, a helpful-looking extension installed months ago that quietly reads every page. The workday now lives in the browser — and so does the attack.

See how we cover it
11:15

A message that fits

It uses the right name, the right project, the right tone. It is not obviously wrong — that is the entire craft. The question is no longer whether someone will click, but what happens when they do.

See how we cover it
14:30

A drive in a hand

From a contractor, a conference, a car park. It has to be read, and the network has no say in it. Physical media walks straight past every control you bought.

See how we cover it
Always

What they can't see about themselves

An old password in a breach dump. A pattern of clicking. Training never finished. None of it is visible to the person — and all of it is visible to an attacker.

See how we cover it
Pillar 01

Browser Security

A managed Chromium extension that does more than block bad addresses. It audits the browser itself, and it stops sensitive text at the moment of the paste — the last instant before the data is gone.

It watches the other extensions

Most browser compromise arrives through an extension the user installed themselves and trusts completely. CyberAware inventories every other extension in the browser and reports what it finds back to your portal — so a side-loaded add-on with permission to read every page stops being invisible.

Uses the browser's management API

The paste that never lands

The extension intercepts paste events before the content reaches the page and cancels the paste outright when it matches a sensitive pattern. Nine patterns ship ready — card numbers, API keys, password keywords, internal domains, employee IDs and more — each with its own severity, each editable per organisation. It applies in every web app, which includes the public AI chat box someone was about to drop a customer list into.

9 patterns · 4 severity levels

Blocking that teaches

Policy blocking runs on the browser's own rules engine, so it is fast and it cannot be argued with. But a dead end teaches nothing: the block page and on-page disclaimers explain what was risky, right where the decision was being made.

Block page · injected disclaimers

Downloads, checked on arrival

Downloads are observed as they happen rather than discovered later on the endpoint, and what the extension sees becomes browser-threat telemetry in the portal — which is also one of the five inputs to that person's risk score.

Feeds the risk score

Yours, not ours

Manifest V3, deployed through your normal enterprise policy channel, themed per organisation, and configured centrally. Your people see your organisation looking after them, not a third-party tool bolted on.

MV3 · managed policy
Pillar 02

Phishing Defense

Phishing stopped being only an email problem years ago. We simulate it on all four surfaces it actually arrives through, measure who reports it rather than only who falls for it, and give people one button to do the right thing.

Spear-phishing written by AI

A generic template fools nobody twice. The spear-phishing wizard generates tailored email content from what is known about the target, so the simulation carries the specificity a real targeted attack would — the right name, the right context, the right pretext.

AI wizard · per-target

QR codes, where nobody is looking

A QR code bypasses every email control by moving the attack onto a personal phone. Our QR simulations track the whole chain — scan, device type, landing page, form submission, credentials entered — and, crucially, whether the person reported it.

Scan → submit → report

Attacks made of paper and plastic

Run a real physical campaign: dropped USB sticks, letters, envelopes and cloned badges, printed and tracked from the portal. This is the one attack surface that awareness programmes almost always skip, and it is the one that walks through the front door.

4 physical prop types

One button, in the client they already use

Add-ins for Outlook and Gmail put reporting one click away, inside the mail client rather than in a portal nobody remembers. Reported messages arrive in a queue built for triage and analysis — so reporting produces an outcome, which is the only reason anyone keeps doing it.

Outlook · Gmail

The lesson lands while it still stings

Clicking a simulation is the single best teaching moment you will ever get with that person. Remedial training is assigned off the back of it, and whether it was completed becomes 20% of their risk score — so follow-through is measured, not assumed.

20% of the risk score
Pillar 03

USB Security

A dedicated scanning kiosk that lives where the media enters — a reception desk, a plant floor, a secure area. It is built to run with no network at all, because the places that need it most are the places that do not have one.

Six engines, one verdict

ClamAV, Microsoft Defender, Emsisoft, YARA, LOKI and oletools each run over the same drive. They disagree usefully: signature engines catch the known, YARA and LOKI catch patterns and indicators, and oletools opens the macro-bearing documents that carry so much of it.

6 engines in parallel

Designed for the air gap

The kiosk scans, quarantines and issues a clean stamp with no connection to anything. Engine signatures are refreshed by carrying a prepared USB to it, and scan reports queue locally until there is somewhere to send them — the queue depth is on screen, so nothing is silently lost.

Offline-first · queued sync

Nobody carries the signing key

Kiosk updates are Ed25519-signed and a kiosk refuses anything unsigned or altered. The private key stays on the portal and never reaches a laptop, a USB stick or an engineer's hands — the builder sends file hashes and receives a signature back. The tablet only ever holds the public key, so a stolen kiosk cannot forge an update for the rest of your fleet.

Ed25519 · portal-held key

Locked down, on purpose

It runs full-screen as a standard, non-administrative user with the shell replaced and the usual escape routes closed. Administrative actions sit behind a PIN with an escalating lockout, and the destructive ones demand it again even if the panel is already open.

Kiosk lockdown · PIN re-auth

Deep where it matters

Archives are opened and scanned rather than skipped, the boot sector is checked, and file types you have banned outright are removed regardless of what any engine thinks of them. Detections are quarantined to a protected folder, and the operator decides — with the decision recorded either way.

Archives · boot sector · blocklist
Pillar 04

Risk & Intelligence

The other three pillars each see one slice of a person. This is where the slices become a picture — a single, explainable score per human being, and per organisation.

Five signals, openly weighted

Phishing susceptibility carries 35%, unfinished training 20%, and quiz accuracy, browser threats and external exposure 15% each. No black box: an administrator can see every factor, its weight and the evidence behind it.

35 · 20 · 15 · 15 · 15

Honest about what it does not know

A new employee who has never been sent a simulation is not low-risk — they are unmeasured, and those are different things. Factors with no data are excluded and the remaining weights renormalise, so a score is never quietly propped up by absent evidence.

Renormalising by design

A grade people understand

Scores resolve to an A-to-F grade with a named level, because "A" starts a conversation and "63.4" ends one. It rolls from the individual up to the whole organisation using the same arithmetic, so the board view and the one-to-one view never contradict each other.

A–F · person → org

Exposure you did not publish

Open-source exposure tracks your domain and your people's addresses appearing in breaches, credential leaks and pastes. Findings are classified across five types and five severities and move through a real triage workflow — open, acknowledged, remediated, dismissed, false positive — with severity feeding straight into the score.

Analyst-driven · 5 types · 5 severities

A score you can act on

Every factor names what would move it. A high score is not a verdict on somebody — it is a list of the specific next steps that would lower it, which is the only version of this that ever changes behaviour.

Every factor explains itself
Why "Human-Centric" Is Not A Slogan

Security that treats people
as the solution

Every tool here reports on people. What makes it human-centric is that every tool also gives something back to them — at the moment it is useful, in their own language.

Learning that is actually a game

A playable security adventure, not a slideshow with a quiz stapled to the end.

A leaderboard, because pride works

Progress is visible and comparable. Teams move faster when the good behaviour is the one on display.

In their pocket

A mobile app so awareness is not something that only exists at a desk.

Arabic as a first language

Full right-to-left across the platform. Not a translation layer bolted on afterwards.

Taught at the point of the mistake

The block page, the paste warning, the post-click training — the lesson arrives where the decision was made.

Nobody is left as a number

Every risk score comes with the reasons behind it and the steps that would lower it.

One Platform

Four pillars. One picture of one person.

Browser Security Phishing Defense USB Security Risk & Intelligence

Bought separately, these are four tools and four dashboards that never quite agree. Built together, the browser tells the risk score what it saw, the simulation tells it who clicked, the training tells it who followed through, and exposure monitoring tells it what an attacker already knows. Multi-tenant to the core, so a managed provider runs many organisations with strict separation between them.