Skip to content

CISO and IT directors

All six NIST CSF functions, with the team you have.

Three products, each complete on its own, mapped to the six functions of NIST CSF 2.0. Start with UASR: one score, and the ten actions that move it. Then add ZT-SSE, and the posture of each device decides what it can reach.

UASRUnified Attack Surface Reduction

Ten tasks, not four thousand.

Your team is the size it is. UASR looks at your internet exposure, laptops, cloud, internal network and governance, puts one number on it, and ranks the actions that move that number. Your team knows what to do on Monday morning.

Score 62 out of 100, grade B. Up 0 points. 0 of 10 actions done.

Today's ten actions

Ranked by effort. Tick one and watch the number move.

Points and grades are examples.

  • Every surface reports in

    Internet exposure, laptops and devices, the browser and AI assistants, Microsoft 365 and Google Workspace, the internal network and Active Directory, governance. All of it feeds one score.

  • Ranked by effort

    The list is ordered by what each action gains for the work it takes. Nobody has to sort four thousand findings first.

  • Fixes, not only findings

    Hardening measures are applied with guidance, or automatically. Drift is detected, and the loop starts again.

ZT-SSENew

Then your posture decides who gets access.

ZT-SSE takes the posture of each device from UASR or from the ZT-Station. Every connection is authenticated, encrypted and authorised, and granted on one condition: the state of the device asking.

  • No ticket, no analyst

    An unpatched laptop loses access on its own. Access returns as its posture recovers.

  • Learn first, then enforce

    Learning mode shows what would be blocked. Shadow mode tests the policy next to the live one. Enforcement is switched on system by system.

  • Evidence, not promises

    Every decision is logged and every privileged session is recorded. When the auditor asks, the proof is already there.

Monday: the score dropped.

What it looks like in practice, with the team you have.

  1. Monday morning, the score is down.

    Twelve laptops are graded D after the weekend. You see which ones, and why.

  2. The task list puts them first.

    The fix is at the top of today's actions. Your team knows where to start.

  3. ZT-SSE has already reduced their access.

    It takes device posture from UASR, so those laptops reach less until they are fixed. No ticket, no analyst.

  4. The fix is pushed. By Tuesday the score is back.

    ZT-SSE restores access as posture recovers, and the board sees the dip and the recovery.

UASR and ZT-SSE are sold separately, and each works on its own.

We help you become compliant and we give you the evidence.

NIS2, ISO/IEC 27001 and GDPR each ask you for proof. One answer counts for every framework that asks the same question, and the audit trail is complete and exportable.

What you hand the auditor

  • NIS2

    A compliance score per control, playbooks, recorded privileged sessions, secure administration.

  • ISO/IEC 27001

    A control-by-control assessment, gaps tracked as issues, a complete audit trail.

  • CRA and GDPR

    Vulnerability history, patch reports, data-loss event history, CNIL notification templates.

The questions we get.

  • “We already have a VPN and an EDR.”

    Good. Keep the EDR. A VPN trusts the network once you are in, and an EDR watches after the fact. We remove the assumptions both rely on.

  • “Three products is three integrations.”

    They are one lifecycle. Start with UASR or the ZT-Station, each complete on its own, and add ZT-SSE, which draws device posture from whichever you chose.

  • “Rolling out zero-trust policy is risky.”

    Learning mode shows what would be blocked. Shadow mode tests the policy next to the live one. Enforcement is switched on system by system.

One score. One policy.
One trusted system.

Start with your Cyber Score. In two weeks you know where you stand and what to fix first.