VulnApproval

Suppression Approval · NIS2 Compliance

Accepted risk, formally signed.

Turn a vulnerability suppression into a CIO-approved, digitally signed risk acceptance — an Exception Policy NIS2 with a unique ID, audit-ready.

THE PROBLEM

A suppression without signature is a compliance gap.

In normal operations, some vulnerabilities are temporarily suppressed at the request of server owners. However, NIS2 Directive (Art. 21) requires documenting and formally approving each accepted risk from management.

A suppression without CIO approval is a compliance gap — and a concrete risk during NIS2 or ISO 27001 audits.

HOW IT WORKS
business report.png

From suppression to signed Exception Policy.

VulnApproval is the SaaS system managed by Cyberfero that extracts suppressions from any supported VM system, enriches each record with the server owner from ServiceNow CMDB, composes a package in management language for the Global CIO, and collects the digital signature — issuing a formal NIS2 Exception Policy (EP-XXX) as auditable evidence.

Badge: SaaS · NIS2 · Multitenant · Multilingual IT/EN

One platform, every VM system, every legal entity.

business report.png

VM System agnostic — 8 platforms

The VM connector is configurable per tenant and replaceable without impact on the approval flow, documents, or audit trail. Switch Vulnerability Management platforms by updating only the connector configuration.

Platform features

VM System agnostic

8 platforms with a common interface. Switch VM systems without touching the approval flow or audit trail.

Architettura multitenant

Un'unica piattaforma gestisce tutte le legal entity del gruppo con dati isolati, credenziali cifrate e flusso indipendente.

ServiceNow CMDB

Arricchimento automatico del server owner dal campo u_server_owner. Nessuna ricerca manuale del responsabile.

Exception Policy NIS2

EP-YYYY-TTT-NNN document with unique ID, scope, compensating measures, and validity — ready evidence for NIS2 and ISO 27001 audits.

Flexible digital signature

Mode A via API (DocuSign, Adobe Sign, Namirial) or Mode B manual upload. Both modes coexist and are selectable after go-live.

Portale CIO dedicato

The CIO signs or rejects with one click. If rejected, the suppression is automatically deleted via API in the VM system within seconds.

Audit trail immutabile

Conservazione immutabile 5 anni, hash SHA-256, reminder pre-scadenza automatici: evidenza pronta per qualsiasi ispezione.

Sincronizzazione periodica

Pull automatico ogni 6 ore con mark-and-sweep: soppressioni scadute o rimosse aggiornate in tempo reale.

Entra ID SSO

Autenticazione Microsoft Entra ID (OIDC) per gli utenti del tenant cliente, con MFA e Conditional Access nativi.

Security included in subscription

TLS 1.3 + LUKS

Cifratura in transito (TLS 1.3) e a riposo (LUKS filesystem). Dati sempre protetti.

Isolamento tenant

Dati separati crittograficamente per tenant. Credenziali VM e CMDB in vault cifrato Fernet.

Backup & SLA 99,5%

RPO 24h · RTO 4h · Data center europeo. Cyberfero gestisce infrastruttura e monitoraggio.

Process-aligned, not a generic GRC tool.

No commercial solution natively integrates multiple VM systems, management approval workflow, CMDB ownership, and flexible signing in a single NIS2 flow.

VM System agnostic

The VM connector is configurable per tenant and replaceable without impact on the flow. Switch platforms by updating only the configuration.

CMDB-based ownership

Automatic enrichment from ServiceNow: every suppression has its real owner, without manual lookup in the corporate CMDB.

Formal Exception Policy

EP-XXX document with unique ID, scope, compensating measures, and validity — ready evidence for NIS2 and ISO 27001 audits.

Flexible signature

Mode A (DocuSign, Adobe Sign, Namirial) and Mode B (manual upload) coexist — selectable even after go-live, without migrations.

Automatic rejection

If the CIO rejects, the suppression is automatically deleted via API in the VM system: the vulnerability becomes visible again within seconds.

Secure multitenant

Cryptographically isolated data per tenant, credentials encrypted in a separate vault, independent logical schema for each legal entity.

MSSP expertise

Ten years of cybersecurity expertise: Cyberfero knows the real vulnerability management processes of enterprise companies.

REMEDIA + VulnApproval: governance end-to-end.

VulnApproval closes the remediation loop: when a vulnerability cannot be fixed in time, it governs formal risk acceptance up to executive sign-off. One asset model, one Entra ID SSO, one audit trail.

Detection → Remediation → Suppression → CIO Approval → EP NIS2

business report.png

Frequently asked questions

Does VulnApproval replace my Vulnerability Management system?

No. VulnApproval is not a VM system — it connects to the one you already use (CrowdStrike, Tenable, ConnectSecure, etc.) and adds the formal NIS2 approval flow for suppressions. Your VM system continues to detect vulnerabilities as before.

How does the connection to the VM system work?

Via tenant-configurable native connectors. Enter the API credentials in settings, click ‘Test connection’, and the system starts syncing. No on-premise installation required.

Does the data remain in Europe?

Yes. The infrastructure is managed by Cyberfero on European data centers with LUKS filesystem encryption and TLS 1.3. Each tenant has cryptographically separated data.

Is VulnApproval suitable for groups with multiple legal entities?

Yes, it is designed for this. The multitenant architecture manages all group legal entities from a single interface, each with its own approval flow, EP numbering, and signing CIO.

Is it possible to get a demo?

Yes. Contact us via the form below: we will arrange a personalised demo with your VM system and CMDB data.

Contact us for a demo

Customers