For the CISO

Connect every control to the decisions they protect. Prove security outcomes with confidence.

Risks, controls, obligations, assessments and evidence in one model inside your Microsoft tenant, so the audit reads what the assessment already holds.

In one sentence

AlignX gives the CISO controls, risks, evidence and decisions on one record, so cyber posture is proved from governed data rather than reconstructed for the board.

Written forChief Information Security OfficerHead of ComplianceHead of Cyber Security

The solution

What the CISO has to prove.

Evidence

Sixteen items of evidence, each attached to the control answer it proves.

Multi-factor enforcement, shared account authentication, access review maturity, findings to closure — every question carrying the exports, attestations and logs that answer it, so the audit reads what the assessment already holds instead of asking for it again.

See the GRC product

Control crosswalk

One control, mapped into every framework that asks for it.

A master control carries its Essential Eight, ISO 27001 and other framework references, so the same evidence answers all of them.

See the GRC product

Assessment

The assessment answered per target, evidence attached as you go.

Respond to each question for each target system, attach the export or the report, and the validation and evidence tabs fill themselves.

See the workflow builder

Control state

The controls a system actually runs, with their state.

Implemented, partially implemented, not implemented, on the IT component's own record, next to its risks and issues.

See the architecture product

Third-party assurance

Tier, due diligence date, and every assessment run against the provider.

Vendor security review completed at eighty-four per cent, business continuity still in progress at sixty-six, risk rating medium. On the provider record, not in a spreadsheet someone owns.

See the vendor product

Day to day

What changes.

Without AlignXWith AlignX
The audit requestA month of gathering evidence from inboxes and shared drives.
The audit requestThe assessment already holds the evidence, hashed and dated.
The framework crosswalkThe same control maintained in three spreadsheets, one per framework.
The framework crosswalkOne master control, mapped once, answers every framework.
The risk register reviewRisks scored in a register that does not know which systems carry them.
The risk register reviewInherent and residual on the record, linked to the systems, vendors and projects.
The control testResults typed into a form; nobody can find last cycle's.
The control testAnswered per target, evidence attached, validation kept.
The findingClosed when someone says it is closed.
The findingClosed when the retest passes, on the record.
The board risk reportA slide with a heat map nobody can drill into.
The board risk reportA dashboard on the risk register, opened live.

The AlignX technology

Nothing new to govern.

  • Runs inside Microsoft 365In your tenant, on your Dataverse. Nothing leaves it.
  • Entra ID governs who sees whatThe roles you already run decide access. No second directory.
  • Australian data residencyYour Dataverse environment sits in an Australian region. Purview and retention policies apply as they do everywhere else.

How AlignX sits inside Microsoft 365

Questions

What CISOs ask us.

Does AlignX replace or augment our GRC/IRM tool (ServiceNow IRM, Archer, LogicGate, MetricStream)?

Both, depending on your setup. AlignX covers cyber risk, controls, third-party risk, incident management, policy attestation and audit response in one platform, and brings overall governance and risk management into one connected model. Where you use deep, category-specific GRC functionality, AlignX augments and extends it rather than ripping it out. Where functionality overlaps, most CISOs consolidate onto AlignX for the business context standalone GRC cannot provide.

What cyber, GRC and vendor risk tools does consolidation cover?

AlignX is not here to replace specialised GRC tools where their depth is genuinely used. Where an organisation runs a niche capability that AlignX does not match, we integrate and extend. Where the standard GRC/IRM functionality overlaps with what AlignX delivers (IRM platforms like ServiceNow IRM, Archer, LogicGate, third-party risk tools like Prevalent or ProcessUnity, standalone control testing and policy attestation), consolidation is usually the right call. Combined saving is typically significant and cyber risk finally connects to the assets it protects.

How does AlignX handle cyber risk against our control frameworks (ISO 27001, Essential Eight, NIST CSF, SOCI Act)?

Control libraries for ISO 27001, Essential Eight, NIST CSF, SOCI Act and PSPF ship with AlignX. Every control maps to the assets and processes it protects, with maturity, evidence and testing captured. Compliance reporting is a byproduct, not a project.

Can I show board-level cyber posture without another manual paper?

Yes. The Cyber Board Report generates a live view of control maturity, top risks, incident trends, third-party exposure and remediation progress. It refreshes on demand and every number is drillable. Boards get evidence-backed cyber assurance, not another traffic light.

How does AlignX handle third-party and supply chain cyber risk?

Every vendor has a cyber risk profile with assessment questionnaires, evidence collection, control ratings and residual risk. Vendors are linked to the applications, data and processes they touch, so you see supply chain exposure by business impact, not just by vendor count.

How does AlignX link cyber risk to the business outcomes it protects?

Every cyber risk links to the business capabilities, revenue streams and services it affects. When you brief the exec on Zero Trust investment, you show the business impact avoided, not just the security hygiene improved. This is the conversation CFOs actually engage with.

How does AlignX integrate with our SIEM, ITSM and CMDB?

Two-way integration with ServiceNow ITSM/CMDB and Jira Service Management (JSM), plus connectors to SIEM platforms (Sentinel, Splunk) and vulnerability tools (Qualys, Tenable). Incidents flow in, control test data is captured, CI relationships stay current. AlignX is the risk and governance layer over the security operations tools that stay.

See where you stand.

Ten minutes, twenty-one questions, an instant maturity score.