Where CYBORA is heading next
Our public product road map — the modules, integrations and capabilities we're building across autonomous SOC, agentic GRC, threat intelligence and quantum-safe security.
On the road map
Autonomous SOC expansion
Deeper AI-driven detection and response automation across the HybridSOC platform. Detailed milestones coming soon.
Agentic GRC modules
More framework coverage and automated evidence workflows. A full timeline will be published here soon.
Quantum-safe tooling
Expanding the post-quantum readiness and migration tooling. Release schedule to follow soon.
Osprey Sentry scanners
New self-service security scanners and intelligence feeds. Specifics coming soon.
2026 delivery plan
Planning estimates for the requirements below that aren't live yet — sequencing, not a contractual delivery date.
Feature & requirements matrix
Every capability we're asked about for the phishing-simulation and security-awareness platform, and exactly where it stands today.
| No. | Parameter | Required minimum | Status |
|---|---|---|---|
| 1 | Cloud architecture | The solution must be a cloud-based software platform that does not require deployment within the contracting authority's infrastructure. | Available |
| 2 | Management console | The platform must have a centralised web-based management console. | Available |
| 3 | User synchronisation | The platform must support user synchronisation with directory services (e.g. Microsoft Entra ID). | Roadmap |
| 4 | Microsoft 365 integration | The solution must support integration with the Microsoft 365 environment. | Roadmap |
| 5 | Email client integration | The solution must support a plugin for email clients. | Roadmap |
| 6 | Report button | The solution must let employees report suspicious emails. | Roadmap |
| 7 | Automatic analysis | The system must automatically analyse suspicious emails flagged and reported by users via the report function, and return an assessment result. | Available |
| 8 | User feedback | The platform must give the user instant feedback on whether a simulation was correctly identified. | Available |
| 9 | API | The system must have an open Application Programming Interface (API). | Available |
| 10 | SIEM integration | The system must support integration with SIEM (Security Information and Event Management) solutions. | Roadmap |
| 11 | Simulations | The platform must support social-engineering simulations that imitate emails sent by an organisation's own staff, managers, or other trusted parties. | Available |
| 12 | Internal-contact impersonation | The platform must support scenarios that imitate emails between employees. | Available |
| 13 | Social-engineering scenarios | The system must support realistic social-engineering scenarios. | Available |
| 14 | Multi-stage attacks | The platform must support multi-stage simulations. | Available |
| 15 | Phishing scenario library | The system must have a phishing scenario library containing at least 1,000 scenarios. | Partially available |
| 16 | Simulation scheduling | The system must support automatic simulation scheduling. | Available |
| 17 | Automatic simulation distribution | The system must automatically distribute phishing simulations across the calendar year at random intervals. | Available |
| 18 | Automatic difficulty adjustment | The system must automatically increase or decrease phishing-simulation difficulty based on the user's prior results. | Available |
| 19 | Peer-simulation authoring | The system must let employees create and send social-engineering simulations to colleagues within the organisation for training purposes. | Available |
| 20 | Automatic training delivery | The system must automatically deliver training after a simulation. | Roadmap |
| 21 | Micro-learning | The system must deliver short training modules (up to 3 minutes long) immediately after a user's actions during a simulation. | Roadmap |
| 22 | Training formats | The system must support interactive training formats. | Roadmap |
| 23 | Language support | The platform must support training in Lithuanian and English. | Available |
| 24 | Interactive scenarios | The system must have scenario-based training. | Available |
| 25 | Personalisation | Training must be personalised to the user's behaviour. | Available |
| 26 | Automatic training assignment | The system must automatically assign training to users whose risk level has increased, based on their actions during social-engineering simulations, training results, or the system's calculated risk assessment. | Roadmap |
| 27 | Gamification | The platform must have gamification elements and encourage employee engagement. | Roadmap |
| 28 | Points system | The system must let points be awarded to users for secure behaviour — for example, successfully identifying phishing simulations, reporting suspicious emails, or completing training on time. | Roadmap |
| 29 | Rankings | The platform must let users and user groups be ranked and compared on resilience to social-engineering attacks, based on simulation results, training completion, and other metrics tracked by the system. | Roadmap |
| 30 | AI for content | The system must be able to use artificial intelligence to create training content. | Partially planned |
| 31 | AI scenario generation | The system must be able to generate new simulation scenarios using artificial intelligence. | Available |
| 32 | AI analysis | The system must use artificial intelligence to analyse user behaviour and personalise training. | Available |
| 33 | Adaptive training system | The system must use an AI-driven adaptive training system that automatically selects simulation difficulty, scenarios, and training content based on each user's prior behaviour, mistakes, and risk level. | Roadmap |
| 34 | Automated training process | The training and simulation process must be automated and run continuously without an administrator manually planning each campaign. | Roadmap |
| 35 | Automated training programmes | The system must have pre-built automated training programmes for employee awareness. | Roadmap |
| 36 | Risk scoring | The system must calculate a user risk score or an equivalent cyber-risk indicator, allowing the user's risk level to be assessed from their actions during simulations, training results, and other criteria evaluated by the system. | Available |
| 37 | Individual resilience index | The system must calculate an individual phishing resilience score for each user, continuously updated based on their actions in simulations and training. | Available |
| 38 | Risk segmentation | The system must segment users by risk level (e.g. low, medium, high, or equivalent vendor-defined levels). | Available |
| 39 | Behaviour analysis | The system must analyse user behaviour during simulations. | Roadmap |
| 40 | Training statistics | The system must analyse training effectiveness. | Roadmap |
| 41 | Organisation-level statistics | The system must generate organisation-wide security metrics. | Roadmap |
| 42 | Department analysis | The system must provide risk analysis of user groups by organisational structure or other grouping criteria defined in the system. | Roadmap |
| 43 | Management reports | The system must generate reports for management. | Available |
| 44 | Reports | The system must generate detailed training and simulation reports. | Available |
| 45 | Dashboard | The platform must have customisable dashboards. | Available |
| 46 | Data export | Reports must be exportable to standard formats such as PDF, CSV, or XLS. | Available |
| 47 | GDPR | The solution must comply with GDPR requirements. | Available |
| 48 | Role-based access control (RBAC) | The system must support role-based access control. | Available |
| 49 | Audit logs | All administrative actions must be logged. | Partially planned |
| 50 | Multi-factor authentication | Administrator accounts must be protected by multi-factor authentication (MFA). | Available |
| 51 | Data retention | Simulation and training data must be retained for at least 6 (six) months. | Available |
| 52 | Data location | Platform data must be stored in data centres within the European Economic Area (EEA). | Available |
| 53 | Platform availability | Platform availability must be at least 99.9%. | Available |
| 54 | Automatic content updates | Training content and phishing scenarios must be continuously updated in line with the latest cyber-threat trends. | Available |
Näe seda oma perimeetril
Tell us where you are today. A CYBORA engineer — not a salesperson — will come back with what actually applies to your situation.
- Reply within one business day
- Scoped to your regulatory frameworks
- No obligation, no sales pitch
Take control of your perimeter
Register for a pilot demonstration of the CYBORA GRC and HybridSOC platform. One team, accountable for your full cyber security lifecycle.