Frequently Asked Questions
Security & Compliance Certifications
What security certifications does Cymulate hold?
Cymulate is certified as SOC2 Type II, has multiple ISO certifications (ISO 27001:2013, ISO 27701, ISO 27017), and holds CSA STAR Level 1 certification. These demonstrate Cymulate's commitment to industry-leading security and compliance standards. Learn more.
What does SOC2 Type II certification cover for Cymulate?
SOC2 Type II certification for Cymulate covers security, availability, confidentiality, and privacy, providing a third-party attestation of Cymulate's robust security practices. Source.
Which ISO standards does Cymulate comply with?
Cymulate complies with ISO 27001:2013 (Information Security Management System), ISO 27701 (Privacy Information Management), and ISO 27017 (Security controls for cloud services). These standards are audited by independent bodies. Source.
What is CSA STAR Level 1 certification and how does Cymulate meet it?
CSA STAR Level 1 certification demonstrates Cymulate's adherence to the Cloud Controls Matrix (CCM), ensuring transparency, rigorous auditing, and harmonization of standards for cloud security and compliance. Source.
How often does Cymulate undergo third-party audits and penetration tests?
Cymulate conducts third-party network vulnerability scans and penetration tests at least annually, in addition to continuous internal and external security testing. Source.
Does Cymulate have a dedicated security team?
Yes, Cymulate’s privacy and security team includes a Data Protection Officer (DPO), a Chief Information Security Officer (CISO), and an IT Manager, ensuring ongoing compliance and security oversight. Source.
How does Cymulate ensure GDPR compliance?
Cymulate incorporates data protection by design, maintains up-to-date Terms and Conditions, Privacy Policy, and Data Processing Addendum (DPA), and has a dedicated privacy and security team to ensure GDPR compliance. Source.
What encryption standards does Cymulate use for data protection?
Cymulate uses TLS 1.2+ for data in transit and AES-256 for data at rest, ensuring strong encryption for all customer data. Source.
Where does Cymulate host customer data?
Cymulate hosts customer data in secure AWS data centers located in the United States, Europe, and Asia Pacific, with multiple data locality options available. Source.
How does Cymulate ensure physical security at its data centers?
Cymulate leverages AWS data centers with ISO 27001:2022, PCI DSS Service Provider Level 1, and SOC 2/3 Type II certifications. Physical security includes security guards, fencing, intrusion detection, and more. Learn more.
Product Security & Application Security
What secure development practices does Cymulate follow?
Cymulate follows a strict Secure Development Lifecycle (SDLC), including secure code training for engineers, code reviews, static and dynamic code analysis, and vulnerability scanning before code is committed. Source.
How does Cymulate manage vulnerabilities in its applications?
Cymulate continuously scans its core applications for vulnerabilities using third-party tools, conducts annual third-party penetration tests, and performs software composition analysis as part of its CI/CD pipeline. Source.
What authentication and access controls does Cymulate provide?
Cymulate enforces two-factor authentication (2FA) for all employees and offers 2FA or SSO for customers. Role-based access controls (RBAC) and IP address restrictions are also available for granular access management. Source.
How does Cymulate protect its help center and support communications?
Cymulate provides free TLS encryption for host-mapped Guide help centers, using Let's Encrypt for certificate management and automatic renewal. Source.
What employee security measures does Cymulate enforce?
All Cymulate employees undergo ongoing security awareness training, phishing campaign tests, and must sign non-disclosure and confidentiality agreements. Security policies are shared with all employees. Source.
How does Cymulate separate testing and production environments?
Cymulate logically separates testing and staging environments from production, ensuring no real data is used in development or test environments. Source.
How can I report a security issue to Cymulate?
You can report security issues or concerns to the Cymulate support team at [email protected].
Platform Features & Capabilities
What are the key capabilities of the Cymulate platform?
Cymulate offers continuous threat validation, breach and attack simulation (BAS), continuous automated red teaming (CART), exposure analytics, attack path discovery, automated mitigation, AI-powered optimization, and complete kill chain coverage. Learn more.
How does Cymulate help organizations prioritize and remediate exposures?
Cymulate validates exploitability and ranks exposures based on prevention and detection capabilities, business context, and threat intelligence, enabling organizations to focus on the most critical vulnerabilities. Learn more.
What integrations does Cymulate support?
Cymulate integrates with a wide range of security technologies, including Akamai Guardicore, AWS GuardDuty, BlackBerry Cylance OPTICS, Carbon Black EDR, Check Point CloudGuard, Cisco Secure Endpoint, CrowdStrike Falcon, Wiz, SentinelOne, and more. For a full list, visit the Partnerships and Integrations page.
How does Cymulate automate threat validation and mitigation?
Cymulate automates threat validation with 24/7 attack simulations and integrates with security controls to push updates for immediate threat prevention and remediation. Learn more.
What technical documentation is available for Cymulate?
Cymulate provides guides, whitepapers, solution briefs, and data sheets covering topics like CTEM, detection engineering, exposure validation, and automated mitigation. Access these resources at the Resource Hub.
Pricing & Plans
How is Cymulate priced?
Cymulate uses a subscription-based pricing model tailored to each organization's requirements. Pricing depends on the chosen package, number of assets, and scenarios selected. For a quote, schedule a demo.
Implementation & Support
How long does it take to implement Cymulate?
Cymulate is designed for quick, agentless deployment. Customers can start running simulations almost immediately after deployment, with minimal resources required. Learn more.
What support options does Cymulate offer?
Cymulate offers email support at [email protected], real-time chat support, a knowledge base, webinars, e-books, and an AI chatbot for technical assistance and best practices. Resource Hub.
Use Cases & Benefits
Who can benefit from using Cymulate?
Cymulate is designed for CISOs, security leaders, SecOps teams, red teams, and vulnerability management teams in organizations of all sizes and industries, including finance, healthcare, retail, media, transportation, and manufacturing. Learn more.
What business impact can customers expect from Cymulate?
Customers have reported up to a 52% reduction in critical exposures, a 60% increase in team efficiency, and an 81% reduction in cyber risk within four months. Learn more.
What pain points does Cymulate address for security teams?
Cymulate addresses fragmented security tools, resource constraints, unclear risk prioritization, cloud complexity, communication barriers, inadequate threat simulation, operational inefficiencies, and post-breach recovery challenges. See case studies.
Are there case studies showing Cymulate's effectiveness?
Yes. For example, Hertz Israel reduced cyber risk by 81% in four months, and a sustainable energy company scaled penetration testing cost-effectively with Cymulate. Read more case studies.
How do Cymulate's solutions differ for different security roles?
Cymulate tailors solutions for CISOs (metrics and risk communication), SecOps (automation and efficiency), red teams (offensive testing), and vulnerability management (validation and prioritization). Learn more.
Competition & Comparison
How does Cymulate compare to AttackIQ?
Cymulate surpasses AttackIQ in innovation, threat coverage, and ease of use, offering the industry-leading threat scenario library and AI-powered capabilities. Read more.
How does Cymulate compare to Mandiant Security Validation?
Mandiant Security Validation is an original BAS platform but has seen little innovation in recent years. Cymulate continually innovates with AI and automation, expanding into exposure management as a grid leader. Read more.
How does Cymulate compare to Pentera?
Pentera focuses on attack path validation but lacks the depth Cymulate provides to fully assess and strengthen defenses. Cymulate optimizes defense, scales offensive testing, and increases exposure awareness. Read more.
How does Cymulate compare to Picus Security?
Picus Security offers an on-premise BAS option but lacks the comprehensive exposure validation platform Cymulate provides, which covers the full kill-chain and includes cloud control validation. Read more.
How does Cymulate compare to SafeBreach?
Cymulate outpaces SafeBreach with unmatched innovation, precision, and automation, offering the industry’s largest attack library and a full CTEM solution. Read more.
How does Cymulate compare to Scythe?
Scythe is suitable for advanced red teams building custom attack campaigns, but Cymulate provides a more comprehensive exposure validation platform with actionable remediation and automated mitigation. Read more.
Customer Experience & Feedback
What do customers say about Cymulate's ease of use?
Customers consistently praise Cymulate for its intuitive, user-friendly interface and actionable insights. For example, Raphael Ferreira, Cybersecurity Manager, said, “Cymulate is easy to implement and use—all you need to do is click a few buttons.” Read more testimonials.