Skip to content
NEXT SIGHT

Product · Sec Manager

Sec Manager.
Governance-grade risk management.

Sec Manager helps security managers run comprehensive risk analyses for their organisations. It delivers situational awareness and regional risk context using public-source intelligence — so teams understand third-party exposure and public reporting that affects their security posture, aligned to leading ISO standards.

Sec Manager by Next Sight

Built for

Security managersRisk & complianceBusiness continuityCorporate securityProcurement & vendor risk

Capabilities

What it does.

Situational awareness dashboard

See what is being publicly reported and why it matters to your security posture — in one actionable view.

Regional risk context

Location-aware queries surface developments in the specific regions, cities, and districts tied to your operations.

Third-party exposure lens

Identify public reporting tied to vendors, partners, and infrastructure that could affect your risk profile.

Smart case & task management

Investigation Task Manager for tracking leads and secure chat-thread organisation. (Pro / Agency tiers)

Expert risk assessments

Use expert-built templates or build fully custom questionnaires with your own scenarios and scoring.

Actionable PDF reporting

Detailed PDF reports with risk scoring, response history, and recommendations — ready for stakeholders and auditors.

Inside the platform

Every standard, one workspace.

Run ISO-aligned questionnaires — from ISO 31000 risk management through 27005, 22301 and 45001 — score posture, and apply real-world events to recalculate risk inside a single governance workspace.

Sec Manager available questionnaires catalog showing ISO 27005, GDPR, CMMC, PCI DSS, NIST CSF and ISO 27017 compliance templates
Sec Manager available questionnaires catalog showing ISO 27005, GDPR, CMMC, PCI DSS, NIST CSF and ISO 27017 compliance templates
Sec Manager apply-events screen listing CMMC Level 1 and Level 2 risk events that recalculate a completed questionnaire's score
Sec Manager apply-events screen listing CMMC Level 1 and Level 2 risk events that recalculate a completed questionnaire's score

Toolset

All standards supported. Full customisation.

Whether aligning with recognised standards or company-specific protocols, Sec Manager ships ready-to-use templates across the risk-management landscape.

Risk management

  • ISO 31000:2018 — Risk Management
  • ISO 31010:2019 — Risk Assessment Techniques
  • ISO 14971:2019 — Risk Management for Medical Devices

Information security & continuity

  • ISO/IEC 27005:2022 — Information Security Risk
  • ISO 22301:2019 — Business Continuity
  • ISO 22317:2021 — Business Impact Analysis
  • ISO 22318:2021 — Supply Chain Continuity
  • ISO 27031:2011 — ICT Readiness for Business Continuity

Operations, safety & integrity

  • ISO 45001:2018 — Occupational Health & Safety
  • ISO 37001:2016 — Anti-bribery Management
  • ISO 22320:2018 — Emergency Management
  • ISO 22316:2017 — Organisational Resilience
  • ISO 22395:2018 — Community Support in Emergencies

Live signal

OSINT context, on tap.

Pull regional and third-party reporting directly into the assessment loop. Per-organisation scoping and credit-tracked queries keep collection auditable and aligned to your governance posture.

Sec Manager OSINT news search results for cybersecurity, scoped to a selected organisation with remaining query credits and source attribution
Sec Manager OSINT news search results for cybersecurity, scoped to a selected organisation with remaining query credits and source attribution
Sec Manager apply-events workflow detail showing event titles, questionnaire context and one-click open-questionnaire actions
Sec Manager apply-events workflow detail showing event titles, questionnaire context and one-click open-questionnaire actions

Security & compliance

The three-step governance process.

Step 01 — Assess your posture
Use expert ISO templates or custom questionnaires to evaluate your security across any standard.
Step 02 — Public-source retrieval
Posture-aligned queries surface relevant reporting on vendors, regulatory signals, and incident context.
Step 03 — Governance outputs
Generate actionable outputs to support risk decisions, stakeholder updates, and compliance documentation.
Included on every plan
Secure sign-in, risk scoring, response history, PDF report exports, and a compliance-progress dashboard.
Pro & Agency tiers
Add the Investigation Task Manager for tracking leads and secure chat-thread organisation across cases.
Built for defensibility
Outputs are designed to support audit, procurement, and regulator conversations — not just internal review.

How it fits Next Sight

The governance layer around your security operation.

Sec Manager focuses on the governance side of security work: structured risk assessment, third-party exposure visibility, and defensible documentation. It is offered as a standalone product at sec-manager.com.

Where Nexus equips analysts with an AI platform for intelligence work, Sec Manager equips the security organisation around them with the ISO-aligned controls, evidence, and auditability that procurement and regulators expect.

Answers

Frequently asked questions.

  • Sec Manager is Next Sight's governance-grade OSINT and risk management platform. It helps security managers run comprehensive risk analyses, maintain situational awareness, and align their security posture with leading ISO standards using public-source intelligence.

  • Security managers, risk and compliance leaders, business continuity owners, and corporate security teams who need structured risk assessments, third-party exposure visibility, and defensible governance outputs.

  • Sec Manager ships templates for ISO 31000:2018 (Risk Management), ISO 31010:2019, ISO/IEC 27005:2022 (Information Security Risk), ISO 22301:2019 (Business Continuity), ISO 14971:2019, ISO 45001:2018 (OH&S), ISO 37001:2016 (Anti-bribery), ISO 22320:2018, ISO 22316:2017, ISO 22317:2021, ISO 22318:2021, ISO 27031:2011, and ISO 22395:2018. You can also build fully custom questionnaires for company-specific protocols.

  • Three steps: (1) Assess your posture using ISO templates or custom questionnaires; (2) Public-source retrieval surfaces relevant reporting on vendors, regulatory signals, and incident context; (3) Generate governance outputs — actionable PDF reports, risk scoring, and stakeholder-ready documentation.

  • Every plan includes secure sign-in, risk scoring, response history, PDF report exports, and a user-friendly dashboard for tracking compliance progress. Pro and Agency tiers add the Investigation Task Manager and secure chat-thread organisation.

  • Nexus is the AI intelligence assistant for investigators; Sec Manager is the governance and risk-management layer for security organisations. They are complementary and can be used independently.

Discuss a mission requirement.

Speak with Next Sight about deploying Sec Manager. alongside our services, training, and operational support.