About

About this project

Hey there - my name is Sarath, creator of SimplifiedCS. I built this site with one goal: making cybersecurity accessible to everyone.

With over 9 years of experience in cybersecurity and IT, I've seen the hurdles most companies actually run into firsthand, and wanted to design a simpler workflow for getting past them. This isn't meant to be a last-resort or final solution for every cyber need you have - the goal is to minimize risk as much as realistically possible, using existing tools and minimal cost, not to replace a real security program entirely.

A few technical highlights

  • An adaptive decision-graph engine, not a static form - questions branch on industry, region, infrastructure, and prior answers, with a session-wide de-duplication system so nothing is ever asked twice
  • Compounding-risk detection that flags dangerous combinations of gaps, not just individual weak answers - each one mapped to a real MITRE ATT&CK technique, not a generic warning
  • A deliberate hybrid AI architecture: a tested, deterministic scoring engine as the guaranteed-correct core, with an optional live layer checking named vendors against current threat data on top of it
  • Live threat intelligence pulled from CISA's KEV catalog, VulnCheck, ENISA, and NVD, scored by real-world exploitation likelihood via FIRST.org's EPSS model
  • An AI Readiness & Governance question track following EC-Council's Adopt/Defend/Govern framework - scoped to how AI actually shows up in your environment, scored by the same engine, with real MITRE ATT&CK/ATLAS mapping for AI-specific techniques like prompt injection
  • A programmatically-built, selectable-text PDF export, and a real client-side router with working back/forward navigation and shareable URLs - not the "everything is one page pretending to be many" shortcut it's easy to settle for

This is a work in progress, and feedback is genuinely welcome - if you think a feature is missing or something could work better, I'd like to hear about it.

This project is an adaptive cybersecurity assessment and compliance-readiness platform designed for small and medium-sized businesses. It helps organizations understand their current security posture, identify weaknesses, and receive practical recommendations to strengthen their cybersecurity defenses.

The platform is based primarily on the NIST Cybersecurity Framework and CIS Critical Security Controls v8. It guides organizations through structured assessments, highlights security gaps, and provides actionable suggestions to improve their overall resilience.

In addition to security assessments, the platform supports compliance-readiness initiatives across eight frameworks - ISO/IEC 27001, NIS2, SOC 2, HIPAA, GDPR, SOX, Cyber Essentials, and PCI DSS - layered in based on your industry and the regions you operate in, with more frameworks planned as the tool grows. Its long-term goal is to provide businesses with a centralized solution for continuously monitoring, improving, and demonstrating their security and compliance posture.

Most recently, the platform added a hybrid AI layer to the results. Every report is still built first by the same tested, deterministic scoring engine the assessment has run on from the start - that part doesn't change, and it's already complete and accurate on its own. On top of it, an optional live pass checks your named vendors and products against current CISA and NVD vulnerability data, and looks for patterns in your specific answers the fixed rule set wasn't built to anticipate. It's clearly labeled wherever it appears, and it's additive, not a replacement. The assessment itself grew alongside that: a dedicated AI Readiness & Governance track now scores how AI actually shows up in your own environment and how prepared you are against AI-powered attacks, whether or not you've adopted AI yourself - so this site both uses AI carefully in how it builds your report, and assesses how carefully you're using (or defending against) AI in the first place.

The idea behind the mark

Fragments, scattered and disconnected, converging into a single, complete shield. That's meant to mirror what this tool actually does - individually small, disconnected gaps (a missing control here, an unpatched system there) assembling into your real security posture once they're identified and addressed together.