Skip to content
English
  • There are no suggestions because the search field is empty.

Getting Started With Security Resources

Security Resources are the inventory of what your organisation actually runs, owns and relies on, and they are what your controls, business systems and threat simulations are evidenced against.

Security Resources, under Catalogue > Security Resources, is your record of the things that make up your security posture: the technology you run, the people who operate it, the providers you depend on, and the documentation that governs it. It matters because almost everything else in CyberHQ eventually points back to it. A control is credible when a resource evidences it, a business system is meaningful when you know what it is built from, and a threat simulation can only produce a financial case when the resources involved carry costs.

The four types of resource

Every resource is one of four types, and the type determines what you record against it:

  • Technology covers software, hardware and infrastructure. Your firewalls, your endpoint protection, your logging platform.

  • People covers roles and staff who perform a security function, whether that is a dedicated security team or someone carrying the responsibility alongside another job.

  • Service Providers covers the third parties who deliver part of your security for you, such as a managed detection provider. Where you also assess that provider as a vendor, you can link the two so the assessment and the dependency sit together.

  • Documentation covers the policies, standards and procedures that govern how the rest of it works.

The split matters because it changes what a resource can evidence. A policy document is the right evidence for a governance control in a way that a firewall is not.

What to record, and why it pays off later

Beyond a name and description, three fields do more work than they first appear to:

  • Criticality tells you and everyone else how much the organisation depends on this resource. It is what lets you answer "what matters most here" without reading the whole inventory.

  • Cost is what makes financial modelling possible. A resource can carry a purchase or capital cost, an ongoing operating cost and a one-off non-recurring cost. Threat simulations use these to produce a return on investment figure, so a resource with no cost recorded contributes nothing to that calculation. If you intend to use Threat Modelling to justify spend, record costs as you go rather than retrofitting them later.

  • Expiry date drives renewal reminders, covered below.

For People resources you can additionally record what they are responsible for, how many days a week they are available, and whether they are key personnel. That last one is worth using honestly: it is how you surface a single point of failure that happens to be a person rather than a system.

Renewal and expiry reminders

Any resource can carry an expiry or depreciation date, which is what turns your inventory into something that tells you when to act rather than something you have to remember to read.

Where reminders are enabled for your workspace, CyberHQ sends a warning ahead of the date and a further notice once it passes. By default the warning arrives 90 days before expiry, which suits annual licences and contracts.

Two details are worth knowing:

  • Reminders go to the resource's owner, and the expiry notice goes to your administrators as well. A resource with no owner sends everything to your administrators, so assigning owners is what stops renewals becoming one person's problem.

  • Extending a date re-arms the reminders. Push an expiry date into the future and both notices reset, so a renewed contract warns you again next cycle without anything to reconfigure.

Bringing resources in, and getting them out

You can add resources one at a time, upload many at once from a CSV template, or link a connect to your CyberHQ workspace to import them from an external platform. Each route is described in How to Add and Edit a Security Resource. Export works the same way in reverse, which makes bulk editing practical: export, edit the spreadsheet, upload it back. See How to Export your Data to CSV.