Skip to content

Cybersecurity CRM

In cyber security the work sold is tied to a date window and a written authorisation; when the scope and the authorisation document do not match, the test does not start. The report delivered is sensitive too — as much as who may see it, when the findings will be retested has to be tracked.

The date the written authorisation was received is a field on the project record; while that field is empty, the rule defined at setup stops the record moving to the testing stage.

Cybersecurity CRM
  • Keep the test scope, the environment and the test window dates in fields on the project record, and set a rule so the stage does not move on before the written authorisation arrives
  • Track report delivery and the retest date as fields, drop the ones whose deadline is approaching into a list and open a task for the person responsible
  • Limit access to the report and its attachments with role-based authorisation, and determine from the role definition which user can see the record
  • Keep monitoring and subscription renewal dates under the account, and queue the request opened on an incident notification and route it with the assignment rule defined at setup
Test ProjectA test is a project record; the number of assets in scope, the environment and the start and end dates of the test window sit in its fields.
Written AuthorisationThe client's written authorisation is a date field; while the field is empty, the record moving to the testing stage is blocked by the rule defined at setup.
Retest DateReport delivery and the retest are each date fields; files whose deadline is approaching drop into a list and a task is opened for the person responsible.
Report AccessThe record and its attachments are subject to role-based authorisation; which user sees the report is read from the role definition.

A penetration testing job is defined not by the quote but by the scope: how many addresses, how many applications, which environment and which date range. After the quote, that information stays in an email chain, and on the morning the test is due to start somebody goes looking for whether the client's written authorisation has arrived. Once the report is delivered the job closes there; yet the period given for the retest that would confirm the findings have been closed expires a few months later, and nobody sends a reminder. The report itself is a separate problem: a document that names open vulnerabilities should not sit in a folder everyone in the company can reach.

In Rapitek CRM every test is a project record; the number of assets in scope, the environment, the start and end dates of the test window and the date the written authorisation was received are fields on that record — and while the authorisation field is empty, the rule defined at setup stops the record moving to the testing stage. Because report delivery and the retest date are fields, the ones whose deadline is approaching drop into a list and a task is opened for the person responsible. The record and its attachments are subject to role-based authorisation; which user sees the report is determined by the role definition. The renewal date of monitoring and subscription services sits under the same account; when an incident notification comes in, the request that is opened drops into the queue and goes to the team on duty through the assignment rule defined at setup.

The scope of the plans and the separately priced items are set out on the pricing page.

Frequently asked questions

Can the system stop a test from starting before written authorisation arrives?
The date the client's written authorisation was received is a field on the project record; while that field is empty, the rule that stops the record moving to the testing stage is defined at setup. You decide at which stage it becomes mandatory, and the record does not move on until that condition is met.
How do we avoid missing the retest period for the findings?
The report delivery date and the period given for the retest are each date fields. Files whose deadline is approaching drop into a list by date and a task is opened for the person responsible; the reminder to go to the client is also planned from the same record.
Can we limit who inside the company can see the vulnerability report?
Yes. The report is an attachment on the test project record, and the record is subject to role-based authorisation; which user sees the record and its attachments is determined by the role definition. Who changed which field and when also sits field by field in the change history.
Which is the best CRM software for cyber security?
When choosing a CRM for the cyber security industry you should look at sector workflows, integration capabilities, customisation options and the quality of support. You do not set Rapitek CRM up, we do: we configure the fields, the stages and the reports around your cyber security process, we migrate your data, and we train your team in Turkish. Before we built our own platform our team completed more than 200 enterprise CRM projects in its Salesforce years; we carry out the setup with that experience.
How much does a cyber security CRM system cost?
In cyber security, because which user sees the report is read from the role definition, people are defined in the system with their roles. We keep current plan prices in one place and publish them openly on our pricing page; we do not put figures on this page, so that you do not read a different price in two places. The price is set by the number of users and the plan chosen. The scope of setup, data migration and training is not the same on every project; the scope and the setup fee, if any, are worked out together in the discovery call and shared in writing. Rapi artificial intelligence credit and ERP integration are separately priced items.
How are CRM integrations done in the cyber security industry?
If you use Logo, Netsis, Mikro or SAP, your CRM talks to it — we build the connection. There is no out-of-the-box module: because the access and field structure on the ERP side change from one installation to the next, a single button does not work the same way everywhere. The connection is built for each project over our REST API covering 183 business objects, OAuth2, webhooks and import/export. We work out the scope and the cost in the discovery call and share them in writing.
How does the move to a CRM system work in the cyber security industry?
We start with a discovery call: we map out your cyber security process, which fields and which stages are needed, together. After the call we give you a date, not a range. We migrate your data and we train your team in Turkish. There is no call centre on our support line. Your question is answered by the team that builds and develops the product — this is a choice, not a matter of capacity.
Can mobile CRM be used for cyber security?
Yes. Field and branch teams can update the customer card, notes and follow-up tasks from their phone. The app is live on both the App Store and Google Play. The web interface also works on tablets and phones. The app does not work offline; if the connection drops while you are filling in a form, what you have typed is kept on the device for 24 hours.
Made with RapitekGO

We would like to use optional cookies to measure your visit. The site works exactly the same if you decline. Cookie policy