From org chart to signed-off report.
Set the group up once, then run an assessment against it on whatever cadence you need. Six steps, one cycle.
Map the group
Add every entity in the corporate group and how they nest — from the holding company down to each plant, service or subsidiary.
Assign frameworks & standards per entity
Put each entity on the Framework or standard it actually answers to.
Score with evidence
Mark each control local, inherited or hybrid, attach the evidence behind it, and attest. Inherited scores aren't trusted until the chain is verified.
Watch posture roll up
Scores aggregate into criticality-weighted group figures, worst-case by function, and the profile radar — the whole group at a glance.
Work the gaps
The gap register ranks gaps by criticality and points each at the entity where the fix belongs. Turn any gap into an owned remediation action.
Sign off & report
An engagement lead finalises the cycle and exports the audit report — scores, gaps, maturity and evidence, as a dated artifact.
When one entity sets a control, everything below it inherits the score.
Groups aren't flat. Shared services set controls that every subsidiary depends on. Gjallarhorn tracks that inheritance, so a weak score surfaces where the problem actually sits.
Inheritance-aware scoring
Every control is local, inherited, or a blend, and an inherited score isn't trusted until it carries a verified attestation.
Fix upstream, once
Each gap names the entity where the fix belongs and shows how many entities one fix clears.
Criticality-weighted rollups
Group scores weight each entity by how critical it is, and name the weakest one per function.
Different entities, different requirements.
A group can run NIST CSF 2.0 as its common language, keep one subsidiary certified to ISO 27001*, and hold another to the Essential Eight. Each entity is assessed against the framework or standard it answers to, and scored the way that model actually works.
NIST CSF 2.0
All six functions and 106 subcategories, scored 0–4 against a target profile.
ISO/IEC 27001:2022*
Annex A coverage for the entities that carry certification, in the same posture model as everything else.
Essential Eight
Maturity is gated, not averaged. A strategy reaches ML2 only when every ML1 and ML2 control passes; one failure drops the level.
Every gap gets an owner, a due date, and a paper trail.
Gaps come straight from the scores, ranked by criticality, each pointing at the entity where the fix belongs. Assign one to a person with a deadline, track it to done, and close the cycle with a sign-off and a report you can hand to an auditor.
| Control | Current → Target | Where to fix |
|---|---|---|
| GV.OC-01 | 3 → 4 | ⌖ Fix here → clears 2 gaps |
| PR.AA-05 | 1 → 4 | ⌖ Fix here → clears 3 gaps |
| DE.CM-01 | 0 → 3 | Fix upstream → Digital Services |
| ID.RA-10 | 2 → 4 | Fix upstream → Meridian Group |
| RS.MA-01 | 1 → 3 | Fix here |
Remediation actions
Owned by a named person, with a due date and status; overdue work is flagged.
Findings & exceptions
Rate an observation, or formally accept a risk with an expiry date.
Sign-off & report
An engagement lead signs the cycle off, and the report lays out scores, gaps, maturity and evidence.
Isolated per tenant
Each tenant's data stays separate; access is invite-only and scoped to specific entities.
SSO only
Sign in with Google or Microsoft.
Backed by evidence
Every score links to the evidence and attestation behind it.