AutoFix AI

Other tools tell you what's broken.CYBERWHITE deploys the fix.

One click pushes verified Microsoft Graph policies for Essential 8 and SMB1001. Snapshot first, deploy honestly per Microsoft's actual mode (report-only where Microsoft supports it, active for the rest), verify, and roll back any change with a single click if anything looks off.

Plus baseline SOC 2 M365 policies (MFA + access review). NIST CSF, NIST AI RMF and CIS v8 are covered by assessment + CARS prioritisation + evidence collection.

56

fixes deployed in one click

Drata, Vanta, Secureframe: 0

151

controls covered

Essential 8, SMB1001 and SOC 2

1 click

rollback on any change

Snapshot taken before every deploy

REPORTS vs REMEDIATES

Most compliance platforms find the gap and stop there. You still have to fix it.

Drata · Vanta · Secureframe

Reporting tools

  • Scan your tenant for compliance gaps
  • Produce reports for auditors
  • Show you which controls are failing
  • You implement every fix manually in M365
  • No snapshot, no rollback, if a policy breaks something, you debug it

CYBERWHITE AutoFix

Remediation engine

  • Scan your tenant for compliance gaps
  • Produce reports for auditors
  • Show you which controls are failing
  • Pushes the fix in one click. Verified Microsoft Graph policy library
  • Snapshot before every deploy. One-click rollback. Audit trail of every change.
How AutoFix Works

Four steps. Every action. Every time.

No black box, no surprises. Every AutoFix action runs the same disciplined sequence.

1

Snapshot

Before changing anything, CYBERWHITE captures the current state of the M365 setting via Graph API. Stored as a rollback record with a timestamp.

2

Execute

Deploys the policy via Microsoft Graph API. Where Microsoft supports it (e.g. Conditional Access), it starts in report-only so you can review impact before enforcing. Other policy types deploy active and can be rolled back instantly.

3

Verify

Re-queries Graph API to confirm the policy is applied. Verification result + timestamp written to the audit log. No "fire and forget."

4

Roll back (anytime)

One click restores the snapshot. If a user complains, if the policy needs tuning, if anything looks off, undo in seconds. Audit log records every roll back too.

The AI does the homework. The engine does the deploy.

AutoFix AI never changes your tenant on its own. The deployment is a deterministic, verified policy library with snapshot and rollback. The AI is the expert beside your engineer.

Explains every control

The risk, and the benefit, in your framework's language.

Writes the steps

Manual where Microsoft has no API, automated where it does, with prerequisites.

Proves it worked

Engineer-grade verification steps to confirm the policy is live in M365.

Tailored to your tenant

Specific to your environment, not generic advice.

Responsible AI

AI that earns an engineer's trust

Our AI explains and guides, then gets out of the way. It never touches your tenant, never leaves Australia, and is never trained on your data. Built for IT teams who don't hand production to a chatbot.

Hosted in Sydney. Stays in Australia.

Inference runs on private, enterprise Azure OpenAI in the Australia East (Sydney) region. Your tenant configuration and compliance data are processed in Australia and do not leave it. When your auditor asks where the data goes, the answer is simple.

Private. Not public ChatGPT.

This is our own enterprise Azure OpenAI deployment. Your prompts and your data are never used to train any model, never shared with OpenAI, and never pooled with other customers.

Explainability only. No write access.

The AI reads and reasons, it does not act. It explains each control, the risk, the remediation steps and how to verify the fix. It has no path to deploy or change anything in your tenant. Every change is a deterministic policy your engineer approves.

Used only where it earns its place.

We apply AI per control, only where it adds real value: turning a raw gap into a framework-grade plan your engineer can action in seconds. What the control is, why it matters, the exact steps, and how to confirm it works. Not a gimmick bolted on the side.

The AI advises. Your engineer decides. The deterministic engine executes, with a snapshot and one-click rollback on every change. Your IT team gets an expert co-pilot for the thinking, and an auditable engine for the doing.

56 fixes deployed for you. 151 controls covered.

We map 151 remediation actions across Essential 8 (ML1 and ML2), SMB1001 and SOC 2, and CYBERWHITE deploys 56 of them straight into your Microsoft 365 tenant in one click. The rest we scan, license-check, deep-link, or track as attestations, so nothing slips through. Reporting tools hand you the whole list and walk away.

Essential 8 ML1

48

remediation actions

MFA, patching, macros, admin privileges, application whitelisting, backups

Essential 8 ML2

59

remediation actions

PIM, ASR rules, conditional access tightening, audit log retention, AppLocker

SMB1001 (Bronze → Diamond)

42

remediation actions

Defender Antivirus, Windows Firewall, automatic updates, strong password policy, TLS 1.2+

SOC 2 (M365 mapping)

2

remediation actions

CC6.1 MFA enforcement + access review baseline

What AutoFix does NOT do

NIST CSF, NIST AI RMF and CIS v8 are covered by assessment, CARS prioritisation and evidence collection, but no AutoFix actions today. Same for organisational controls (policies, training, vendor reviews) which can't be deployed via API. For those, CYBERWHITE collects evidence and tracks completion while your team implements.

Honest categorisation

Not every control is one-click. We tell you which is which.

Every action in our registry is labelled with one of five categories so you know what to expect before you approve a deployment.

graph_deployable

Real Graph API call. CYBERWHITE writes the policy straight into your tenant in one click. 56 of the highest-impact E8 and SMB1001 controls deploy this way (MFA, ASR rules, firewall, patching). Reporting tools deploy none of them.

license_gated

Deployable IF the tenant has the required M365 license (e.g. E5, P2). Otherwise CYBERWHITE shows the manual instructions instead.

detection_only

We can scan and prove compliance, but there's no policy to deploy (e.g. audit logs that are already on by default).

portal_manual

Must be configured in a specific admin portal (e.g. Defender Security Center). CYBERWHITE provides the deep link + step-by-step guide.

attestation_only

Business-process control. Your team attests yes/no with evidence. CYBERWHITE tracks the attestation and reminds you to renew it.

Why this matters

Other tools claim "automated everything." We're honest: not every control fits an API. Knowing which controls we deploy vs which need manual work makes audit prep predictable.

Built for admin access. Designed for trust.

We're asking for write access to your Microsoft 365 tenant. Here's how we make that safe.

You decide what gets deployed

CYBERWHITE never deploys a policy automatically. Every AutoFix requires you to click deploy on a specific recommendation in the dashboard. Without that click, nothing changes in your tenant.

Connect for assessment. Deploy when you're ready. Roll back if you change your mind.

Report-only first

Every Conditional Access policy CYBERWHITE deploys starts in report-only mode. You review impact for 24-48 hours before enforcing.

Standard Microsoft pattern, nothing exotic.

Pre-flight checks

Before deploying, CYBERWHITE checks for conflicts, existing policies, excluded users, tenant-specific risks. Surfaces them in the approval screen.

No surprise overrides of your existing setup.

Full audit trail

Every snapshot, deploy, verify, and rollback is logged with timestamp, actor, tenant ID, and the exact payload sent to Microsoft Graph.

Export to your SIEM or auditor on request.

Stop reading reports. Start deploying fixes.

From $199/mo for MSPs. $99/mo for direct businesses. Cancel anytime, no contract.