All your GRC, driven from a single tool

ISO 27005 risk analysis, multi-framework compliance and action plans — from risk to decision. Sovereign, hosted in Europe.

Covers
ISO 27001 NIS2 DORA GDPR HDS
Hosted in Europe
1,200+ CISOs, DPOs, CIOs supported

All your GRC, in one tool

Beyond the feature list, six value promises structure the platform. Each pillar embeds several operational modules.

Risk

Identify, assess and quantify your risks using the ISO 27005 approach. AI-generated scenarios, interactive risk matrix, annual financial quantification.

ISO 27005 scenarios per asset
Interactive 4×4 risk matrix
Financial risk quantification

Compliance

Audit ISO 27001, NIS2, DORA, GDPR and HDS simultaneously. Security policies, records of processing activities, Statement of Applicability tracking.

93 ISO 27001:2022 controls
NIS2, DORA, GDPR, HDS pre-loaded
Security policies & DPIA

IT Assets

Map your applications, servers and services with CIA scores. Feared events, business impacts, cross-navigation between assets and risks.

Application inventory
Confidentiality / Integrity / Availability scores
Feared events & business impacts

SecOps

Anticipate threats with Threat Intelligence correlated to your assets, automated OSINT and the Phishia phishing simulation module.

Contextualised Threat Intelligence
OSINT & digital footprint
Phishing simulation (Phishia module)

Third parties & insurance

Manage supplier risks (TPRM), monitor your supply chain and generate your cyber-insurance underwriting files.

Supplier questionnaires & scoring
Continuous NIS2 supply-chain monitoring
Automated cyber-insurance files

Governance

Multi-entity steering, integrated DMS, professional exports (PDF, PPTX, XLSX) and executive dashboards.

Multi-tenant & granular access control
PDF / PPTX / XLSX exports
Executive dashboards

What you concretely get

Three examples of deliverables produced directly by Galea — an exact reflection of what your teams handle day to day.

R3
R1
R2
R4
R5
R6
Risk

Interactive 4×4 risk matrix

Overview of your scored risks, clickable and filterable by entity or framework.

RISK REGISTER
R1 ERP ransomware 16
R2 HR data leak 12
R3 SaaS CRM downtime 9
Steering

Centralised risk register

All your risks in one place, with owner, treatment status and history.

ISO 27005 REPORT
2026 Risk Analysis
PDF
42 p.
Deliverables

Exported ISO 27005 report

A PDF ready to present to your executive committee, defensible to auditors and insurers.

Artificial intelligence

A sovereign AI,
cyber-specialised

Galea doesn't just answer: it executes your GRC workflows, from the risk scenario to the action plan. A human expert always remains the decision-maker — that's the dual scoring AI / Expert.

How our AI works
GALEA
Support

Expert support
beyond the tool

Galea is more than a platform. Our Phishia team supports your people — initial audit, training, operational follow-up — to turn the rollout into a measurable success.

Initial audit of your cyber and regulatory context
Training for CISO, DPO and business teams
Operational follow-up & campaign review
Phishing simulation and continuous awareness
Discover Phishia
Phishia
Awareness & phishing
50+
Templates
Campaigns
+38%
Awareness

Ready to secure your organisation?

Personalised 30-min demo, no commitment. Free trial available.

Free trial — No credit card

Ready to secure your organisation?

Join the companies that trust Galea to drive their cyber-résilience. 30-minute demo.

Already a customer? Go to the platform