๐ŸŽ‰ Early-Bird Launch Offer โ€” 50% Off EARLYBIRD Discounted rate stays while your subscription remains active
๐Ÿ›ก๏ธ SME Cybersecurity Plans

Cybersecurity that turns alerts into action.

Your own SOC โ€” without building one.

CiBRAI gives smaller organisations a practical operating layer for detection, investigation, response and security management โ€” in one secure, isolated workspace. Deploy a guided agent to Windows, macOS or Linux machines, and start building visibility today.

๐Ÿ–ฅ๏ธ Windows ยท macOS ยท Linux
๐Ÿ”’ Isolated AU-hosted tenant
๐Ÿค– Agentic AI built-in
๐Ÿ“‹ Cancel anytime
Early-Bird Launch Pricing

Choose the level of coverage that fits today.

Use code EARLYBIRD for 50% off any self-service plan. The discounted rate stays in place while your subscription remains continuously active.

Most Popular
SME
SME
Small business getting real SOC coverage
$1,990 SAVE 50%
$995
AUD / month โ€” with code EARLYBIRD
๐Ÿ–ฅ๏ธ Up to 10 machines
โœ“ Cross-platform agents
โœ“ Live SIEM alerts
โœ“ Core Agentic AI
โœ“ Case and incident management
โœ“ Guided forensic investigation
โœ“ Core threat intelligence
โœ“ Isolated tenant
โœ“ Email and in-app support
Get Started โ†’
GROWTH
Growth
Scaling teams building a real security function
$3,990 SAVE 50%
$1,995
AUD / month โ€” with code EARLYBIRD
๐Ÿ–ฅ๏ธ Up to 25 machines
โœ“ Everything in SME
โœ“ Automated threat enrichment
โœ“ MITRE ATT&CK context
โœ“ Essential Eight reporting
โœ“ Saved watchlists
โœ“ Scheduled AI reviews
โœ“ Priority support
Get Started โ†’
BUSINESS
Business
Multi-site and more complex operations
$6,990 SAVE 50%
$3,495
AUD / month โ€” with code EARLYBIRD
๐Ÿ–ฅ๏ธ Up to 50 machines
โœ“ Everything in Growth
โœ“ Automated response playbooks
โœ“ Custom detection rules
โœ“ Advanced case correlation
โœ“ Enhanced forensic workflows
โœ“ Dedicated onboarding session
Get Started โ†’
ENTERPRISE
Enterprise
Large estates, defence and regulated industries
 
Let's Talk
Custom pricing โ€” scoped to your environment
๐Ÿ–ฅ๏ธ 51 to 250+ machines
โœ“ Everything in Business
โœ“ Dedicated or on-premise deployment
โœ“ SSO and SAML
โœ“ Custom integrations
โœ“ Private threat feeds
โœ“ Custom AI workflows
โœ“ Named security engineer
Contact Us โ†’
๐Ÿ“‹ SME, Growth and Business are month-to-month self-service subscriptions. Cancel anytime. GST, fair-use conditions and full terms confirmed at checkout.
Included across every self-service tier
Every plan includes the core operating layer โ€” from day one.
โœ“ Isolated customer tenant
โœ“ Cross-platform agents (Win ยท Mac ยท Linux)
โœ“ Live SIEM alerts and monitoring
โœ“ Case and incident management
โœ“ Core Agentic AI assistance
โœ“ Guided forensic investigation
โœ“ Threat intelligence context
โœ“ Human approval and audit trail
Detect, Investigate, Respond and Manage

One operating model across the full cyber workflow.

CiBRAI connects detection, investigation, response and management activities so the evidence collected at the start of an incident remains available through containment, closure and reporting.

Step 01
๐Ÿ”

Detect

Live SIEM alerts, endpoint activity, anomaly scoring and a prioritised threat queue.

Live SIEM alerts and event monitoring
Anomaly scoring and prioritisation
Health monitoring and asset visibility
Step 02
๐Ÿ”Ž

Investigate

Cases, threat intelligence, MITRE ATT&CK context, email analysis, timeline and evidence review.

Case and evidence management
MITRE ATT&CK mapping
Email and indicator analysis
Step 03
โšก

Respond

Tasks, approvals, playbooks, containment recommendations, remediation tracking and closure evidence.

Human-approved response actions
Automated playbooks (Growth+)
Full audit trail retained
Step 04
๐Ÿ“Š

Manage

Essential Eight reporting, risk and posture views, executive summaries and trend reporting.

Essential Eight reporting (Growth+)
Board-ready executive summaries
Control evidence and trend reporting

From sign-up to useful security in minutes.

Most organisations can connect the first supported machine quickly. Coverage expands as you tune and add devices.

First 15 Minutes

Your isolated tenant is provisioned. Confirm the primary administrator, notification address and basic workspace settings.

First Hour

Deploy the agent to initial Windows, macOS or Linux machines. Security events and asset context begin to arrive.

First Day

Review the first alerts, validate expected activity, invite additional users and establish initial notification rules.

First Week

Tune detections, confirm case workflows, review the first posture summary and decide which machines to add next.

Capability Matrix

Detailed plan comparison.

Core = available in plan. Enhanced = more automation, context or scale. Advanced = broader correlation and customisation. Scoped = defined in Enterprise order form.

Core operations

CapabilitySMEGrowthBusinessEnterprise
Monthly standard price$1,990$3,990$6,990Quoted
Early-bird monthly price$995$1,995$3,495Quoted
Monitored machinesUp to 10Up to 25Up to 5051โ€“250 standard scope
Windows, macOS and Linux agentsโœ“ Includedโœ“ Includedโœ“ Includedโœ“ Included
Isolated customer workspaceโœ“ Includedโœ“ Includedโœ“ IncludedDedicated or on-premise
Live SIEM alerts and event monitoringCoreCoreEnhancedAdvanced / tailored
Agentic AI alert explanationCoreEnhancedAdvancedCustom workflows
Case and incident managementCoreCoreEnhancedAdvanced / tailored
Guided forensic investigationCoreEnhancedAdvancedTailored
Core threat intelligence contextโœ“ Includedโœ“ Includedโœ“ Includedโœ“ Included
Human approval and action audit trailโœ“ Includedโœ“ Includedโœ“ IncludedTailored RBAC
SupportEmail + in-appPriorityPriority + onboardingNamed engineer
CancellationAnytimeAnytimeAnytimeOrder form

Intelligence, response and governance

CapabilitySMEGrowthBusinessEnterprise
Automated threat intelligence enrichmentOn demandโœ“ IncludedAdvancedPrivate or custom feeds
MITRE ATT&CK mappingGuidedโœ“ IncludedAdvancedTailored
Essential Eight reportingNot includedโœ“ Includedโœ“ IncludedTailored compliance scope
Scheduled multi-agent reviewsLimitedโœ“ IncludedAdvancedCustom schedules
AI-generated executive summariesCoreEnhancedAdvancedTailored
Automated response playbooksNot includedGuidedโœ“ IncludedCustom
Custom detection rulesNot includedStandard libraryโœ“ IncludedCustom engineering
SSO and SAMLNot includedNot includedOptionalโœ“ Included / scoped
Dedicated tenancy or on-premiseNot includedNot includedNot includedโœ“ Available
Named security engineerNot includedNot includedOnboarding sessionโœ“ Included
Custom connectors and integrationsAdd-onAdd-onAdd-onโœ“ Included / scoped
Managed monitoring or DFIR serviceAdd-onAdd-onAdd-onScoped
๐Ÿ’ก This matrix is a customer-facing guide. Confirm final inclusions, fair-use limits, retention, support SLAs and integration scope at checkout or during your onboarding conversation.
Clear Expectations Before You Subscribe

Frequently asked questions.

Everything you need to know before getting started.

Is this a fully managed 24x7 SOC service?

No. SME, Growth and Business are primarily self-service subscriptions. Managed monitoring, co-managed operations, incident response and DFIR services can be scoped separately.

What counts as a monitored machine?

One supported Windows, macOS or Linux endpoint or server with an active CiBRAI agent connected to your tenant. Final treatment of offline or retired machines is defined in the subscription terms.

Will CiBRAI replace our antivirus?

Not necessarily. CiBRAI provides monitoring, event correlation, investigation, cases, intelligence and response workflows. It is designed to work alongside existing endpoint protection and other security controls.

How does the AI make decisions?

Agents analyse the evidence and permissions available to your tenant, then explain findings and recommend next steps. High-impact actions are held for an authorised human decision and recorded in the audit trail.

What does the forensics capability include?

Operational investigation, evidence linkage, timelines, case notes, endpoint and log context, indicator enrichment and report export. Specialist acquisition, legal chain-of-custody and expert witness services are separate.

Where is our data kept?

The self-service plans are designed for isolated Australian-hosted tenancy. Enterprise customers can discuss dedicated and on-premise deployment. The final order form defines data location, retention and subprocessors.

Can we upgrade later?

Yes. Start with the machine count and capability level that fits today, then move to a larger plan as your environment, compliance obligations or response needs grow.

Can we cancel?

SME, Growth and Business are proposed as cancel-anytime subscriptions, subject to the final billing and cancellation terms. Enterprise arrangements are governed by the applicable order form.

๐Ÿš€ Ready to start?

Begin building security visibility today.

Choose the plan that fits your current machine count, use code EARLYBIRD, deploy the first agent and start building visibility. For more complex environments, contact CiBRAI for a short scoping conversation.

Use code EARLYBIRD โ†’ 50% off, applies at checkout
Choose your plan
Get started online โ†’
Book a walkthrough
info@cibrai.com
Enterprise scoping

Dedicated and on-premise options โ€” contact us to discuss