
One place for your risk register, your controls and the evidence behind them.
Horizon is the platform we use alongside our consultants to keep cyber risk, control status and remediation work visible between reviews — not a replacement for the advice, but a live record of it.
Risk information that lives in the last meeting, not in one place.
Most organisations we meet already have some version of a risk register. It usually sits in a spreadsheet that was last properly updated before the last audit, held together by whoever inherited it, with control status tracked in a different document and evidence scattered across email attachments and a shared drive nobody fully trusts. None of this is a criticism — it's the natural result of risk management being treated as a periodic exercise rather than ongoing work.
The practical cost shows up in specific ways. A risk owner leaves and nobody updates the record. A control gets marked 'in progress' and stays that way for eighteen months because there's no review date attached to it. An auditor asks for evidence of a control operating, and the file that proves it expired without anyone noticing until the meeting itself.
Board and audit committee reporting compounds the problem, because someone has to manually reconstruct a current picture from documents of varying age before every meeting. That reconstruction takes time, introduces errors, and tends to flatter the position slightly because whoever is building the report is working from what they can find rather than what's actually true.
Vulnerability remediation adds a further layer. Scanning tools produce findings, but those findings rarely connect back to the risk register or the control they relate to, so a genuinely serious vulnerability can sit unaddressed for months while looking, on paper, like routine IT hygiene rather than a live risk.
None of this means the organisation is being careless. It usually means the record-keeping hasn't kept pace with the volume of decisions being made, and nobody has had the time to build something better while also doing the day job.
- Risk registers that are accurate on the day they're built and stale within weeks
- Control status tracked separately from the evidence that proves it
- Vulnerability findings disconnected from the risks they actually affect
- Board reports rebuilt from scratch, from documents of uncertain age, before every meeting
A live record your consultant maintains with you, not for you alone.
Horizon isn't something we hand over and leave you to run. Your Secure Chain consultant works inside the same platform, building the initial risk register with you, agreeing scoring criteria that reflect your actual business rather than a generic template, and assigning owners and review dates that get followed up rather than ignored.
Controls sit alongside the risks they mitigate, mapped to Cyber Essentials and ISO 27001:2022 Annex A so you can see which requirements are already met and where the genuine gaps are. This mapping is there to support the work your consultant does — it doesn't replace the judgement involved in deciding what 'good enough' looks like for your business, and it isn't a certificate in itself.
The evidence library keeps the documents that prove a control is operating — policies, configuration exports, training records, supplier assurances — attached to the relevant control, with expiry reminders so nothing quietly goes out of date before the next review.
Where Secure Chain also provides vulnerability management or managed security services, remediation data from that work flows into Horizon, so an open vulnerability shows up against the risk and control it actually affects rather than sitting in a separate scanner report that nobody cross-references.
Your consultant reviews the register with you on an agreed cadence, and the platform reflects those conversations as they happen rather than requiring a separate write-up afterwards. The thinking stays with the consultant; Horizon is where that thinking is recorded, tracked and made visible to the right people.
- Risk register built and reviewed with your consultant, not populated automatically
- Controls mapped to Cyber Essentials and ISO 27001:2022 Annex A
- Evidence attached to the control it proves, with expiry reminders
- Remediation tracking connected to the risk it relates to, not held separately
Everything in the engagement, set out up front.
Horizon access forms part of your Secure Chain engagement, alongside the consultancy work it supports.
Live risk register
Risks scored, owned and dated for review, updated as your consultant identifies or reassesses them.
Control management
Controls tracked against Cyber Essentials and ISO 27001:2022 Annex A, showing status and ownership.
Evidence library
Supporting documents held against the control they evidence, with expiry reminders so nothing lapses unnoticed.
Remediation tracking
Open vulnerabilities from Secure Chain managed services linked to the risk and control they affect.
Supplier and third-party register
Key suppliers recorded with an assurance status, so third-party exposure sits alongside your own risk picture.
Role-based access
Your team and your Secure Chain consultants see the views relevant to them, controlled by role rather than a blanket login.
What you receive.
- Populated risk register with scoring, owners and review dates
- Control library mapped to Cyber Essentials and ISO 27001:2022 Annex A
- Evidence documents attached against each relevant control
- Supplier and third-party register with assurance status
- Remediation items linked to the risks and controls they affect
- Role-based user access for your nominated team members
- Exportable summary suitable for internal reporting
- Agreed review cadence with your Secure Chain consultant
Built for organisations that need the work done properly.
Organisations replacing a spreadsheet register
Businesses whose risk record has outgrown a document and needs owners, dates and evidence attached properly.
Firms working towards Cyber Essentials or ISO 27001
Organisations that want their control status mapped clearly against the framework they're targeting.
Businesses using Secure Chain managed services
Clients whose vulnerability remediation work should sit against the risk register it actually informs.
Growing companies with more suppliers to track
Organisations whose third-party exposure has grown past what an informal supplier list can manage safely.
What changes once the work is done.
What changes once your risk record lives in Horizon rather than scattered documents.
One current view
Risk, control and evidence status that reflects this week, not the last time someone rebuilt the spreadsheet.
Nothing quietly expires
Evidence and review-date reminders catch lapses before they surface in an audit or a client questionnaire.
Remediation with context
Vulnerabilities tracked against the risk they affect, not left as an isolated scanner output.
Faster, more honest reporting
Board and executive reporting drawn from the live record rather than reconstructed under time pressure.
Clearer accountability
Every risk and control has a named owner and a date, so follow-up doesn't depend on memory.
A record that survives staff changes
New risk owners inherit context and history instead of starting from a blank document.
Where Horizon sits alongside the consultancy work.
It's worth being clear about what Horizon is and isn't. It's a platform, not a consultancy in itself, and it doesn't decide what your risk appetite should be, which controls matter most for your business, or how to prioritise a limited budget against a long list of gaps. Those decisions come from the consultants who use it alongside you, drawing on experience across similar clients and sectors.
What the platform does well is remove the friction that usually gets in the way of that advice being acted on — the register that's hard to find, the control status that's out of date, the evidence that was somewhere but nobody can locate it under time pressure. Horizon keeps that record current so the conversation with your consultant can focus on what to do next rather than on reconstructing what's already true.
We built Horizon around the way our own consultants actually work with clients across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London — risk workshops, control reviews and evidence collection that happen on a cadence, not a once-a-year scramble. The platform reflects that rhythm rather than imposing a different one on you.
If you already use Secure Chain for vulnerability management or managed security, Horizon is where that work becomes visible against your wider risk position rather than sitting in a separate report. If you don't yet use those services, the platform still gives you a properly structured register and control library, built and reviewed with a consultant rather than left to maintain alone.
Questions we are asked most often.
What is Secure Chain Horizon, exactly?
Horizon is our UK-hosted platform for tracking cyber risk, controls, evidence and remediation in one place. It's the working record we and your team use during an engagement — a live risk register, control mapping, an evidence library and a view of open vulnerabilities — rather than a set of spreadsheets and email threads that go stale between reviews.
Does Horizon replace our consultant or our IT provider?
No. Horizon holds the record and does the calculations; the judgement about what a risk means for your business, which control gaps matter most, and what to do next still comes from your Secure Chain consultant. The platform makes that advice visible and trackable rather than replacing the thinking behind it.
How does the risk register get populated?
Your consultant builds the initial register with you during onboarding, drawing on risk workshops, existing documentation and any assessment work already completed. From there, risks are added, scored, assigned an owner and given a review date as they're identified, so the register reflects live conversations rather than an annual exercise.
How does Horizon connect to vulnerability data?
Where Secure Chain provides managed vulnerability scanning or managed security services, the remediation data from that work feeds into Horizon so open vulnerabilities appear alongside the risks and controls they relate to. If those services sit elsewhere, we can still track remediation manually against the register.
Which frameworks does the control library map to?
Controls in Horizon are mapped against Cyber Essentials and ISO 27001:2022 Annex A, so you can see at a glance which controls satisfy which requirement and where the gaps sit. This is a mapping to support the work, not a certification in itself — assessment against either scheme is still carried out by the relevant body.
Who can see what inside Horizon?
Access is role-based. Your executive team, risk owners and technical staff see the views relevant to them, and Secure Chain consultants have the access needed to support the engagement. You control who from your side is added, and access can be adjusted as roles change.
Is our data hosted in the UK?
Yes, Horizon is UK-hosted. Data residency is a question we're asked often by organisations in regulated sectors, and it's a deliberate part of how the platform is run rather than an afterthought.
What does it take to get started?
A new client engagement typically starts with a working session to scope your risk register and confirm which controls and evidence you already hold. Horizon access follows once that scoping is done, so the platform reflects your actual environment from day one rather than a generic template.
Executive cyber dashboard
How the same Horizon record is turned into board and audit committee reporting.
Vulnerability management as a service
The managed scanning and remediation work that can feed directly into Horizon.
Compliance support
Consultancy across ISO 27001, Cyber Essentials and other frameworks that Horizon's controls map against.
See Horizon working against a register like yours.
We can walk you through the platform with a risk register and control set similar to your own, or start with a free consultation to talk through what your current setup is missing.
Book a Horizon walkthrough