Skip to main content

What’s New in Hyver – August 2025

ISO 42001 → NIST CSF 2.0 mapping, MITRE D3FEND → CSF 2.0 mapping, and automated STORM ingestion in Hyver.

Updated over a month ago

Overview

This article walks you through the updates released in Hyver during August 2025. You’ll see how new standards mappings improve your Maturity Assessment and how integrations make it easier to keep findings current. These changes help ensure that your Exposure values and mitigation planning reflect the most accurate, real-world context.


ISO 42001 mapping to NIST CSF 2.0

What’s new

Hyver now supports mapping of ISO 42001 (the international standard for Artificial Intelligence Management Systems) to NIST CSF 2.0 within Maturity Assessment.

Why it matters

With this new mapping in Hyver, you can leverage the results of your ISO 42001 certification audit to influence your Maturity Assessment scoring — making your Exposure value more accurate and ensuring it reflects your AI management system.

Where to find it

Go to Maturity Assessment → open Standards to view the new ISO 42001 → NIST CSF 2.0 mapping. You can also use the ISO 42001 filter to see only the subcategories with available mappings:


MITRE D3FEND mapping in Maturity

What’s new

Hyver now maps MITRE D3FEND defensive techniques to NIST CSF 2.0 subcategories in Maturity Assessment.

Why it matters

Unlike MITRE ATT&CK (which catalogs attacker behaviors), D3FEND focuses on defensive actions such as hardening, isolation, and detection. With this update, you can see which actionable D3FEND techniques align with each CSF 2.0 subcategory. This makes it faster to plan remediation strategies using specific, recognized defensive techniques.

Where to find it

Open any CSF 2.0 subcategory in Maturity Assessment → check the Standards tab for mapped D3FEND techniques. Use the D3FEND filter to view only the subcategories with available mappings:


STORM integration

What’s new

Hyver now integrates directly with STORM, enabling automated ingestion of findings.

About STORM

The STORM system (also known as D.Storm) is a cyberattack simulation platform focused on distributed denial of service (DDoS) attacks. It helps organizations test their readiness, safeguard business continuity, and strengthen defenses against real-world threats.

Why it matters

Instead of manually transferring data, findings from STORM are now pulled into Hyver automatically. They are also tagged and mapped, giving you a continuous, real-time view of your security posture. This keeps your remediation workflows consistent and up to date.

Where to find it

Enable the integration under SettingsIntegrationsSTORM:

You’ll need admin permissions in Hyver to set up the STORM integration. If that’s you, you can follow the full step-by-step guide here.


Wrap-up

That’s it for August’s updates — three new features that tighten the connection between standards, defensive practices, and live data. Feel free to explore them all at once or try them gradually, depending on your current workflows.

Did this answer your question?