Guide

Getting the most out of the Fortify Portal

What each part of the portal does, where to find it, and how the key features work.

How the portal is laid out

The portal has a dark sidebar on the left for navigation and a main content area on the right. Every feature in Fortify lives in the sidebar — start from the Compliance Hub and Action Hub near the top, or browse the other groups like Supply Chain and Incidents.

app.getfortify.com/portal/acme/roadmap
Fortify
Organisation
Acme Ltd
Dashboard
Getting Started
How to Use
Compliance Hub▾
Audits
Action Hub▾
Findings
Roadmap
Risk Register
Compliance
Policies
user@acme.com
What is this section for?
Your step-by-step plan for closing security gaps.
✕
Roadmap
?
30 daysEnable multi-factor authentication
Open · no evidence attached
30 daysPatch management process
Open

Sidebar

Navigation — always visible

Guidance banner

First-time section intro

? HelpTip

Hover or click for detail

Scout button

Ask questions, bottom-right

Key interface elements

Four things you'll use on nearly every page.

① Help icons

The ? icon next to headings

Every section heading in the portal has a small grey circle with a ? in it. Click it — or hover over it — to see a plain-language explanation of what that section or metric measures, why it matters, and what to do about it.

Useful when you're in a section you haven't used before, or when you want to understand a specific number on the Compliance Health dashboard.

Roadmap
?
Your roadmap groups improvement actions from assessments into 30, 60, and 90-day horizons. Drag to reprioritise within each band.

Click the ? next to any heading for a plain-language explanation.


② Ask Scout

The violet button in the bottom-right corner

The violet circle (always visible in the bottom-right of every portal page) opens Scout — an AI that knows your specific assessment results and can answer questions about your security position in plain language.

  • → “What does this finding mean for my business?”
  • → “Which open findings should I fix first?”
  • → “How do I explain our security score to a customer?”

There's also a full Ask Alex page in the sidebar for longer conversations.

Ask Scout — always here

③ Guidance banners

Blue banners at the top of each section

The first time you visit any section, a blue banner appears at the top explaining what the section is for, who should use it, and why it matters. Once you dismiss it, it won't appear again.

If you want to re-read a banner, clear your browser's localStorage for the Fortify domain — the banners will reappear.

What is this section for?

Track security issues and improvements as you find them.

Every issue gets a reference number and a status so you can show auditors you have a process for identifying and closing problems.

Required for ISO 27001
Dismiss

④ Adding evidence

Attaching files or links to findings

On the Roadmap and Findings pages, you can attach evidence to each item to prove a control is in place. Open any item and use the Evidence panel to upload a file or paste a URL.

  • → Screenshots showing a setting is enabled
  • → Policy documents or configuration files
  • → URLs linking to external records or tools

Use “Export evidence pack” on the Roadmap to download everything as a ZIP for auditors.

30 daysEnable multi-factor authentication

Status: In progress

Evidence

MFA_config_screenshot.png
Attach a file or paste a URL

⑤ Security Goals

Setting and tracking measurable targets

Security Goals (under the ISO 27001 section in the sidebar) are measurable targets that show auditors your programme is actively improving — not just stable.

Set a goal like “reduce open critical findings to zero by Q3” or “achieve 80% policy coverage by year end”. Update the current value monthly. Goals that slip to “at risk” surface on the Compliance Health dashboard.

ISO 27001 requires measurable information security objectives with tracked progress — Security Goals is where you build that record.

Reduce open critical findings to zeroAt risk

Target: Q3 2026 · Owner: Jason

Progress3 / 7 resolved
43%Target: 100%

Where to start

Follow these steps the first time you set up the portal.

01

Complete a free assessment

Go to the home page and take a Digital Resilience, GDPR, or Business Continuity assessment. It takes about 10 minutes. You'll get a PDF report and a session token to import your results.

02

Import your results into the portal

In the portal, go to Assessments and paste your session token. This populates your dashboard score, findings list, and roadmap automatically.

03

Complete Getting Started

The Getting Started checklist walks through your org profile, compliance goal (e.g. ISO 27001), and team setup. Completing it unlocks your full dashboard score.

04

Work through your 30-day roadmap actions

The Roadmap organises your findings into 30, 60, and 90-day actions. Start with the 30-day items. Mark each one in progress and attach evidence when done.

05

Publish your first policy

Go to Policies and generate an Information Security Policy. Edit the draft to match your organisation, then publish it. Drafted policies don't count towards your score.

06

Set at least one Security Goal

Under ISO 27001 → Security Goals, create a measurable target with a deadline. Auditors ask for evidence of planned improvement — this is where you build that record.

07

Run your first quarterly review

Once you've imported an assessment and closed some roadmap items, generate a Quarterly Review PDF. Download it and share with your board or keep it on file.

Portal sections — quick reference

Sign in to the portal and use the sidebar to navigate between sections.

Top level

Dashboard — Overall resilience score and top risks at a glance.
Getting Started — Onboarding checklist and org setup.
How to Use — This guide — return here any time.

Compliance Hub

Compliance Hub — Where to find compliance gaps — status of your assessments and framework audits in one place. Expand it in the sidebar to jump straight to any of the below.
Assessments — Import and review your assessment results.
Audits — Cyber Essentials Plus, ISO 27001, NHS DSPT, DORA, and Business Continuity readiness audits — a progress bar shows how many are included in your plan.
Internal Audits — ISO 27001 control audit with evidence capture.

Action Hub

Action Hub — Everything that needs fixing, in one place — findings, roadmap, risk actions, improvements, and upcoming deadlines. Gantt-style scheduling with dependencies on Annual. Expand it in the sidebar to jump straight to any of the below.
Findings — Security gaps identified in your assessments.
Roadmap — 30/60/90-day action plan from your findings.
Risk Register — Custom risks with scoring and response plans. Each risk gets an automatic next-review date based on its rating.
Improvement Log — Non-conformities and opportunities for improvement (also included in the Action Hub list).
Change Requests — Propose, approve, and track changes to your systems or processes with a formal sign-off workflow.
Calendar — Policy reviews, agreement renewals, risk reviews, and other compliance deadlines — the upcoming ones also surface in the Action Hub as read-only items.

Compliance

Policies — Draft, publish, and review your policy library.
Continuity Builder — Describe your business and get an editable first-draft business continuity plan.
Leadership Reviews — Formal programme review records for auditors.
Security Goals — Measurable targets tracked monthly.
Compliance Health — Live dashboard of key compliance metrics.
Asset Register — Register of hardware, software, and data assets.
Agreements — Contract register — NDAs, DPAs, MSAs.

Supply Chain

Vendors — Supplier register with risk ratings and DPA status.
Data Processing — GDPR Article 30 records of processing activities.
Threats — CVE vulnerabilities found in vendor software.
SC Reports — Vendor register, DORA ICT, and ROPA exports.

Incidents

Incidents — Log, manage, and close security incidents.
Playbooks — Step-by-step response guides per incident type.

Insights

Jacob — Your AI information security manager (Annual plan) — drafts policies, builds risk treatment plans, and answers security questions on demand.
Ask Alex — Full chat page for longer AI conversations.
Quarterly — PDF progress report for boards and investors.

Learning

Training — AI-generated staff security awareness courses.
Startup Toolkit — Recommended tools and checklist items, tailored to your business by a short quiz.

Settings

Team — Invite and manage the people on your account.
Account — Subscription, billing, and organisation details.
Trust Center — Build a public page — certifications, security practices, and contact details — to link from your own website.

Ready to get started?

Take a free assessment and import your results into the portal in under 15 minutes.