Discover powerful Dolibarr extensions designed to automate your business processes

Advanced Cybersecurity Management turns Dolibarr into a full-fledged cybersecurity business ERP. It is designed for cybersecurity companies, security-focused IT service firms (ESN), SSI audit practices, outsourced CISOs (RSSI), independent consultants and internal IT departments.
The module centralizes the entire cybersecurity value chain — from prospecting and client maturity tracking to missions, audits, penetration testing, risk analysis, vulnerability and incident management, IT asset inventory, security policies, regulatory compliance, remediation plans, service contracts, consultant management, time tracking, technical reporting and a SOC-style dashboard — without any external software.
Target users:
· Cybersecurity companies and managed security service providers (MSSP/SOC)
· Security-specialized IT service companies (ESN)
· SSI / information-security audit practices
· Outsourced CISOs (RSSI) and independent security consultants
· Internal IT and security departments
The module follows the standard Dolibarr modular architecture and is fully integrated with the native framework (CommonObject, rights, menus, hooks, multi-entity, multi-language).
Key technical characteristics:
· Technical name: cybersecuritymanagement — installed under htdocs/custom/
· Module number 515300 — verified collision-free in the rights registry
· 15 dedicated business objects, each with its own SQL table (prefix llx_csm_)
· Generic, registry-driven list and card engine (consistent CRUD, filters, column selector)
· Schema self-healing on activation (adds missing columns on upgrade)
· First-activation demonstration dataset generator (installable / removable)
· Five languages: French, English, Spanish, Italian, German
· Module-unique language keys to avoid cross-module label collisions
· PHP 8.x compatible; Dolibarr 16 and above
|
Module area |
Description |
|
Security clients |
Enriched client file: sector, size, CISO/IT contacts, maturity score, criticality, incident and audit history. |
|
Missions |
Audit, pentest, risk analysis, compliance, CISO service, SOC, incident response — with team, budget, planning, progress and status. |
|
Security audits |
Infrastructure, network, application, cloud, organizational — framework, scope, conformity rate, findings, recommendations. |
|
Penetration tests |
Web, Mobile, Network, API, Infrastructure — scope, methodology, vulnerabilities found, critical count, max CVSS. |
|
Risk analysis |
Asset, threat, probability and impact with automatic Risk = Probability x Impact scoring and criticality matrix. |
|
Vulnerabilities |
CVE database, affected system, CVSS score, severity, exploit availability, remediation and treatment lifecycle. |
|
Cyber incidents |
Malware, phishing, data leak, intrusion, ransomware, account compromise — severity, impact, actions, resolution workflow. |
|
IT assets |
Inventory of servers, workstations, network, applications, databases, cloud — owner, criticality, IP, OS, security level. |
|
Security policies |
Versioned document management: passwords, access, incident procedure, IT charter, backup, continuity. |
|
Compliance |
ISO 27001, GDPR, NIST, CIS Controls, PCI-DSS — requirements, evidence, gaps and corrective actions. |
|
Remediation plans |
Corrective actions with owner, deadline, priority, progress and overdue alerts. |
|
Security contracts |
SOC, monitoring, maintenance, outsourced CISO — SLA, renewal date, amount, billing frequency. |
|
Consultants |
Profiles (pentester, SOC analyst, network expert, ISO consultant, CISO), certifications, costs, availability. |
|
Timesheets |
Time tracking per consultant and mission, billable flag, hourly rate and amount. |
|
Reports & reporting |
Technical reports plus decisional reporting (missions, risks, vulnerabilities, incidents, compliance, finance) with CSV export. |
|
SOC dashboard |
Security score, open risks, critical vulnerabilities, active incidents, mission board and analytical charts. |
Prospecting → Security needs analysis → Commercial proposal → Quote validation → Cybersecurity mission → Audit / diagnostic → Risk analysis → Vulnerability detection → Remediation plan → Security report → Client validation → Security maintenance contract → Continuous monitoring → Invoicing → Security reporting.
Created → Planned → In progress → Analysis → Reporting → Validated → Completed (or Cancelled).
Detected → Analyzed → Remediation planned → Corrected → Validated.
Detection → Qualification → Investigation → Resolution → Lessons learned / closure.
Rights are granted per functional group (read / write / delete). Read and write are enabled by default on activation so the module is immediately usable. Suggested role mapping:
|
Profile |
Scope |
|
Administrator |
All rights on every area plus module administration. |
|
CISO (RSSI) |
Global security view: risks, vulnerabilities, incidents, compliance, assets. |
|
Auditor |
Audits and penetration tests. |
|
Consultant |
Assigned missions, timesheets and reports. |
|
Sales |
Security clients and quotes. |
|
Compliance officer |
Standards, policies, compliance items and corrective actions. |
The module extends and reuses the native Dolibarr modules rather than duplicating them:
· Third parties: security clients link to native companies (customers, prospects, partners).
· Products / Services: cybersecurity service catalog (audit, pentest, SOC, monitoring, training).
· Quotes & Orders: an accepted quote drives the creation of a cybersecurity mission.
· Invoicing: fixed-price missions, time-and-materials, security subscriptions and recurring contracts.
· Projects & Agenda: audit phases, teams, planning and deliverables.
· Users: mission managers, responsibles and consultants map to Dolibarr users.
· Multi-entity and multi-language support inherited from the Dolibarr core.
© 2026 DoliResources — www.doliresources.com