Skip to main content

Set up the Cyberwatch connector

This article is for teams who want to connect their Cyberwatch instance to Tenacy to automate the collection of security indicators, without manual re-entry.

Cyberwatch helps companies reduce their risk through two solutions: a vulnerability detection and monitoring solution and a compliance management solution that can adapt to any environment and rule. These cross-platform applications (Windows, Linux, Mac) are quickly installed with or without an agent, or in offline mode, within client networks.

This connector queries the Cyberwatch API to collect indicators (values tracked over time on a perimeter) on assets, their vulnerabilities, and their compliance, as well as to synchronize security issues as gaps (security flaws recorded in a Tenacy register) in Tenacy.

This connector allows the following information to be collected:

  • Indicators of the number of scanned assets (vulnerabilities and compliance), with recent results.

  • Indicator on assets with critical vulnerabilities.

  • Indicators on the number of discovered and critical vulnerabilities.

  • Indicator on compliant assets.

  • Cyberwatch security issues as gaps in Tenacy.

Add and configure the connector

To add this connector, go to Catalog > Connectors > Cyberwatch > Add a connector

After adding it, you need to configure:

  • Operator perimeter: the perimeter (an entity of your organization, such as a legal entity or a site) that operates and dictates the vulnerability and compliance scan rules, to which the indicators and the default gaps register will be attached.

  • Frequency: automatic query frequency of the Cyberwatch API and periodicity of associated indicators. This periodicity can be daily, weekly, monthly, semi-annual, or annual.

⚠️ When creating this connector, the measure (the mechanism that materializes a security requirement in Tenacy, here the Internal Vulnerability Scans measure, TE016) will automatically be applied to the relevant perimeter if not already in place.

Once the connector is created, the configuration continues:

  • Cyberwatch API URL: corresponds to the connection URL for the Cyberwatch dashboard. This URL is displayed when the API key is generated.

  • Cyberwatch API Key: this API key must be generated and linked to a Cyberwatch administrator account. The "Read Only" permission is sufficient for the connector to work.

⚠️ Non-administrator users do not have the necessary permissions to query the API.

  • Cyberwatch API Secret: this secret is generated at the same time as the API key. It is only accessible and visible at that moment. A new API key must be generated if it is lost.

  • Gaps register: security flaws identified by Cyberwatch can be raised as gaps in Tenacy.

    • Existing register: select it from the list provided (a dedicated register is already listed).

    • New register: enter its name in the field; if it doesn't exist yet, Tenacy will create it automatically when the configuration is saved.

  • Maximum number of gaps: optional limit on gap creation, capped at 100.

    • If the field is filled in: Tenacy stops creating gaps once this number is reached.

    • If the field is left empty: Tenacy synchronizes all security issues identified by Cyberwatch as gaps.

  • Groups in perimeters: lets you feed your metrics and indicators according to the groups already defined in Cyberwatch.

    • Add as many Tenacy perimeters as needed and associate the matching Cyberwatch group ID next to each one.

    • If you want to associate multiple Cyberwatch groups with the same Tenacy perimeter: separate their IDs with a comma.

💡 To generate a new API key on Cyberwatch, click on your avatar at the top right in Cyberwatch > My Profile > View My API Keys > Add +

Run your first test

Once the connector is properly configured, test the integration by running an initial execution.

Go to ⚙️ > Connectors > Click on the Cyberwatch connector > Run now:

💡 Feel free to contact Tenacy support if you have any questions regarding this.

Expected result

Once the test runs successfully, the connector automatically queries the Cyberwatch API according to the chosen frequency. The indicators linked to the Internal Vulnerability Scans measure (TE016) start updating, and Cyberwatch security issues progressively appear as gaps in the configured register.

🔎 To understand in detail how each indicator fed by this connector is calculated, see: The Different Metrics Supplied by Cyberwatchhttps://help.tenacy.io/en/articles/281063-the-different-metrics-supplied-by-cyberwatch

Frequently asked questions

What happens if I don't specify a gaps register?


Security issues detected by Cyberwatch are not synchronized as gaps in Tenacy. Only the indicators continue to be fed.

What happens if measure TE016 already exists on my perimeter?


Tenacy doesn't create a duplicate: the connector relies on the existing measure instead of creating a new one.

Can I connect several Cyberwatch instances to Tenacy?


Yes, each instance requires adding a separate connector, with its own API URL, key, and perimeter configuration.

What happens if my Cyberwatch API key is revoked or expires?


The connector can no longer query the API: indicators stop updating until a new valid key is entered in the configuration.

Did this answer your question?