1. What is Cyber Advisor
Cyber Advisor is the GenAI virtual assistant of Cyber Guru specialized in cybersecurity, available 24/7 to provide immediate support and expert advice on threats, corporate policies, and regulatory compliance.
The assistant's name is "Guru": a cybersecurity consultant always available who adapts to each user's competency level.
2. Why Cyber Advisor
The modern business context requires immediate decisions:
- Employees face critical security choices every day: managing suspicious emails, using AI tools, handling sensitive data
- Awareness training alone is no longer sufficient: contextual support is needed at the moment of need
- IT and security resources are overwhelmed by repetitive questions that could be resolved independently
- It is necessary to reduce the time between doubt and secure action
Cyber Advisor bridges this gap by providing:
- Immediate advice: answers in 2–5 seconds instead of hours/days for IT tickets
- Contextual support: guidance at the moment of decision, not just theoretical training
- Helpdesk load reduction: autonomy for common questions, escalation only for complex cases
- Compliance always-on: immediate clarifications on NIS2, DORA, GDPR
- Scalability: from the board of directors to the break room, supports the entire organization
3. Target Audience
Cyber Advisor is designed for the entire workforce:
- Operational employees: daily support on email, passwords, device security
- Managers: policy consultation, incident response procedures, compliance requirements
- Board & Executive: included free in NIS2 and DORA Board Training programs
- IT/Security Team: reduction of repetitive tickets, self-service knowledge base
4. Availability
- Add-on for Cyber Guru Awareness, Channel, Phishing products
- Included free in NIS2 and DORA Board Training solutions
- Licensable separately for other Cyber Guru training programs
5. Distinctive Features
5.1 Specialized Artificial Intelligence
- LLM-based chatbot with conversational memory and learning capabilities
- Trained on certified Cyber Guru content (awareness, compliance, best practices)
- Not a generic chatbot: deep knowledge of cybersecurity, NIS2, DORA
5.2 Cybersecurity Focus with Guardrails
- Integrated guardrails keep conversations strictly on security topics
- Prevents off-topic or inappropriate responses
- Integrated content moderation (LlamaGuard)
5.3 Conversational Approach
- Engaging and intuitive support in the style expected by digital natives
- Bidirectional conversations with context memory for 60 minutes
- Language and tone adapted to the user's technical level
5.4 Global Accessibility
- Multilingual support: over 20 languages
- Primary (high accuracy): Italian, English, Spanish, French, German, Portuguese
- Secondary: Dutch, Polish, Swedish, Norwegian, Danish, Russian, Japanese, Chinese, Korean and others
- Automatic language detection from request
- Available 24/7 via web app
5.5 Customizable for Your Organization
- Extensible with corporate IT policies, internal procedures, compliance documentation
- Becomes a corporate assistant reducing IT/security team load
- On-demand corporate document search
6. Main Features
6.1 Interactive Cybersecurity Consultation (Chat)
What it does
Direct conversation with a virtual expert available via web app integrated in the Cyber Guru platform.
Guru answers questions about:
- Threats and attacks: phishing, ransomware, malware, social engineering, deepfakes
- Best practices: password management, MFA, device security, secure remote work
- Regulatory compliance: NIS2, DORA, GDPR, ISO 27001, explanation of specific articles
- Corporate policies: interpretation of internal policies uploaded by administrator
- Incident response: what to do in case of suspected breach, reporting procedures
How it works
For end users:
- Open Cyber Advisor chat from Cyber Guru platform
- Type your question in natural language (e.g., "What is a ransomware attack?")
- Guru responds in 2–5 seconds with a clear explanation
- Conversation continues with context memory (up to 60 minutes)
Behind the scenes:
- The system uses RAG (Retrieval-Augmented Generation) technology
- Responses are based on real documents, not just generic knowledge
- Search in Cyber Guru library (training materials, regulatory guides)
- If enabled, also searches corporate documents uploaded by administrator
6.2 Operating Modes
Generic Mode (default)
- Source: Shared Cyber Guru library (CG-LLM)
- Content: training materials, cybersecurity best practices, NIS2/DORA/GDPR/ISO 27001 guides
- Activation: automatic for generic questions
- Example: "What does NIS2 require for incident management?" → answer from official NIS2 guides
Corporate Documents Mode (opt-in)
- Source: Corporate document database
- Content: policies, internal procedures, audit reports, compliance documentation uploaded by admin
- Activation: toggle "Company Document Search" in chat
- Example: with toggle enabled, "What is our password policy?" → answer from corporate document
6.3 Response Times
| Request Type | Response Time |
| Simple question (no RAG) | 1–3 seconds |
| Generic search (RAG) | 2–5 seconds |
| Corporate search (RAG company) | 3–6 seconds |
| Image analysis | 2–4 seconds |
6.4 Integration with Corporate Policies (RAG)
Document Upload
The following roles can access the "Training Material" section and upload documents:
- Admin
- CSM
- MSP
- Company Admin
- Company Manager
Procedure:
- Log in to Cyber Guru platform as administrator
- Navigate to: Training Material → Cyber Advisor Documents
- Upload documents (supported format: PDF, text and not scanned images)
- Save and wait for automatic indexing
Recommended documents: Password Policy, Acceptable Use Policy, BYOD Policy, Incident Response Procedure, Data Classification Policy, Remote Working Guidelines, Backup Policy, Vendor Management Procedure, Business Continuity Plan, Internal Privacy Policy.
What happens behind the scenes
- PDF processing: text extraction
- Chunking: division into blocks of ~800 characters with 200 character overlap
- Embedding generation: conversion to numerical vectors (384 dimensions)
- Indexing: vectors indexed in dedicated corporate database (quantized FAISS)
- Ready for search: documents queryable by Cyber Advisor
Usage for end users
Activation in chat:
- Open Cyber Advisor chat
- Enable "Company Document Search" toggle (top right)
- Ask a question related to a corporate policy
Cyber Advisor will search corporate documents in addition to the generic library.
Response indicator:
When corporate documents are used, Cyber Advisor explicitly indicates this at the beginning of the message (e.g., "According to corporate policy…"). Responses based on the generic knowledge base use phrases like "As best practice…" or "According to standard guidelines…".
6.5 Suspicious Email Analysis (Email Forwarding)
What it does
Automatic email analysis for phishing detection through forwarding suspicious emails to a dedicated address.
Important: this is NOT a technical security analysis (sandbox, malware analysis). It is an analysis of visible phishing indicators: headers, links, urgency, spoofing, images, attachments.
How it works
For the user:
- Receive a suspicious email in your mail client (Outlook, Gmail, etc.)
- Forward the email to: cyberadvisor@cyberguru.report
- Cyber Advisor automatically analyzes: email headers, links present, attachments, embedded images, language, HTML structure
- Receive response via email with: phishing risk level (Low/Medium/High), list of identified red flags, recommended actions, detailed report
Response time: typically 1-3 minutes
What is analyzed
- Header Analysis: From vs Return-Path mismatch, SPF/DKIM/DMARC, Received headers
- Link Analysis: obfuscated URLs, domain similarity (typosquatting), URL shorteners, HTTPS presence
- Attachment Analysis: suspicious file type, double extension, documents with enabled macros
- Content Analysis: urgency indicators, threatening language, generic greetings, grammatical errors, suspicious requests
- Visual Analysis: logo quality, brand consistency, image-based content
Email analysis limitations
What it does NOT do:
- Attachment sandboxing
- Malware detection
- Link crawling
- Automatic actions (block/delete email)
When to escalate to security team:
- Email with executable attachments (.exe, .scr)
- Breach already occurred
- Targeted attack (spear phishing with precise corporate info)
- Email from compromised internal sender
Privacy and data management in email analysis
- Zero Memory: Cyber Advisor does not retain memory of previous conversations
- No persistent conversation: email analysis does not support follow-up
- Immediate deletion: once the response is generated, email data is removed
- Zero Data Retention: policy configured to zero days for email analysis
6.6 Special Commands
| Command | Function |
| /search {query} | Force search in corporate documents |
| /debug | Corporate routing diagnostics |
| /list_docs | List uploaded documents |
7. How to Use Cyber Advisor Effectively
Best practices for questions
- Be specific: GOOD – "What are the rules for USB use in the office?"; AVOID – "USB Policy?"
- Provide context when necessary
- One question at a time
- Rephrase if necessary
Interpreting responses
- "According to corporate policy…" → internal document
- "As best practice…" → generic industry knowledge
Conversation limitations
- Context memory: 60 minutes of inactivity
- Hallucinations: 3-5% of RAG responses may contain inaccuracies
- No operations: does not open tickets, does not modify systems, does not start workflows
8. When to Use Cyber Advisor vs. Security Team
Use Cyber Advisor for
- First-level consultation and quick reference
- Informational questions on policies and best practices
- Clarifications on already known procedures
- Standard compliance verification
- Initial assessment of suspicious emails (without executable attachments)
Contact security team for
- Critical decisions (legal, formal compliance)
- Suspected ongoing security incident
- Email with suspicious executable attachments
- Requests for access to critical systems
- Policy violations already occurred
- Targeted attacks (spear phishing, Business Email Compromise)
- Loss or theft of corporate devices
- Unauthorized access to corporate accounts
9. Privacy and Security
Protection of corporate data
Corporate documents uploaded by administrator are:
- Physically segregated by company: /data/{company_uuid}/
- Accessible only to authorized users of your organization
- NOT used to train artificial intelligence models
Conversation data
NOT saved: conversation content, question text, response text, personal data (PII)
Saved (metadata only): request timestamps, Session ID (pseudonym), Company ID, technical statistics, technical error logs
Retention periods
| Data | Retention Period |
| Conversations | RAM only for 60 minutes → auto-deletion |
| Application logs | Disk rotation 7 days |
| Aggregated statistics | Indefinite (no content) |
| Corporate PDF documents | Indefinite (customer managed) |
Data processing by Groq
| Data Type | Retention |
| Prompt & Output | 0 days |
| Usage metadata | Indefinite (metrics only) |
| Error logs | Max 30 days |
| Abuse logs | Max 30 days |
Groq Certifications: SOC 2 Type II, Standard Contractual Clauses (SCC) – GDPR compliant for EU → USA transfers.
10. Limits and Best Practices
What Cyber Advisor does NOT do
- Does not perform operations (does not open tickets, does not modify systems)
- No real-time data
- No malware analysis
- Does not replace the CISO
- No formal audit
Technical limitations
- Hallucinations: 3-5% of RAG responses
- Groq API dependency: if Groq API is down, service is unavailable
- Obsolete documents: if PDFs are not updated, responses may be incorrect