· intuitem · News  · 4 min read

What's New in CISO Assistant — Week 31, 2026 (v3.20.3 – v3.20.4)

A native Power BI connector ships as a signed, standalone artifact, third-party risk management joins domain export/import, posture management gains observations and attachments, and the AI chat learns to import spreadsheets. Plus the TISAX v2027 and ENISA SME cyber resilience frameworks, Slovenian localization, and an IAM hardening fix.

A native Power BI connector ships as a signed, standalone artifact, third-party risk management joins domain export/import, posture management gains observations and attachments, and the AI chat learns to import spreadsheets. Plus the TISAX v2027 and ENISA SME cyber resilience frameworks, Slovenian localization, and an IAM hardening fix.

This edition catches up on the two patches that closed out July: v3.20.3 on July 24 and v3.20.4 on July 28. They round out the v3.20 cycle with a native Power BI connector, a much broader domain export, deeper posture management, and two new frameworks.

Headline Features

  • Native Power BI connector — CISO Assistant now ships a first-party Power BI connector with token-based authentication, multi-table modelling with relationships, and incremental refresh, alongside a starter Power BI template with a preconfigured model and pages (PR #4563). It is distributed as its own signed artifact — see the powerbi-v1.0.1 release for the install guide and the certificate trust runbook. Documentation for incremental refresh and real-time data was expanded shortly after (PR #4588). Thanks to @ab-smith and @tarkadia.
  • Full TPRM ecosystem in domain export/import — Domain export previously carried only the Entity record from the third-party risk module. It now covers entity assessments, solutions, solution subcontractors, representatives and contracts, plus the previously dropped entity fields (ref_id, legal identifiers, parent entity, default scores, DORA provider person type). Audit, entity-assessment and contract evidences — and their attachments — are folded into the export scope as well (PR #4571). Note that user relations, filtering labels and enclaves are intentionally not carried over. Thanks to @Mohamed-Hacene.
  • Spreadsheet import from the AI chat — You can now upload XLSX and CSV files directly in the chat, with automatic column mapping and target detection, then review a preview with row counts, updates, errors and truncation warnings before confirming. The Data Wizard also gained downloadable Excel templates for supported record types (PR #4585). Thanks to @ab-smith.

Posture Management

The technical posture management capability introduced in v3.20.0 keeps filling out:

  • Observations and file attachments on posture runs — Posture runs accept observations and attachments (upload, replace, remove, download), with richer run history and detail views and interactive cell navigation. Ships with CIS benchmark libraries for Debian 12, Debian 13 and Kubernetes 2.0.1. Note the attachment limit change is platform-wide: body and request limits are now documented at 50 MB (PR #4581). Thanks to @ab-smith.
  • Faster posture assessment queries — The posture assessment queryset now prefetches assets__folder, cutting query counts on large datasets (PR #4560). Thanks to @Mohamed-Hacene.

Security

  • IAM hardening on framework data API access — A user without proper access to an audit could still retrieve some metadata through the API. Access control on compliance assessment details has been tightened, with a regression test added (PR #4561). Credit to Timothy Siebes, Aegis Consultancy B.V. for the report, and thanks to @eric-intuitem for the fix.

New Features

  • Evidence on security exceptions — Security exceptions can now carry attached evidence (PR #4537). Thanks to @Mohamed-Hacene.
  • Custom fields on security exceptions — Security exceptions join the objects that support custom fields (PR #4426). Thanks to @Banlone.
  • Batch add assets to a BIA — Assets can be added to a business impact analysis in bulk instead of one at a time (PR #4570). Thanks to @ab-smith.
  • Findings assessment improvements — Findings assessments gain filtering labels, an optional “reported at” date, a new “Responsible disclosure” category (English and French), exact-match filtering by asset, and Markdown (.md) uploads (PR #4573). Thanks to @ab-smith.
  • EBIOS-RM elementary action inheritance — Elementary actions are now inherited across domains, so shared catalogs work as expected in multi-domain setups (PR #4578). Thanks to @tchoumi313.

Framework & Library Updates

  • TISAX v2027 — Added the TISAX v2027 framework (PR #4557). Thanks to @tarkadia.
  • ENISA SME Cyber Resilience Maturity Assessment — A new framework covering five cybersecurity domains with 1-to-5 maturity scoring, built on the question-driven scoring system for a smoother experience, and with configurable result visibility for auditors and respondents (PR #4567). It was enriched with recommended controls a few days later (PR #4583). Thanks to @ab-smith.
  • IEC framework fixes — Corrections to the IEC frameworks, along with a global README update (PR #4551). Thanks to @tarkadia.

Internationalization

  • Slovenian translation — CISO Assistant adds Slovenian to its supported languages (PR #4547). Thanks to @Capy-Sec.

UX & Bug Fixes

  • Better input contrast and toast notifications — Form input contrast was improved and inline status messages replaced with toast notifications for clearer feedback (PR #4569). Thanks to @tchoumi313.
  • Stacking issues fixed — Resolved random z-index stacking glitches in the interface (PR #4568). Thanks to @ab-smith.
  • Restored builtin behavior — Fixed a regression affecting builtin objects (PR #4562). Thanks to @eric-intuitem.
  • Clearer oversized-upload errors — Oversized imports and attachments now return an explicit HTTP 400 with stricter validation, and exported workbook metadata correctly reflects the selected library version (PR #4581). Thanks to @ab-smith.

Welcome to new contributors @Capy-Sec and @Banlone, who both made their first contribution in v3.20.3. For full details, check out the v3.20.3 and v3.20.4 release notes on GitHub.

Back to Blog

Related Posts

View All Posts »
What's New in CISO Assistant — Week 28, 2026 (v3.19.2)

What's New in CISO Assistant — Week 28, 2026 (v3.19.2)

A feature-rich patch: a reworked risk acceptance workflow, the NCA ECC-2:2024 framework, evidence on data breaches, expanded document management, ServiceNow asset sync, broader audit-log coverage, Slovak localization, and a long list of fixes.