Author: Julia Grits, Cynet & Netwrix Brand Manager
Cynet has unveiled a new release for its cloud version, which significantly expands the platform’s capabilities in three key areas: centralized management of large environments, faster incident investigation, and the integration of SIEM functions without the need for separate products. These changes will be particularly useful for companies with multiple branches, international organizations, and MSPs that serve many clients simultaneously.
Let’s go through this in more detail, one by one.
A single control panel for all tenants
One of the key new features of this release – Cross-Site Dashboard (Beta).
Previously, administrators had to open each tenant individually to assess the current security status. Cynet now offers a centralized control panel that displays the status across all managed environments at a glance.
You can monitor the following on a single dashboard:
- critical and high-priority incidents
- endpoint security posture
- XDR and ITDR coverage
- email service security status
- integrations with SaaS and cloud services
- utilisation of the SIEM repository
- overall “health” of each tenant

This significantly reduces the time needed to assess risks and enables SOC analysts to identify more quickly which sites require priority attention. When a problem is detected, they can immediately navigate to the relevant site for a detailed analysis.
Updated workflow for investigating and managing security alerts
One of the key aims of this update is to provide SOC analysts with more context without having to switch between different sections of the platform.
So, here’s what’s been added and improved.
A revamped look for alerts
Cynet has updated its alert handling: analysts can now immediately see the key information required to assess an incident and investigate it further.
It is now easier within the interface to determine the severity of an incident, its type, and associated activity, as well as to proceed to a detailed analysis. This is particularly important when dealing with a large number of alerts: analysts can more quickly assess priorities and determine which events require immediate investigation.

More context for the investigation
The update will enable the collection of as much information as possible regarding a specific threat within a single investigation workflow. Analysts can more quickly understand:
- what triggered the alert
- which users and end devices are associated with the activity
- what events preceded the alert
- how critical the detected activity might be
- what next steps are required for verification or response
This reduces the time between the event and the decision being made.
From detection to response
A key feature of Cynet’s approach remains unchanged – investigations are directly linked to the platform’s response capabilities.
After analyzing an alert, the security team can proceed directly to countermeasures without using separate tools. In this way, Cynet gradually integrates detection, investigation, and response into a single workflow: the platform detects potentially dangerous activity, provides context for its analysis, uses CyAI to explain it, and enables a rapid transition to response.

What does this offer the SOC team?
Undoubtedly – a reduction in the time an analyst spends on the initial sorting of events.
Instead of manually gathering context from various sources, the team receives more of the information they need directly in the console. And CyAI helps to interpret complex XDR and ITDR detections more quickly.
This is particularly relevant for small cybersecurity teams: less manual work on alerts, faster analysis, and a shorter path from detection to response.
And now for the icing on the cake – SIEM functionality has been added to the Cynet platform
One of the most interesting new features is the introduction of the SIEM module, although it is currently still in beta. This has been a fairly logical next step in the development of the built-in CLM.

So, we can see that Cynet is steadily moving towards the concept of a unified security platform, adding core SIEM capabilities without the need to integrate a separate solution.
The new module includes:
- centralised event viewing
- log search and analysis
- ready-made query templates for investigations
- customisable event tables
- monitoring of SIEM resource usage
- management of custom detection rules
In effect, analysts are able to carry out standard SIEM tasks without having to switch between different systems, which significantly speeds up the work of the SOC.
What else is new in this release?
We have looked in detail at the most notable changes in this release, but the Cynet v4.33 update for SaaS is not limited to these. Other new and improved features include:
- Cross-Site Profile Management. Centralised creation and application of security profiles to various sites. In particular, this applies to Antivirus, File Monitoring, Storage Device Control and Windows Events.
- Proactive CyOps Incident Response. The ability to configure the CyOps team’s 24/7 proactive response and specify which response actions can be carried out without further approval. Individual users and hosts can be excluded from the automated response.
- ConnectWise RMM Integration. Automated deployment of Cynet Agent and monitoring of its status via ConnectWise RMM.
- HaloPSA Billing Automation. Synchronization of actual endpoint license usage with HaloPSA, which simplifies billing for MSPs.
- Generic Alert Webhook. Forwarding new Cynet alerts to external systems in JSON format. This expands the possibilities for integration with messaging apps, ticketing, and automation systems.
- New response actions for Windows. The ability to install necessary Windows Updates and update selected software on managed end devices.
- Improvements of ITDR and SSPM. Centralized management of ITDR policies by group and export of user SSPM information in CSV format for further analysis and auditing.
- Email Security update. Advanced Allow/Block policies with support for wildcards, domains, and subdomains, as well as checking of nested .eml files up to three levels deep.
The new version of Cynet XDR is not just an update to individual features but another step by Cynet towards more centralized cybersecurity management: from monitoring multiple environments and investigating incidents to SIEM, automated response, and more seamless integration with the company’s IT ecosystem.







