Your cloud, reviewed against the benchmark
Architecture and configuration review across AWS, GCP, DigitalOcean and Kubernetes, with a remediation plan ranked by risk.
The challenge
Cloud defaults are permissive and configuration drifts. Most breaches in cloud environments are misconfiguration, not exploitation.
Scope — included and not included
Included
- Configuration review against CIS Benchmarks
- IAM and privilege review
- Network and exposure review
- Infrastructure as Code review
- Kubernetes configuration
- Prioritised remediation plan
Not included
- Implementing the remediation
- Cost optimisation
- Migration work
- Ongoing posture monitoring
How it works
01
Read-only access
Credentials scoped to read; nothing changes in your environment.
02
Automated and manual review
Benchmarks plus a human reading your architecture.
03
Prioritise
Findings ranked by exposure and blast radius, not alphabetically.
04
Report and walkthrough
The remediation plan, presented live to your team.
What you receive
- →Findings against CIS Benchmarks
- →IAM privilege map
- →Exposure summary
- →IaC review comments
- →Prioritised remediation plan
What we need from you
- ·Read-only cloud credentials
- ·IaC repository access
- ·An architecture contact
- ·Roughly three hours
Timeline and engagement
1 to 3 weeks. Fixed scope.
Standards, methods and tooling
CIS BenchmarksTerraformKubernetesAWSGCPDigitalOceanPortal hosted in Canada
Frequently asked questions