An assessment produces a report, and closing what is in it is a separate problem, which is usually the one people are actually stuck on. Most teams already have a reasonable idea of what is wrong with their cloud security, and what they are short of is someone with the time and the depth to fix it.
We offer the same competence as capacity rather than as a defined deliverable.
It is worth being clear about what that means. An assessment has a fixed price, a fixed scope and a report at the end, so you know what you are buying before you start, and this does not work that way. You are buying time from engineers who do this every week, and you decide what they spend it on.
What the work looks like
The work varies, but often involves:
- Closing findings from an assessment or penetration test, whether ours or somebody else's
- Hardening identity, network and data paths in environments that are already running
- Building detection and response for cloud threats
- Automating guardrails so that the same misconfiguration stops coming back
- Enabling secure software delivery pipelines for IaC and application code
- Covering cloud security work while you are hiring
We tend to leave working systems behind rather than recommendations, meaning changes in your repositories, controls running in your environment, and your own engineers able to keep them going once we are finished.
Everyone we put on an engagement has years of cloud and platform security work behind them, and we do not staff juniors on projects. We work across Microsoft Azure, Amazon Web Services, Google Cloud Platform, OCI and Kubernetes.