The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Cybersecurity
What is misconfigured today, and whose responsibility it is.
We assess your cloud environment against the Cloud Security Alliance controls matrix, which was written for the cloud and addresses the responsibility split between you and your provider. That split is where the serious exposure lives: the provider handles security of the cloud, you handle security in the cloud, and nearly every major incident starts with someone assuming the other party had it covered.
In practice, the work starts by putting in writing what is in scope and what stays out. We then gather evidence, documents, configurations, and logs, and compare actual practice against what each control domain expects. The score comes with fully transparent criteria, and the remediation plan is ordered by real risk, not by the order in which issues surfaced.
On your side, we need access to the environment's evidence and time from the people accountable for it. You receive the score per domain, the prioritized plan, and the responsibility matrix in writing: what is yours, what is the provider's, and what belongs to your vendors. That matrix is where almost every company discovers a gap it thought belonged to someone else.
The engagement options change where the work ends. In the assessment, we deliver the snapshot and the plan. With follow-through, we stay with your team until every fix is closed, because a report nobody chases becomes a permanent backlog item. For CSA STAR preparation, we organize the evidence and review the self-assessment before it goes public, since certification always comes from the independent body.
The stages and deliverables below describe the Security assessment modality. The other modalities appear when you request the proposal.
Scope definition
We agree in writing what is in and what is out, and why. A badly defined scope is the most common cause of a project running over.
Evidence gathering
We collect what already exists: documents, configurations and logs. We start from what the company has, rather than from a blank form.
Maturity analysis
We compare the practice with what each discipline calls for and assign the score, with the criteria in the open.
Report
We consolidate the findings into a report where every item comes with severity, evidence and the path to fix it. We write to be read by the people who will act, not to fatten pages.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.