Assessment domain
Configuration & posture
Configuration and posture is the baseline every other control sits on: how far each account, project, subscription, and tenant has drifted from CIS Benchmarks and the cloud provider's own best practice. Most of these gaps are not exotic — default encryption left off, a service exposed by a template nobody reviewed, a resource that no longer matches the code that created it. They rarely trigger an alarm on their own, which is exactly why they accumulate. We read the whole estate against a known-good baseline and rank the drift by the exposure it actually creates.
Why it matters
Where the risk lives
Posture drift is cumulative and mostly invisible until something breaks — a new region opened without guardrails, a team that copied an insecure template, a resource that has quietly diverged from its Terraform. Any single misconfiguration looks minor; together they widen the blast radius of every other finding and give an attacker the small footholds they chain into a real incident. Posture is also the domain auditors and cyber-insurers probe first, because a documented, benchmarked baseline is the clearest signal that security is managed rather than assumed. Getting it right maps directly to CIS Benchmarks, NIST CSF, ISO 27001, SOC 2, and the patch and change controls in PCI-DSS.

What we assess
The checks inside configuration & posture
Each area below is a focused review with its own findings, per-cloud detail, and remediation.
CIS Benchmark drift
The CIS Foundations Benchmarks are the industry's consensus baseline for a securely configured cloud account, and every estate drifts away from them over time as teams ship. We measure each account, subscription, and project against the relevant benchmark and separate the deviations that create real exposure from the ones that are noise. The goal is not a perfect score — it is knowing exactly where you stand and which gaps to close first.
What we look forProvider best-practice baselines
Beyond CIS, each cloud provider ships its own security posture service — AWS Security Hub, Microsoft Defender for Cloud, and Google Security Command Center. These tools generate real signal, but on their own they produce long, unranked lists that teams learn to ignore. We read the provider's own posture findings, deduplicate them, and translate them into a prioritized set of actions.
What we look forIaC & drift control
When infrastructure is defined as code, the code is the intended state — and drift is when the running environment no longer matches it. Manual console changes, emergency fixes never merged back, and resources created outside the pipeline all erode the guarantees that IaC is supposed to provide. We look at whether the estate is actually governed by its code and whether drift is detected rather than discovered during an incident.
What we look forPatch & vulnerability posture
Cloud does not remove the need to patch — it moves it, and unpatched compute, stale images, and known-vulnerable managed-service versions remain a common path to compromise. We assess whether there is a working process to find and remediate known vulnerabilities across instances, containers, and images, and how long fixes actually take. The focus is on the exposure that is both known and reachable.
What we look forAcross your clouds
AWS, Azure & Google Cloud
AWS
CIS AWS Foundations Benchmark measured per account; AWS Security Hub for aggregated best-practice and standard findings; AWS Config rules and conformance packs for drift and continuous compliance; Systems Manager Patch Manager and Amazon Inspector for patch and vulnerability posture.
Azure
CIS Microsoft Azure Foundations Benchmark per subscription; Microsoft Defender for Cloud secure score and regulatory-compliance dashboard; Azure Policy for guardrails and drift; Azure Update Manager and Defender vulnerability assessment for patch and CVE coverage.
Google Cloud
CIS Google Cloud Foundations Benchmark per project; Security Command Center posture and Security Health Analytics; Organization Policy constraints for preventative guardrails; OS Config patch management and Artifact Registry / GKE image scanning for vulnerability posture.
Compliance evidence
Frameworks this domain produces evidence for
Example finding
Default encryption and logging disabled on a newly-opened region, so every resource created there inherits an insecure baseline
Risk: New workloads start non-compliant and unmonitored by default, quietly reintroducing drift the rest of the estate had already fixed — and widening it every time the team ships.
Fix: Set secure-by-default organization policies (encryption, logging, and network guardrails) that apply to every account and region, so new resources start compliant instead of being remediated after the fact.
Questions
Is this the same as running a CSPM tool?
No. A CSPM tool produces posture data — we use that data, then add the part it leaves out: deduplicating the noise, ranking each finding by the real exposure it creates, and giving you a remediation order your team can actually run. The tool tells you what is wrong; we tell you what to do first and why.
Do you change our configuration to fix the drift?
No. The assessment is read-only — we measure your estate against CIS Benchmarks and provider best practice and hand you a prioritized plan, without altering any setting or touching production. Remediation is a separate, agreed step your team runs, or one we support once you decide what to close.
We have hundreds of findings already. How is this different?
That is the problem we solve. A raw benchmark or secure-score export is a flat list nobody can act on. We turn it into a ranked, deduplicated set of issues tied to CIS, NIST CSF, ISO 27001, SOC 2, and PCI-DSS controls — so the same work reduces drift and produces the evidence your auditors and insurers ask for.
See where you stand on configuration & posture
A health check finds and prioritizes real exposure. It is not a certification or a promise you will never be breached — closing the findings is what changes your risk.
Related domains
The rest of the health check
One read-only assessment covers all six domains — here's where else exposure tends to hide.




