Cloud Security

Identity-first guardrails for AWS & Azure. Reduce blast radius, protect data, and keep developers fast — with evidence you can audit.

Book a Security Review

Business Outcomes

  • Smaller blast radius, fewer critical incidents.
  • Audit-ready posture mapped to POPIA / ISO / CIS with timestamped evidence.
  • Release velocity preserved — controls in CI/CD and golden images.
  • Clear ownership: approver / operator / auditor lines don’t blur.

Controls Framework

  • Orgs/Policies, SCPs/deny-by-default, enforced MFA.
  • Federated SSO, least-privilege roles, right-sizing, break-glass rotation & logs.
  • Zero-trust segmentation, private endpoints, WAF/DDoS, strict egress.
  • Service auth mTLS/OIDC; secrets via KMS/Key Vault.
  • Encryption in transit/at rest; key lifecycle & rotation; envelope encryption.
  • Classification & residency policies aligned to POPIA.
  • Hardened images; EDR; container/IaC scanning; signed artifacts; drift detection.
  • CloudTrail/Activity Logs → SIEM; detective controls; evidence mapped to CIS/NIST/ISO/POPIA.
  • IR playbooks per service; ring-fenced forensics; immutable backups; tabletops.

Evidence & Audit

Control AreaEvidence We ProduceCadence
IdentityRole inventory, unused-perm diffs, MFA coverageMonthly
NetworkIngress/egress allow lists, private endpoint coverageMonthly
DataClassifications, key rotation logs, residency hitsQuarterly
WorkloadsBaseline drift, image provenance, CVE burn-downMonthly
Backups/IRRestore tests, RTO/RPO, tabletop outcomesQuarterly

Engagement Packages

Baseline Sprint (2–4 weeks)

  • Org guardrails, MFA, logging, top-3 risks closed.
  • Evidence pack v1 + drift monitoring on.

Operate & Assure

  • Drift response, monthly evidence, posture reviews with exec pack.

Outcome Add-ons

  • Container signing, secrets rotation, backup immutability tests, PAM integration.

How We Land It

  1. Diagnose: bills, logs, IAM graph, egress map, backup health.
  2. Design: venue-neutral options; control set with trade-offs.
  3. Do: top-value controls first; CI/CD gates & images updated.
  4. Drive: reviews, drift MTTR, evidence cadence.