Private Cloud / Hosting Security
Tight baselines, strong segmentation, and tested backups & DR — measurable resilience on premises or hosted.
Controls Framework
- VLAN/VRF/NSX micro-segmentation; policy-as-code; managed PKI.
- WAF/DDoS, strict egress, private interconnects to cloud.
- CIS baselines, patch orchestration, kernel/service lockdown, EDR everywhere.
- PAM with JIT/JEA, credential vaulting, session recording.
- At-rest encryption, HSM/KMS integration, rotation, tamper-evident logs.
- POPIA-aligned handling; least-access patterns.
- Air-gapped/immutable tiers, quarterly restores, ransomware tabletops.
- Automated reports: backup success, restore time, integrity checks.
- Syslog/ETW → SIEM, UEBA, tuned alerts surfacing real threats.
- Audit packs mapped to ISO 27001, NIST CSF, CIS, and local regs.
Evidence & Audit
Control Area | Evidence We Produce | Cadence |
Segmentation | Policy diffs, blocked lateral paths, change logs | Monthly |
Hardening | Baseline adherence, patch SLA, EDR coverage | Monthly |
PAM | JIT/JEA usage, privileged session records | Monthly |
Backups/DR | Restore tests, RTO/RPO, immutability proofs | Quarterly |
Engagement Packages
Baseline Sprint (2–4 weeks)
- Segmentation policy, OS baselines, backup immutability checks.
- Evidence pack v1; DR skeleton.
Operate & Assure
- Patch cadence, evidence packs, DR exercises, SIEM tuning.
- SLAs for change windows, alert MTTR, false-positive thresholds.
Add-ons
- PAM rollout, HSM integration, ransomware drills.