Home / Services / Cloud Security
Service categoriesCloud Security
Configuration, activity, vulnerabilities. Keep checking your cloud from three angles
CSPM checks for configuration gaps, CSEM monitors suspicious activity in your cloud, and SCA manages workload vulnerabilities. See the “state,” “activity” and “contents” of your cloud across AWS, Azure, Google Cloud and OCI in the same console.
Services
Cloud Security services
CSPM
Continuously finds cloud misconfigurations against CIS Benchmarks and other standards, and prioritizes them by risk that accounts for external attack paths, data exposure and criticality.
MonitorCSEM
Detects suspicious sign-ins, permission changes and external access every 15 minutes from AWS, Azure, Google Cloud and OCI audit and flow logs, and Microsoft 365 and Google Workspace logs. AI explains what each event means and how to respond.
ManageSCA
Builds SBOMs from the dependencies of containers, serverless functions, virtual machines and repositories, and continuously manages vulnerability, end-of-life, license and supply chain risks.
Better together
What changes when you combine them
Watch configuration gaps until they're fixed
Until you fix the public-access misconfigurations or excessive permissions CSPM finds, CSEM can monitor that account for suspicious logins and operations.
Fix the vulnerabilities that matter first
View the vulnerabilities SCA finds together with the external exposure and asset importance CSPM reveals, so you can address what is truly urgent first.
AI runs on your Bedrock
In all three services, the AI used to explain and discuss findings and events runs on your own Amazon Bedrock. Usage fees and model choice stay under your control.
Capabilities
Key features by service
CSPM
- Benchmark-based assessment
- Framework coverage
- Attack path and data exposure views
- Context-aware risk score
- Security score
- System-level view
- Action center and response tracking
- AI explanations
CSEM
- Multi-cloud and SaaS logs
- Predefined detection rules
- Detection every 15 minutes
- Purpose-built views
- AI analysis and response suggestions
- Criticality-based prioritization
- Rule tuning and exclusions
- Severity-filtered notifications
SCA
- SBOMs from a wide range of sources
- Agentless VM scanning
- Multiple vulnerability databases
- Prioritized by exploitability
- End of life and licenses
- Supply chain risk
- Built into the development workflow
- AI explanations and reports
Getting started
Getting started
Connect your cloud
For AWS, just run the CloudFormation template we provide. It creates mostly read-only permissions for each service. Azure, Google Cloud and OCI are also supported.
See results right away
Once connected, configuration assessment and log analysis begin, and findings appear on the dashboard and in the Action Center.
Make it part of operations
Assign findings that need attention to an owner and track them. Set asset importance to make prioritization more accurate.
FAQ
FAQ
Can I contract CSPM, CSEM and SCA separately?
Yes. Each service is contracted individually. If you use more than one, you can review configuration, events and vulnerabilities in the same console.
Where are logs and data processed?
CSPM and CSEM retrieve configuration and logs using the read permissions you grant, and assess and analyze them on the CyberForces side. The SCA scanner runs inside your cloud, and image contents do not leave it. AI explanations and consultation run on your own Amazon Bedrock.
Service inquiries and demo requests
We will propose the services you need for your environment and challenges.