Home / Services / Cloud Security / CSPM

Cloud Security / Cloud configuration assessment

Catch cloud misconfigurations
before they become incidents.

CSPM (Cloud Security Posture Management) continuously inspects your cloud configuration and detects misconfigurations such as incorrect public-access settings and excessive permissions. Findings are ranked not just by severity but by risk that factors in external exposure and account criticality, and each one explains both why it is dangerous and how to fix it.

Challenges

Sound familiar?

Misconfigurations open the door to incidents

Most breaches start with an overlooked setting, such as public storage settings or overly broad security groups.

Too many findings to make progress

Benchmarks produce hundreds of findings, and you can't tell which to fix first.

Different standards across clouds

Each cloud has its own tools and views, so you can't assess your overall posture against one standard.

Features

CSPM key features

01Benchmark-based assessment

Assesses configuration against CIS Benchmarks (AWS / Azure / OCI), AWS Foundational Security Best Practices and NIST SP 800-53 (AWS).

02Framework coverage

Maps findings to major frameworks such as PCI DSS, NIST CSF and SOC 2 to help you understand where you stand.

03Attack path and data exposure views

See on screen the paths by which resources can be reached from the internet, and where important data is exposed.

04Context-aware risk score

Scores combine severity with external exposure, account and asset criticality, and data sensitivity, so findings in important environments rise to the top.

05Security score

A pass rate weighted by severity gives you the state of your whole environment as a single number.

06System-level view

Automatically detects “systems” from how resources connect, so you can manage assets as groups. Includes an IAM inventory screen.

07Action center and response tracking

Shows what to do next in priority order. Create response tasks from findings and track them by owner, due date and progress.

08AI explanations

AI explains the key points of each finding and how to address it. The AI runs on your Amazon Bedrock.

Benchmarks & frameworks

Inspect against industry standards,
see your coverage at a glance

CSPM assesses your cloud configuration against CIS Benchmarks and AWS's official best practices, and maps the results to frameworks such as PCI DSS, NIST and SOC 2. Standards that used to differ by cloud are brought together in one screen and one score.

CIS

CIS Benchmarks

Assesses configuration against the CIS Foundations Benchmarks for AWS, Microsoft Azure, Google Cloud and Oracle Cloud (OCI), and the CIS Google Kubernetes Engine (GKE) Benchmark.

AWS FSBP / NIST 800-53

AWS official standards

Assesses against AWS Foundational Security Best Practices and the AWS Security Hub mapping for NIST SP 800-53 Rev. 5.

PCI DSS / NIST CSF / SOC 2

Mapping to major frameworks

Maps findings to PCI DSS, NIST Cybersecurity Framework and SOC 2 requirements to help you prepare for audits and explanations to business partners.

POSTURE SCORE

Weighted score

A pass rate weighted by severity shows the state of your whole environment and your attainment for each framework as a single number. When too few items could be assessed, the score is not shown, to avoid giving a misleading picture.

Please note: Framework coverage reflects how CyberForces checks map to each standard; it is not a substitute for certification or audit. CIS GKE is evaluated when the Google Cloud project has GKE clusters. Only part of the Microsoft Cloud Security Benchmark can be assessed automatically, so it shows results per control rather than an overall attainment score.

Systems & blast radius

See the blast radius
from how resources connect

Looking at misconfigurations one by one doesn't tell you which business functions they affect, or how far. CSPM automatically detects “systems” from the connections between load balancers, servers, databases, storage and other resources, and groups findings, exposure paths and security events by system.

CyberForces › CSPM › SystemsSystemsAuto-detected · 4 systemsshop-prodshop-prod7 resources · publicCRITcorp-portal5 resources · publicHIGHbatch-etl4 resourcesMEDanalytics6 resourcesLOWMisconfiguration12Attack path3Events (24h)5Resources7INTERNET0.0.0.0/0ALBshop-prod-albpublicCLOUDFRONTd1x...cf.netpublicEC2shop-web-1CVE ×3LAMBDAorder-apiRDSshop-dbPIIS3shop-assetsInternet exposureVia vulnerable resourceNetwork path
Screen mockup (data shown is fictitious)
SYSTEMS

Automatic system detection

Automatically assembles each “system” from network paths and relationships between resources. No need to build an inventory by hand.

NETWORK EXPOSURE

Exposure paths from the internet

Shows, as paths, which resources are exposed to the internet and which servers and data are connected behind them.

DATA EXPOSURE

Paths to important data

Identifies paths by which important data, such as storage and databases, can be reached from outside, and shows them as data exposure.

ROLL-UP

Risk by system

For each system, totals the number of misconfigurations and their highest severity, the number of attack paths and related security events (CSEM), so you know which system to tackle first.

Context-aware risk

The same finding carries
different risk in different environments

A misconfiguration in an internet-reachable production environment and a default setting in an unused region may both be “critical,” but their urgency is completely different. CSPM ranks the findings that truly need urgent action at the top, using a risk score that combines severity with environmental context.

EXPOSURE

External exposure

Weights change depending on whether a resource is directly reachable from the internet, indirectly reachable or internal only.

CRITICALITY

Account and asset criticality

Set criticality, such as production or staging, and the sensitivity of the data handled, and findings in important environments naturally rise to the top.

REGION SCOPE

Unused regions

Default VPCs, security groups and similar resources left in regions with no workloads are weighted lower to reduce noise.

ATTACK PATH

On an attack path?

Findings on a path by which resources or important data can be reached from the internet get even higher priority. Paths and data exposure can be reviewed on screen.

Specifications

Scope and delivery

Supported clouds
  • AWS / Microsoft Azure / Google Cloud / Oracle Cloud (OCI)
Connection method
  • AWS: create a primarily read-only IAM role with CloudFormation
  • Azure: service principal / Google Cloud: service account / OCI: API signing key
Notifications
  • Email / Slack / Webhook
Pricing
  • Base fee plus charges based on the number of monitored resources

Please note: Framework coverage reflects how CyberForces checks map to each standard; it is not a substitute for certification or audit. CIS GKE is evaluated when the Google Cloud project has GKE clusters. Only part of the Microsoft Cloud Security Benchmark can be assessed automatically, so it shows results per control rather than an overall attainment score.

Getting started

Getting started

  1. Connect accounts

    Use the provided template to create read permissions and register them.

  2. Review the assessment

    Assessment starts after you connect, and findings and scores are displayed.

  3. Set criticality

    Setting account and asset criticality makes prioritization more accurate.

FAQ

FAQ

Does it fix settings automatically?

CSPM assesses with primarily read-only permissions and shows how to fix issues. It never changes the configuration of your environment automatically.

Works well with

CSPM — details and demo requests

Our team will explain deployment options and pricing for your environment.