Home / Services / Cloud Security / CSPM
Cloud Security / Cloud configuration assessmentCatch cloud misconfigurations
before they become incidents.
CSPM (Cloud Security Posture Management) continuously inspects your cloud configuration and detects misconfigurations such as incorrect public-access settings and excessive permissions. Findings are ranked not just by severity but by risk that factors in external exposure and account criticality, and each one explains both why it is dangerous and how to fix it.
Challenges
Sound familiar?
Misconfigurations open the door to incidents
Most breaches start with an overlooked setting, such as public storage settings or overly broad security groups.
Too many findings to make progress
Benchmarks produce hundreds of findings, and you can't tell which to fix first.
Different standards across clouds
Each cloud has its own tools and views, so you can't assess your overall posture against one standard.
Features
CSPM key features
01Benchmark-based assessment
Assesses configuration against CIS Benchmarks (AWS / Azure / OCI), AWS Foundational Security Best Practices and NIST SP 800-53 (AWS).
02Framework coverage
Maps findings to major frameworks such as PCI DSS, NIST CSF and SOC 2 to help you understand where you stand.
03Attack path and data exposure views
See on screen the paths by which resources can be reached from the internet, and where important data is exposed.
04Context-aware risk score
Scores combine severity with external exposure, account and asset criticality, and data sensitivity, so findings in important environments rise to the top.
05Security score
A pass rate weighted by severity gives you the state of your whole environment as a single number.
06System-level view
Automatically detects “systems” from how resources connect, so you can manage assets as groups. Includes an IAM inventory screen.
07Action center and response tracking
Shows what to do next in priority order. Create response tasks from findings and track them by owner, due date and progress.
08AI explanations
AI explains the key points of each finding and how to address it. The AI runs on your Amazon Bedrock.
Benchmarks & frameworks
Inspect against industry standards,
see your coverage at a glance
CSPM assesses your cloud configuration against CIS Benchmarks and AWS's official best practices, and maps the results to frameworks such as PCI DSS, NIST and SOC 2. Standards that used to differ by cloud are brought together in one screen and one score.
CIS Benchmarks
Assesses configuration against the CIS Foundations Benchmarks for AWS, Microsoft Azure, Google Cloud and Oracle Cloud (OCI), and the CIS Google Kubernetes Engine (GKE) Benchmark.
AWS official standards
Assesses against AWS Foundational Security Best Practices and the AWS Security Hub mapping for NIST SP 800-53 Rev. 5.
Mapping to major frameworks
Maps findings to PCI DSS, NIST Cybersecurity Framework and SOC 2 requirements to help you prepare for audits and explanations to business partners.
Weighted score
A pass rate weighted by severity shows the state of your whole environment and your attainment for each framework as a single number. When too few items could be assessed, the score is not shown, to avoid giving a misleading picture.
Please note: Framework coverage reflects how CyberForces checks map to each standard; it is not a substitute for certification or audit. CIS GKE is evaluated when the Google Cloud project has GKE clusters. Only part of the Microsoft Cloud Security Benchmark can be assessed automatically, so it shows results per control rather than an overall attainment score.
Systems & blast radius
See the blast radius
from how resources connect
Looking at misconfigurations one by one doesn't tell you which business functions they affect, or how far. CSPM automatically detects “systems” from the connections between load balancers, servers, databases, storage and other resources, and groups findings, exposure paths and security events by system.
Automatic system detection
Automatically assembles each “system” from network paths and relationships between resources. No need to build an inventory by hand.
Exposure paths from the internet
Shows, as paths, which resources are exposed to the internet and which servers and data are connected behind them.
Paths to important data
Identifies paths by which important data, such as storage and databases, can be reached from outside, and shows them as data exposure.
Risk by system
For each system, totals the number of misconfigurations and their highest severity, the number of attack paths and related security events (CSEM), so you know which system to tackle first.
Context-aware risk
The same finding carries
different risk in different environments
A misconfiguration in an internet-reachable production environment and a default setting in an unused region may both be “critical,” but their urgency is completely different. CSPM ranks the findings that truly need urgent action at the top, using a risk score that combines severity with environmental context.
External exposure
Weights change depending on whether a resource is directly reachable from the internet, indirectly reachable or internal only.
Account and asset criticality
Set criticality, such as production or staging, and the sensitivity of the data handled, and findings in important environments naturally rise to the top.
Unused regions
Default VPCs, security groups and similar resources left in regions with no workloads are weighted lower to reduce noise.
On an attack path?
Findings on a path by which resources or important data can be reached from the internet get even higher priority. Paths and data exposure can be reviewed on screen.
Specifications
Scope and delivery
| Supported clouds |
|
|---|---|
| Connection method |
|
| Notifications |
|
| Pricing |
|
Please note: Framework coverage reflects how CyberForces checks map to each standard; it is not a substitute for certification or audit. CIS GKE is evaluated when the Google Cloud project has GKE clusters. Only part of the Microsoft Cloud Security Benchmark can be assessed automatically, so it shows results per control rather than an overall attainment score.
Getting started
Getting started
Connect accounts
Use the provided template to create read permissions and register them.
Review the assessment
Assessment starts after you connect, and findings and scores are displayed.
Set criticality
Setting account and asset criticality makes prioritization more accurate.
FAQ
FAQ
Does it fix settings automatically?
CSPM assesses with primarily read-only permissions and shows how to fix issues. It never changes the configuration of your environment automatically.
Works well with
CSPM — details and demo requests
Our team will explain deployment options and pricing for your environment.