Solutions · CyberSec · Preempt Early access
Fix the cloud risk that matters, and the waste beside it.
Cloud Security Foundation finds posture weaknesses across AWS, Azure and GCP, ranks them by what each one could lead to in your business, and lands the fixes with your teams. The same read-only connectors find the cloud spend that buys nothing.
Fewer critical cloud findings, and savings measured from your bill.
- Fewer critical cloud findings. Measured by CCF, Critical Cloud Findings.
- More of the prioritised fixes shipped. Measured by prioritised fixes shipped.
- Cloud savings you can see on your bill. Measured by realised cloud savings.
Supporting KPIs
Prioritised fixes shipped ↑
Share of consequence-ranked findings closed by a shipped fix, confirmed by re-simulation
re-simulation
Tag coverage ↑
Share of cloud resources carrying owner and cost tags
twin
Realised cloud savings ↑
Savings from removed waste, measured from billing after the change
cloud billing
Baselines are set in the 30-day diagnostic. Targets are committed in the 90-day scorecard. A KPI we cannot measure is reported as UNMEASURED.
Ten thousand findings, ranked by someone else's severity.
A posture dashboard reports every misconfiguration it finds, scored the same way for every company. The same open security group scores the same whether it guards a test sandbox or a server one hop from payment data.
Read why
So the list grows faster than teams can fix it, the fixes that do ship are chosen by score, and nobody can say what a given fix would break.
Meanwhile the resources nobody tagged have no owner for the security finding and no owner for the bill.
What it costs
- Remediation effort spent on findings that reach nothing that matters.
- Fixes deferred because their impact is unknown.
- Cloud spend on resources nobody owns and nobody uses.
One misconfiguration, two consequences.
sg-0f3a41 · ingress tcp/8080 · src 0.0.0.0/0on jenkins-01 · reaches s3://hl-cardholder through P-0198 · ranked first- the same ingress rule on a sandbox instance · reaches no crown jewel · ranked below
- fix proposed: narrow sg-0f3a41 · re-simulated · closes P-0198 · breaks: nothing observed
illustrative console output · the categories and the final line are the contract
Posture as consequence, and fixes that ship.
Cloud Security Foundation runs on SecSemantic's twin, so every posture finding is attached to the asset, the path and the business service it affects.
Misconfigurations across AWS, Azure and GCP are found continuously through read-only connectors.
A weakness on an asset that can reach a crown jewel outranks the same weakness on one that reaches nothing, for reasons that can be stated. Nothing is ranked by raw finding count.
Each proposed fix is applied to the twin as a read-only overlay and re-simulated, so you see what it closes and what it would break before anyone changes production.
Your pod lands the fixes with your platform teams, through your change process.
Untagged and unowned resources are raised as findings, so every finding and every cost has someone to go to.
Cloud spend on idle and unowned resources is found through the same read-only access, and savings are reported as realised from your bill, not projected.
What you get
- Posture findings across your clouds, ranked by consequence to your business
- A fix plan, each fix re-simulated with its impact
- Tag coverage and an ownership backlog
- A waste report with realised savings
Industry lens
Posture on payment and cardholder paths first, framed for PCI DSS scope.
Posture on systems holding patient records first, framed for HIPAA.
Security and cost owned by the same tagged owner.
What it is not
Not a dashboard of every finding. The work is the short list that matters and the fixes that ship.
FAQ
Do you change our cloud configuration?
No. Fixes are proposed with their impact and landed by your teams through your change process, or executed through Governed Containment with a human approval.
How do you decide what is critical?
By what the affected asset can reach in your business: its paths to crown jewels, the data it touches and the services that depend on it. Every ranking breaks down into contributions you can trace to evidence.
How are savings measured?
From your cloud bill after the change, as realised savings. Projected savings are not reported as savings.
Which clouds are covered?
AWS, Azure and GCP.
How Cloud Security Foundation is delivered
A capability, the pod that runs it with you, and a scorecard you hold us to.
-
Diagnostic · days 0 to 30, at no cost.
The twin is launched with read-only credentials and the coverage report arrives within 30 minutes. Posture findings are ranked by consequence, tag coverage and waste are measured, and every KPI baseline is set.
-
The 90-day KPI scorecard is agreed: CCF and the supporting KPIs, each committed against your baseline.
-
Outcome · days 30 to 90.
Your pod lands the prioritised fixes and the tagging with your platform teams, and removes the waste you approve.
-
The scorecard is reported with its evidence and who measured it. The outcome bonus is paid only against it.
-
The Semantic Loop · from day 90.
New findings are ranked as they appear, and every fix, exception and saving is fed back into the twin.
The pod
two senior engineers and a fractional CISO advisor
-
Forward-deployed security engineer.
Deploys the twin, connects your clouds, and owns the KPI baseline with you.
-
Platform change engineer.
Lands fixes and tagging with your platform teams through your change process.
-
Fractional CISO advisor.
Owns the 90-day scorecard with your leadership and chairs the day-90 review.
What runs underneath
Shield's cloud posture and spend analysis, on Sentinel's twin: business context and crown jewels, network reachability, attack paths and SVSS for ranking, and blast radius for re-simulation. Insights presents posture and the fix plan, read-only.
Find the ten fixes that matter.
In the diagnostic we rank your cloud posture by what each weakness could reach in your business, and measure the spend that buys nothing.