Cloud hardening
AWS WAF, GuardDuty and CloudTrail; Azure Sentinel; GCP Security Command Center. Identity, key management and secrets configured for a production estate rather than a pilot account.
02 · ProtectEstate protection
Hardened infrastructure, defenses that have actually been attacked on purpose, and the control evidence that turns a security claim into something an auditor, a regulator or a procurement committee will accept.
The position
Boards do not buy assurance from a description of good practice. They buy it from records: what was configured, what was tested, what was logged, and who could have changed it without anyone noticing.
Production record
The discipline here is not theoretical. It runs daily on MERJ Exchange — a regulated securities exchange serving 135 jurisdictions, with audit logging on every administrative action and penetration testing before every major release.
Uncomfortable truths
None of them require a novel exploit. They require somebody to have checked, and for the check to have left a record.
Responsibility is shared, and the half that fails is almost always yours: identity breadth, storage left open, keys never rotated, logging never switched on.
Assessors do not accept description. They accept records. If the log was not enabled at the time, the control was not in force at the time.
Configuration drifts, dependencies age, and an estate that passed review two years ago is a different estate today. Testing has to recur or it decays into paperwork.
We do the engineering and prepare the evidence. The certificate comes from an accredited body — treat anyone offering both as a finding in itself.
What we build
One engagement, because splitting them produces either a secure estate nobody can certify or a certificate over an estate nobody tested.
AWS WAF, GuardDuty and CloudTrail; Azure Sentinel; GCP Security Command Center. Identity, key management and secrets configured for a production estate rather than a pilot account.
SIEM and EDR with real-time alerting, response playbooks that have been rehearsed, and automated containment for the cases measured in minutes.
External and internal penetration testing, application security testing, and network scanning — delivered as a prioritized remediation sequence, not a document nobody reads.
Role-based access with explicit per-resource matrices, scheduled key rotation, and secrets held in a manager rather than an environment file committed years ago.
Every state change, access and administrative action logged and attributable — the record that turns an assertion of control into something an assessor can verify.
ISO 27001, SOC 2 Type II, GDPR, PCI DSS. Not interchangeable: each changes the controls, the evidence, and how much of the burden lands on your own people.
The rest of the mandate
If the honest answer is never, or not since the last rebuild, that is where the engagement begins. The output is a prioritized sequence — and you are free to take it elsewhere.