AMARAND
Private consultation

02 · ProtectEstate protection

Guard the estate.Prove that you did.

Hardened infrastructure, defenses that have actually been attacked on purpose, and the control evidence that turns a security claim into something an auditor, a regulator or a procurement committee will accept.

The position

Secure is a claim. Evidence is the product.

Boards do not buy assurance from a description of good practice. They buy it from records: what was configured, what was tested, what was logged, and who could have changed it without anyone noticing.

Production record

The discipline here is not theoretical. It runs daily on MERJ Exchange — a regulated securities exchange serving 135 jurisdictions, with audit logging on every administrative action and penetration testing before every major release.

Exchange-grade disciplineObservable at every stepRun daily in production

Uncomfortable truths

Four things most estates get wrong.

None of them require a novel exploit. They require somebody to have checked, and for the check to have left a record.

01

The provider secures the platform, not your configuration

Responsibility is shared, and the half that fails is almost always yours: identity breadth, storage left open, keys never rotated, logging never switched on.

02

A control you cannot evidence does not exist

Assessors do not accept description. They accept records. If the log was not enabled at the time, the control was not in force at the time.

03

Untested defenses are assumptions

Configuration drifts, dependencies age, and an estate that passed review two years ago is a different estate today. Testing has to recur or it decays into paperwork.

04

Whoever builds the controls cannot certify them

We do the engineering and prepare the evidence. The certificate comes from an accredited body — treat anyone offering both as a finding in itself.

What we build

Hardening, testing, and the record that follows.

One engagement, because splitting them produces either a secure estate nobody can certify or a certificate over an estate nobody tested.

C01

Cloud hardening

AWS WAF, GuardDuty and CloudTrail; Azure Sentinel; GCP Security Command Center. Identity, key management and secrets configured for a production estate rather than a pilot account.

C02

Threat detection

SIEM and EDR with real-time alerting, response playbooks that have been rehearsed, and automated containment for the cases measured in minutes.

C03

Adversarial testing

External and internal penetration testing, application security testing, and network scanning — delivered as a prioritized remediation sequence, not a document nobody reads.

C04

Identity and secrets

Role-based access with explicit per-resource matrices, scheduled key rotation, and secrets held in a manager rather than an environment file committed years ago.

C05

Audit evidence

Every state change, access and administrative action logged and attributable — the record that turns an assertion of control into something an assessor can verify.

C06

Framework alignment

ISO 27001, SOC 2 Type II, GDPR, PCI DSS. Not interchangeable: each changes the controls, the evidence, and how much of the burden lands on your own people.

  • ISO 27001
  • SOC 2
  • GDPR
  • PCI DSS
  • NIST CSF
  • OWASP ASVS
  • CIS Controls v8

The rest of the mandate

Three disciplines. One operating layer.

When did someone last try to break in deliberately?

If the honest answer is never, or not since the last rebuild, that is where the engagement begins. The output is a prioritized sequence — and you are free to take it elsewhere.