Whether it’s about cloud risks, compliance gaps, or code security, I’m here to answer questions and connect the dots. Here are just a few examples of questions I hear a lot:
Public assets
Any publicly exposed assets in our cloud?
Vulnerability
Are we getting better or worse at vulnerability management?
Vulnerabilities approaching SLA deadlines
Any vulnerabilities in our cloud environments that are approaching SLA?

Our SLA policies:
- Critical: <critical_severity_sla> hours
- High: <high_severity_sla> hours
- Medium: <medium_severity_sla> hours
- Low: <low_severity_sla> hours

Warning thresholds (advance notice):
- Critical: <critical_severity_threshold> hours
- High: <high_severity_threshold> hours
- Medium: <medium_severity_threshold> hours
- Low: <low_severity_threshold> hours
Vulnerabilities past SLA deadlines
Any vulnerabilities in our cloud environments that have already breached their SLA deadlines?

Our SLA policies:
- Critical: <critical_severity_sla> hours
- High: <high_severity_sla> hours
- Medium: <medium_severity_sla> hours
- Low: <low_severity_sla> hours
Attack paths
Any attack paths in our cloud environment?
SOC 2
Any controls/tests failing against SOC 2?
And if it’s something you want checked regularly, just let me know. I’ll put it on my list of repetitive work, keep an eye on it, and update you when it matters, no need to ask again.