Whether it’s about cloud risks, compliance gaps, or code security, I’m here to answer questions and connect the dot. Here are just a few examples of questions I hear a lot:
Vulnerability
Are we getting better or worse at vulnerability management?
Attack paths
Any attack paths in our cloud environment?
Public assets
Any publicly exposed assets in our cloud?
SOC 2
Any controls/tests failing against SOC 2?
And if it’s something you want checked regularly, just let me know. I’ll put it on my list of repetitive work, keep an eye on it, and update you when it matters, no need to ask again.