Services / Security analysis
Current-state assessmentSecurity analysis - a risk map and an order of work
Cloudflare shows what is exposed to the internet. ntopng shows traffic on the network. OpenVAS shows known gaps. Wazuh shows signals from hosts. We put this into one risk map, with an order of work. Layer deployment and on-call are a separate security service.
Four views, one risk map
A scan without traffic guesses exposure. Traffic without the host does not say what happened on the machine. The edge without the rest sees only the internet. Analysis joins these four views and leaves an order of work.
- The result is a map and a backlog, not a Wazuh deployment or 24/7 on-call.
- A compliance audit maps that state to ISO, SOC 2, or DORA. Analysis first says what is there.
What is public, before we enter the network
Analysis starts at the edge. DNS, certificates, WAF, Access, and whether origin still listens on a public address. Cloudflare Security Analytics shows bot score, rules, and the request log. From that we know what is actually visible from the internet.
Surface
Hostname, ports, panels, API. A list of what should be public. The rest behind Access or VPN.
Internet traffic
Bot score, a scan, a flood, login attempts. Whether the edge stops the mass, or passes it to origin.
Identity
Grafana, cloud, and staging through SSO. A panel on a password on the internet is a finding.
Gap
Origin beside Cloudflare, a stale DNS record, an open admin port. That is exposure, not a network detail.
Traffic that leaves the known profile
ntopng classifies flows, applications, and hosts. Analysis compares an ordinary day with a deviation: a new destination, a scan, large egress, traffic between machines that should not talk. Without this picture a gap scan says what can be attacked, not whether someone already walks the network.
Profile
Who talks to whom, which protocols, which volume. A baseline, not a one-off dump.
Deviation
A new ASN, unusual DNS, a connection outside the known set of services, a jump in volume.
Segmentation
Whether staging sees production, whether the database is reachable from a laptop, whether the jump host is the only path.
Correlation
A flow is lined up with a host alert and with the edge. One event, three views.
Known gaps with exposure, not only a numeric score
OpenVAS gives a list of known gaps. Analysis weights them together with exposure and data. A public application and a card dataset before a host with no internet traffic. The result enters the risk map, it does not stay a separate PDF.
Scope
Hosts, panels, databases, staging, and production. A separate policy for what is visible from the internet.
Priority
CVSS together with traffic and data. A critical gap on a host with no exposure does not outrank a medium on origin.
Authentication
A scan after login shows real package versions. Without that the report guesses.
Next step
A remediation queue with an owner is already hardening or audit. Analysis says where to start.
Signals that are already on the machines
If agents already run, we look at alerts, FIM, and SCA. If not, we still write down which logs exist and which are missing. Analysis does not deploy a SIEM. It shows whether an incident can be seen today, or only reconstructed after the fact from a few files.
Coverage
Which hosts have an agent or a log. Production and the jump host before a test machine.
SCA and FIM
Drift against CIS, a file change outside the window. Material for configuration risk.
Alerts
Noise versus an event that needs a response. A missing playbook is a finding, the same as a missing log.
Audit trail
Whether we can say who, when, and from which source. Log retention and access enter the map too.
From scope to an order of work
First critical systems and data. Then collection from the edge, the network, the scan, and hosts. Finally a report and a decision on what to deploy.
- Scope Systems, data, who signs, what is out of scope.
- Collection Surface, traffic, a gap scan, logs, and configuration.
- Report Risk, exposure, order, a justification for the board and a list for engineering.
- Decision Hardening, a compliance audit, or on-call, according to what came out.
Analysis scope and split of work
How is analysis different from a compliance audit?
Analysis describes the state: what is exposed, what the traffic is, which gaps are known, which signals are visible on hosts. An audit maps that state to ISO 27001, SOC 2, DORA, or KNF controls and leaves a backlog for certification. Analysis is often the first step, the audit the second.
Is this a penetration test?
No. A penetration test composes several gaps into one attack scenario, usually less often and with more depth. Analysis uses a scan of known gaps, traffic, and logs. It gives a map and an order for today. The test says how those gaps can be used together.
Do we already need Cloudflare, ntopng, OpenVAS, and Wazuh?
No. If the tools are there, we use them. If not, we still write down the surface, the logs that exist, and a scan we can run in scope. A missing tool is part of the picture, not a block on the analysis.
What remains after the analysis?
A risk map, an order of work, and a recommendation for the next service: security and hardening, audit, or administration. Layer deployment and on-call are scoped separately, on the basis of that report.
We will discuss the analysis scope and critical systems
On that basis we will prepare a risk map and an order of work.
Contact us