Posture, spend & inventory
Overall posture
health score · vs. last month
Strong security foundation — a couple of critical cloud findings are the main thing between you and an A.
Why this grade: 2 critical and 2 high findings are the main drag — clearing the criticals lifts the grade fastest.
2 critical cloud findings (a public S3 bucket, an exposed key) are the main drag; the rest is low/medium.
Multi-AZ EC2 behind an ALB; backup coverage at 74% with two failed jobs to chase down.
MFA at 88%; 24 privileged and 31 stale accounts flagged for review.
SOC 2 Type II in progress; CIS AWS Benchmark at 84%.
Intune + CrowdStrike across the fleet; one stale Windows host and a couple of EDR gaps.
AWS spend trending under last month; a few idle resources to trim.
EC2 instance querying a known crypto-mining domain · us-east-1
Critical CVE-2024-3094 (xz-utils backdoor) on processing host · us-west-2
Not enterprise-ready
4
Spend (MTD)
$19,205
Cloud resources
112
Devices compliant
20%
Servers compliant
0%
Public-facing servers
1
Entra app hygiene — retiring what isn't used.
The highest-exposure findings, ranked by severity, internet reach, data sensitivity, privileged access & age.
AWS::EC2::Instance · i-0nwprocessingec201 · us-west-2
AWS::EC2::Instance · i-0nwtradeapi3 · us-east-1
AWS::EC2::Volume · nw-processing-ec2-01 · us-west-2
AWS::Lambda::Function · processing-processor · us-west-2
Audit readiness across the frameworks that matter to the business.
91/91 controls · audited Mar 15, 2026 · Annual renewal Mar 2027
162/254 controls · Target QSA assessment Q1 2027
47/114 controls · Risk treatment plan in review
79/110 controls · audited May 20, 2026
Who can get in, and how well that access is controlled.
Update posture across cloud services, user devices, and servers.
0 of 2servers assessed — Azure & on-prem via Update Manager (Arc), AWS via Systems Manager Patch Manager. 2 not yet assessed (enable a periodic assessment / patch baseline scan).
Can we get the business back if something fails?
Last successful backup Jun 27, 2026.
The human layer — training and phishing resilience.
Critical & high-severity alerts from endpoint security and watched Teams channels.
🔴 P1: Operations portal p95 latency > 4s for 8 min; on-call paged — Northwind NOC (Teams — #nw-alerts).
Falcon detected suspicious LSASS access consistent with credential dumping on nw-fin-04 (CrowdStrike Falcon). Host network-contained; IR engaged.
Encoded PowerShell spawned from Office on nw-sales-11 — likely a macro-borne loader (CrowdStrike Falcon). Blocked; investigating delivery.
Falcon quarantined an Emotet-family binary on nw-ops-02 (CrowdStrike Falcon). No lateral movement observed; monitoring for re-infection.
Tickets your team manages in NorthwindSD.
Monitored workloads and your key services — live uptime and vendor status pages.
Findings, spend & resources across connected clouds.
GuardDuty flagged nw-trade-api-3 making repeated DNS lookups to a known cryptocurrency-mining pool — consistent with compromise.
Fix: Isolate the instance, rotate its credentials, and hunt for persistence (Amazon GuardDuty).
AWS::EC2::Instance · i-0nwtradeapi3 · us-east-1
since 2026-08-04
Inspector detected the compromised xz-utils build (CVE-2024-3094, CVSS 10.0) on nw-processing-ec2-01.
Fix: Patch xz-utils to a fixed release and rebuild the AMI (Amazon Inspector).
AWS::EC2::Instance · i-0nwprocessingec201 · us-west-2
since 2026-08-03
The processing-processing Lambda has no reserved concurrency. Under load it competes for account concurrency and throttles, delaying processings at peak.
Fix: Set reserved + provisioned concurrency sized to peak and add a DLQ for failed invocations.
AWS::Lambda::Function · processing-processor · us-west-2
since 2026-06-03
Several EBS volumes on production hosts are unencrypted at rest — fails the encryption-everywhere baseline.
Fix: Snapshot, re-create as KMS-encrypted volumes, and enable EBS encryption-by-default on the account.
AWS::EC2::Volume · nw-processing-ec2-01 · us-west-2
since 2026-05-30
vs $27,121 last month (-29%)
Active endpoints from Intune & Jamf (seen in the last 30 days), grouped by device class — encryption, EDR coverage, and patch status.
| Device | User | OS | MDM | Encrypted | EDR | Updated | Last seen |
|---|---|---|---|---|---|---|---|
Northwind-WIN-FIN-038 9JK1120LMN | p.okoye@northwind.example | Windows 11 22H2 | Intune | BitLocker: yes BitLocker | EDR: yes CrowdStrike | Updated: no | 5d ago |
Northwind-WIN-LEGAL-011 3RT5560WQP | d.reyes@northwind.example | Windows 10 22H2 | Intune | BitLocker: yes BitLocker | EDR: no | Updated: no | 21d ago |
Northwind-WIN-OPS-076 7XY8821RTM | k.shah@northwind.example | Windows 11 23H2 | Intune | Encrypted: no | EDR: yes CrowdStrike | Updated: yes | 2d ago |
Northwind-WIN-TRADE-112 5CD2419QPL | t.nguyen@northwind.example | Windows 11 23H2 | Intune | BitLocker: yes BitLocker | EDR: yes CrowdStrike | Updated: yes | today |
| Device | User | OS | MDM | Encrypted | EDR | Updated | Last seen |
|---|---|---|---|---|---|---|---|
Northwind-IPHONE-ONCALL | shared-oncall@northwind.example | iOS 18.5 | Intune | Data Protection: yes Data Protection | EDR: unknown | Updated: yes | 8d ago |
Cloud & on-prem hosts by environment — encryption, EDR, patch status, and public exposure.
| Host | OS | Env | Encrypted | EDR | Updated | Public IP(s) |
|---|---|---|---|---|---|---|
nw-bastion-01 us-west-2 | Amazon Linux 2023 | prod | EBS KMS: yes EBS KMS | EDR: yes CrowdStrike | Updated: no | 44.230.61.7 |
nw-processing-ec2-01 us-west-2 | Ubuntu 22.04 LTS | prod | Encrypted: no | EDR: yes CrowdStrike | Updated: yes | none |
How each workload is wired across AWS, Azure & GCP — internet-facing entry points down to data services.