Skip to content
KanoSystems

Security built into every layer of your estate.

An auditor asks for evidence, not policy. We find what is actually exposed and write it up so an engineer can reproduce it and a board can understand it.

What you get

Outcomes you can expect.

Evidence an auditor accepts, not a folder of documents nobody has read
Findings with reproduction steps — and a retest that confirms they are closed
Every privileged account owned by a named person who knows they own it
Cybersecurity

Cloud security & identity

We assess your cloud posture (CSPM) against CIS benchmarks, close gaps with guardrails, and move identity to zero trust and least privilege, so misuse gets noticed.

Who it is for

  • Teams whose cloud accounts grew faster than anyone reviewed them.
  • Organisations with far more active accounts than staff, and no clear owner for the extras.
  • Businesses that need single sign-on and phishing-resistant sign-in across cloud and internal systems.

What you get

  • A written assessment with findings an engineer can reproduce
  • Guardrails that stop the same mistakes being made again
  • Accounts and roles with a named owner and the least access they need
  • Single sign-on and phishing-resistant sign-in where it matters most
  • Evidence that each fix was retested and closed

What we do

  1. Benchmark the estate

    We assess accounts against CIS benchmarks with Prowler and Security Hub, Defender for Cloud or Security Command Center, covering IAM, storage, networking and secrets, and write up what is exposed.

  2. Close the gaps with guardrails

    We turn findings into policy as code and preventive controls that block unsafe settings before they are created, so a fix stays fixed.

  3. Tidy identity

    We clean up accounts and roles, move people to SSO on Entra ID, Okta or Keycloak (SAML or OIDC), add phishing-resistant MFA (FIDO2) and conditional access, and put admin rights behind PAM with just-in-time access.

  4. Cover detection

    We check the logs and alerts needed to spot misuse exist, and fill gaps with a SIEM such as Wazuh or Microsoft Sentinel, EDR and detection engineering mapped to MITRE ATT&CK.

  5. Retest and keep the evidence

    We verify each fix closed its gap and keep the evidence, so an auditor sees proof and not a promise.

Start here

Cloud security assessment

A bounded look at what is actually exposed in your cloud and who can reach it, ending in a written report with the first fixes marked.

What is examined

  • Account and configuration settings, checked against recognised benchmarks with tooling
  • Who holds privileged access, who owns each account, and which accounts nobody can explain
  • How people sign in, and where single sign-on and phishing-resistant sign-in are missing
  • Whether the logs and alerts needed to spot misuse exist and are watched

How it works

  1. 01 Scope. We agree which accounts, environments and questions are in, and who we need to talk to.
  2. 02 Discover. We gather configuration and identity data with read-only access, and talk to the people who run the cloud.
  3. 03 Assess. We test the findings so each one can be reproduced, and rank them by the harm they could do.
  4. 04 Report. We write up what is exposed, in plain language, with the first fixes marked.
  5. 05 Review. We walk through the report with your team, answer questions and agree what happens next.

What you receive

  • A written report with findings an engineer can reproduce
  • A ranked list of fixes, with the reasons
  • A map of who can reach what, with the risks marked
  • A readout session with your team
  • If you want help, we can close the gaps with guardrails, or hand the plan to your own team.
  • If you do not, you keep a clear record of where your cloud stands and why.
Book a consultation

Scope and timing are agreed on a call, before anything is committed.

Cybersecurity

Penetration testing & red team

We test your systems as an attacker would, from outside and within, write findings you can reproduce, and retest the fixes. Red team exercises also test detection and response.

Who it is for

  • Organisations preparing for an audit, a launch or a major change.
  • Teams that want to know what an attacker could really do, not what a scanner lists.
  • Security leaders who want to learn whether detection and response work, not just prevention.

What you get

  • A report with reproduction steps for every finding
  • A plain-language summary for leadership
  • The attack paths we found, drawn from start to finish
  • A retest confirming which findings are closed
  • A debrief with your engineers

What we do

  1. Agree scope and rules

    We settle what is in, what is off limits, and who knows the test is happening, so nothing surprises your operations.

  2. Test as an attacker would

    External, internal, web, API, mobile and cloud testing against the OWASP Top 10 and ASVS, plus Active Directory and Kubernetes attack paths, using the methods a real intruder would try.

  3. Chain the weaknesses

    One weakness is rarely the story. We chain them, through privilege escalation, lateral movement and misconfigured Active Directory certificate services, and show the path to administrator rights where one exists.

  4. Write findings you can reproduce

    Every finding has steps an engineer can follow, a plain explanation a board can understand, and a recommended fix.

  5. Retest, and go further if you are ready

    Retesting is included. For mature teams we run objective-based red team and purple team exercises, mapped to MITRE ATT&CK, that test whether you detect and respond.

Cybersecurity

Compliance & data protection

We take you through ISO 27001 and SOC 2, from scope and risk method to controls and audit, and map data protection law to controls with named owners.

Who it is for

  • Companies whose customers or regulators have asked for ISO 27001 or SOC 2.
  • Teams that treat compliance as paperwork and want controls that actually operate.
  • Organisations that move data across borders and must show it is handled lawfully.

What you get

  • A scope and risk method written down and agreed
  • Controls running inside your teams, each with a named owner
  • A map from data protection law to your controls
  • Evidence collected from your systems
  • Support through the audit and its follow-up

What we do

  1. Set the scope and the risk method

    We agree what the certification covers and how risk will be judged, so effort goes where the risk is.

  2. Implement controls that operate

    We put controls into the way your teams already work, with a named owner for each and continuous control monitoring, instead of adding a parallel process.

  3. Map data protection to controls

    GDPR, CCPA and local regimes are mapped to specific controls and owners, with data mapping, DPIAs and a record of processing, including the rules for moving data between countries.

  4. Gather evidence as you go

    Evidence is collected automatically from the systems that do the work, so audit week is a review and not a scramble.

  5. Support the audit

    We prepare your team, sit in on the audit, and handle the follow-up questions.

Ready to get started?

Book thirty minutes with our team for a clear view of scope and cost.