Skip to content
CloudMindSolutionsCloudMind Solutions Inc.
Cybersecurity

A finding you can't reproduce isn't a finding.

Plenty of assessments hand you a 90-page report generated by a scanner, sorted by CVSS score, with no view on which paths an attacker would actually take through your estate. We write the ones you can act on, in the order that reduces real risk.

reports include
Reproduction steps
starts with
Attack-path review
retest
Included, no re-scope

Severity scores are not a priority order.

A critical vulnerability on an isolated internal host with no route to anything valuable is a lower priority than a medium on the box that holds domain admin credentials. Scanner output cannot make that distinction because it does not know your network, your data, or your business.

We work the other way round: identify what an attacker would actually be after, map the paths that reach it, and then rank findings by whether they shorten one of those paths. The report is shorter and the remediation list is one you can finish.

Scope

What the practice covers

Assessment and remediation are separable. Taking the assessment and fixing things with your own team is a perfectly good outcome, and we price it so that stays true.

Risk assessment

Named attack paths from a realistic starting position — a phished user, a compromised vendor account, an exposed service — through to the data or systems that would actually hurt. Ranked by path length and impact, not by score.

Penetration testing

Manual testing with reproduction steps a developer can follow, evidence attached, and a retest after remediation included in the original scope. External, internal, web application, and cloud configuration.

Zero-trust architecture

Identity-centred access design, segmentation, and conditional policy — sequenced so each phase is independently useful. Nobody finishes a zero-trust programme; the point is that stopping halfway still leaves you better off.

Compliance readiness

HIPAA, PCI DSS, SOC 2, and CMMC. Control mapping, gap analysis, evidence collection wired into systems that already produce it, and the artifacts an auditor will ask for. We reduce audit scope before we secure it — the cheapest control is the system that no longer holds regulated data.

Incident response

Retainer-backed response, containment, forensics, and the written timeline your insurer and counsel will need. Tabletop exercises beforehand, because the first time a team runs the plan should not be during an incident.

Detection engineering

Tuned detections mapped to techniques your estate is actually exposed to, with alerts routed to somebody who can act on them. An unread alert queue is worse than no alerting, because it looks like coverage.

Process

How a security engagement runs

Rules of engagement are agreed in writing before anything is touched, including what we will not do without a phone call first.

Week 1

Scope and rules of engagement

What is in scope, what is explicitly out, testing windows, escalation contacts, and the conditions under which we stop and call you. Signed before any testing begins.

Week 2–3

Test and validate

Manual testing supported by tooling, not the reverse. Every finding is reproduced and evidenced. Anything critical is reported the same day rather than held for the report.

Week 4

Report and walk through

A ranked remediation list with reproduction steps, a technical session with your engineers, and a separate plain-language summary for the board. Both are written by the people who did the testing.

After remediation

Retest

We verify the fixes and update the report. Included in the original scope — a retest should not require a new statement of work.

Worked example · Community bank

Four findings that mattered out of a scanner's ninety-one

Drawn from engagements the founders ran at previous employers, before CloudMind existed. It is not a CloudMind client reference, and we will not present it as one.

An annual assessment from a previous vendor had produced 91 findings and no meaningful remediation, because the list was unrankable and the team had stopped reading it.

What we did

  • Attack-path mapping from three realistic starting positions, including a compromised branch workstation
  • Manual testing of the paths that reached core banking or customer data
  • Four findings identified as materially shortening a path to the crown jewels; the rest documented and deprioritised with reasoning
  • Remediation walkthrough with the internal team, who did the fixes themselves
The previous report told us we had ninety-one problems. This one told us which four an attacker would actually use.
What we took away from it
Findings on the critical path
4Findings on the critical path
To full remediation
11 daysTo full remediation
Verified closed at retest
100%Verified closed at retest

[PLACEHOLDER STAT] Figures are illustrative. Replace with real numbers from the founder’s prior engagement, cleared by that employer and with a contactable reference — or remove the section until one exists.

Questions

What people ask before they sign.

If your question is not here, ask it directly — we would rather answer it now than in month three.

Will testing take our systems down?

Testing carries risk and we do not pretend otherwise. We agree testing windows, exclude fragile systems by name, and stop immediately on any sign of instability. Denial-of-service testing is out of scope unless you specifically ask for it in writing. For genuinely fragile production systems we test a staging replica and say so clearly in the report.

Do you just run a scanner?

Scanners are used for coverage, not for findings. Anything that appears in the report has been reproduced by hand with evidence attached. If a finding is scanner output we could not validate, it goes in an appendix marked as unverified rather than in the main list.

We need a report for a client or insurer by a specific date. Can you meet it?

Usually, if the scope is agreed with enough lead time. Be direct with us about the deadline and what the report needs to demonstrate — a client security questionnaire and a PCI assessment are different pieces of work, and scoping for the wrong one wastes both our time.

What if you find something serious mid-test?

We stop and call you the same day, before it goes in any document. Critical findings are reported as they are discovered. You should never learn about active exposure from a PDF three weeks later.

Can you fix what you find?

We can, but it is a separate engagement and you are under no obligation to use us. There is an obvious conflict in the same firm finding and billing for problems, so we keep the assessment fee fixed and independent of what turns up. Taking the report and remediating in-house is a perfectly good outcome.

Start with a cybersecurity assessment.

Two weeks, fixed fee, no commitment to a build. You end up with a written account of what you run today and a costed plan — yours to keep even if you take it elsewhere.