Secorvia is my attempt at both:
ā One console for AWS, Azure, GCP and DigitalOcean.
ā CVEs enriched with EPSS and CISA KEV, not just CVSS. So "Critical" means
someone is actually exploiting this, not just that it scored high.
ā Over-permissioned identities, unused roles and stale access surfaced (CIEM),
because in cloud, identity is the perimeter.
ā Containers, Kubernetes, runtime and IaC misconfigurations caught before they
deploy, not after.
ā Findings mapped to SOC 2, ISO 27001, CIS and NIST CSF, so audit prep is a
report instead of a project.
Where it's at: posture scanning is agentless, so it's a read-only role and about
five minutes (depends on the number of resources) to your first real attack paths.
I'll be here all day. And a genuine question, because I want to hear how other
people do this: how does your team decide what to fix first right now? Severity
sort? Whatever the auditor flagged? Gut feel? I've heard all three and I don't
think anyone's happy with any of them.