What we look at
- Internet-facing attack surface: what is exposed, and should it be
- Operating system hardening against CIS-style baselines
- Identity and access: privilege paths, stale accounts, shared credentials
- Remote access: SSH, RDP, VPN and jump host configuration
- Web and application server configuration, TLS and certificate hygiene
- Patch and vulnerability management in practice, not on paper
- Backup coverage - and whether a restore has ever been tested
- Logging and detection: would you know, and how soon