|
▸ External port exposure
|
Unnoticed open ports become breach entry points |
NmapMasscan |
🔴 Security |
Plain English
What it means: Every open network "door" on your servers is a potential way in. A port is like a numbered entrance — 80 and 443 are normal web doors, but an open 22 (SSH) or 3389 (RDP) exposed to the whole internet is an invitation for attackers to try passwords all day long.
Why it matters: Most breaches start with something simple: an exposed database port (like 3306 or 5432) that nobody noticed. Our scan finds every open door so you can close the ones you don't need and lock down the ones you do.
|
|
▸ TLS / SSL configuration
|
Weak ciphers expose data in transit; expired certs kill trust |
testssl.shSSLyze |
🔴 Security |
Plain English
What it means: TLS (the lock icon in your browser) scrambles data so nobody can read it as it travels. An old or misconfigured TLS setup is like using a cheap padlock — attackers can pick it, and browsers will warn visitors your site is "not secure."
Why it matters: Weak encryption means customer passwords and card numbers can be intercepted. Expired certificates cause scary browser warnings that scare away visitors and search engines. We check everything and tell you exactly what to fix.
|
|
▸ DNS hygiene
|
Dangling records, zone transfer leaks, subdomain takeover |
dnsreconAmass |
🔴 Security |
Plain English
What it means: DNS is the internet's phone book — it turns your domain name into a server address. Old, forgotten records can point to servers you no longer own. An attacker can claim that server and impersonate your brand.
Why it matters: Subdomain takeover is one of the most common ways attackers host phishing pages under a trusted brand name. We audit every record and flag the ones pointing to nothing.
|
|
▸ IAM privilege escalation
|
One over-permissive role → full account takeover |
CloudSplainingPMapper |
🔴 Security |
Plain English
What it means: IAM (Identity and Access Management) controls who can do what in your cloud. If one user has too many permissions, an attacker who compromises that account can "climb the ladder" and eventually take over everything.
Why it matters: This is how small breaches become catastrophic. A contractor with one overly broad role can accidentally (or maliciously) delete your entire infrastructure. We map every possible escalation path so you can lock them down.
|
|
▸ S3 / Blob public access
|
Data leaks, regulatory exposure, brand damage |
ProwlerScoutSuite |
🔴 Security |
Plain English
What it means: Cloud storage "buckets" (S3 on AWS, Blob on Azure) hold your files. If one is set to "public," anyone on the internet can download everything inside — customer data, backups, internal documents.
Why it matters: Public buckets have caused some of the largest data breaches in history. Data protection regulations impose significant penalties on the data controller. We check every bucket's permissions and flag the risky ones so you can remediate.
|
|
▸ Cloud spend anomalies
|
Zombie resources, over-provisioning, hidden egress fees |
InfracostAWS Cost Explorer |
🟢 Cost |
Plain English
What it means: Cloud bills are notoriously confusing. "Zombie" resources are servers and databases nobody uses anymore but still cost money every month. Over-provisioning means paying for way more power than you actually need.
Why it matters: Most companies waste 30–40% of their cloud spend without knowing it. We find the waste, show you exactly what to delete or downsize, and often pay for the assessment itself in the first month of savings.
|
|
▸ Kubernetes RBAC
|
Over-permissive service accounts → cluster compromise |
kube-benchkubescape |
🔴 Security |
Plain English
What it means: Kubernetes runs your containers (apps). RBAC decides which app can talk to which other app. If every container can talk to every other container, one compromised app can infect the whole cluster.
Why it matters: A single vulnerable container with too many permissions can let an attacker move laterally across your entire application infrastructure. We check every role and permission to enforce least privilege.
|
|
▸ Container image CVEs
|
Known vulnerabilities shipped straight to production |
TrivyGrype |
🔴 Security |
Plain English
What it means: Containers are built from "images" — pre-packaged software. Those images often contain outdated libraries with known security holes (CVEs). You might be shipping a vulnerability into production every time you deploy.
Why it matters: Attackers don't need to find new bugs when they can exploit known ones you haven't patched. We scan every image and tell you exactly which packages to update.
|
|
▸ CI/CD secret leakage
|
Credentials in pipeline logs / env vars → lateral movement |
gitleakstrufflehog |
🔴 Security |
Plain English
What it means: Your build pipeline (CI/CD) handles passwords, API keys, and tokens. If one of those leaks into a log file or a public repository, anyone who finds it can access your systems.
Why it matters: Leaked secrets are one of the fastest ways attackers get in — no hacking required, they just use the key you left lying around. We scan your pipeline history and environment for exposed credentials.
|
|
▸ Compliance-readiness technical support
|
Technical gaps can slow down your formal compliance process |
ProwlerScoutSuite |
🟣 Readiness |
Plain English
What it means: PING192 does not perform formal compliance audits or issue certifications for HIPAA, PCI-DSS, SOC 2, or ISO 27001. What we do is review your technical configuration against common control expectations and produce evidence-oriented findings that your own auditor, counsel, or compliance team can use.
Why it matters: Technical gaps — missing encryption, weak access controls, insufficient logging — often surface during a formal audit and slow the process down. We help you find and fix those technical items before your auditor does, so your formal process goes smoother.
Important: Formal certification must be performed by a licensed, qualified auditor. PING192's findings are technical observations and are not a substitute for legal or compliance advice.
|
|
▸ Backup & recovery validation
|
Untested backups = no recovery when ransomware hits |
resticVelero |
🟡 Uptime |
Plain English
What it means: A backup you've never tested is just a hope. Disaster Recovery (DR) is the plan for getting back online after something terrible happens — ransomware, fire, flood, or a rogue employee.
Why it matters: Ransomware attacks now specifically target backups first. If your backups are connected to your network, they're already compromised. We verify that your backups actually work and your recovery plan is real — as a technical observation, not a guarantee.
|
|
▸ Structural drift detection
|
Prod drifts from IaC → unpredictable failures, audit friction |
Terraform plandriftctl |
🟡 Uptime |
Plain English
What it means: "Infrastructure as Code" means your servers are defined in files (like Terraform). Drift is when someone makes a manual change in the cloud console that isn't in those files — now your documentation is a lie.
Why it matters: Drift causes outages you can't predict or reproduce. It also frustrates auditors who need to see that what's documented matches what's running. We compare your real infrastructure against your code and show you every difference.
|
|
▸ Identity graph & lateral paths
|
Attackers pivot from low-priv user to domain admin |
PMapperBloodHound |
🔴 Security |
Plain English
What it means: In large environments, identity permissions form a web. An attacker who compromises a low-level account can follow that web step by step until they reach "domain admin" — the keys to the kingdom.
Why it matters: This is how advanced attackers operate. They don't smash the front door — they find a path through the permissions you've already granted. We map every possible path and show you where to break the chain.
|
|
▸ Web server misconfig
|
Default headers, directory listing, verbose errors |
Niktocurl |
🔴 Security |
Plain English
What it means: Web servers ship with default settings — and defaults are the first thing attackers check. Directory listing shows visitors a file menu of your server (like handing a burglar a floor plan). Verbose error messages reveal exactly what software and version you're running.
Why it matters: A single misconfiguration can leak sensitive files, reveal your tech stack to attackers, or let someone browse folders they should never see. We check every header and setting against best practices.
|
|
▸ Uptime & response observation
|
Downtime directly burns revenue and reputation |
PingSLAUptimeRobot |
🟡 Uptime |
Plain English
What it means: We observe how fast your site or app responds and how often it appears unavailable during the assessment window. This is a point-in-time technical observation — not an SLA guarantee or a continuous monitoring commitment.
Why it matters: Every minute of downtime costs you sales and trust. Slow response times make visitors leave before the page even loads. We give you a baseline observation so you can make informed decisions about monitoring and reliability investments.
|
|
▸ Subdomain enumeration
|
Forgotten subdomains widen the attack surface |
Amasssubfinder |
🔴 Security |
Plain English
What it means: Large organisations often have dozens or hundreds of subdomains — dev, staging, old marketing sites, forgotten microservices. Each one is another door. Attackers find them, you may not even know they exist.
Why it matters: You can't protect what you don't know you have. We discover every subdomain and test its security posture so there are no surprises.
|
|
▸ Security headers
|
Missing headers leave browsers open to XSS, clickjacking |
securityheaders.com |
🔴 Security |
|
▸ CMS & plugin vulnerabilities
|
Outdated WordPress/plugins are the #1 small-business breach |
WPScandroopescan |
🔴 Security |
Plain English
What it means: If your website runs on WordPress, Joomla, Drupal, or any CMS, it uses plugins and themes written by third parties. When those third parties release a security patch, you have to install it — or attackers will use the old vulnerability to break in.
Why it matters: The majority of small-business website breaches happen through outdated CMS plugins. We scan every plugin and theme and tell you which ones are vulnerable.
|
|
▸ Terraform state exposure
|
State files contain secrets and infrastructure blueprints |
tfseccheckov |
🔴 Security |
Plain English
What it means: Terraform keeps a "state file" that records everything about your infrastructure — including passwords and connection strings. If that file leaks, attackers get a complete map and the keys.
Why it matters: State files are often stored in public S3 buckets or committed to Git by accident. We check where your state lives, who can access it, and whether it's encrypted.
|
|
▸ Security group / firewall rules
|
0.0.0.0/0 rules expose services to the entire internet |
ProwlerAWS Config |
🔴 Security |
Plain English
What it means: A security group is a firewall rule that says "this port is open to this IP range." A rule that says "0.0.0.0/0" means the whole internet can reach that port. That's fine for a public website, but dangerous for a database.
Why it matters: Misconfigured firewall rules are one of the top causes of cloud breaches. We audit every rule and flag anything that shouldn't be world-accessible.
|
|
▸ Cloud logging & monitoring
|
No audit trail = no forensics when something goes wrong |
CloudTrailGuardDuty |
🔴 Security |
Plain English
What it means: When something happens in your cloud — someone logs in, deletes a database, changes a permission — a log entry should record it. Without logs, you have no way to investigate a breach or demonstrate due diligence.
Why it matters: "We think we were breached three months ago but we can't tell" is not a good answer for customers, partners, or regulators. We verify that logging is enabled everywhere and retained long enough for your needs.
|
|
▸ Network segmentation
|
Flat networks let one breach compromise everything |
Nmapcloud-native tools |
🔴 Security |
Plain English
What it means: A "flat" network is like an open-plan office — everyone can walk into everyone else's space. Segmentation puts walls between departments so an intruder in accounting can't stroll into the CEO's office.
Why it matters: Segmentation limits the blast radius of a breach. If a web server gets compromised, segmentation stops the attacker from reaching your databases. We map your network zones and test the boundaries.
|
|
▸ Observability gaps
|
Blind spots mean you learn about outages from customers |
PrometheusGrafana |
🟡 Uptime |
Plain English
What it means: Observability is your ability to see what's happening inside your systems — metrics, logs, and traces. Without it, you're flying blind. You find out about problems when customers complain, not when they start.
Why it matters: Every minute you spend diagnosing a problem is a minute your service is down. Good observability turns a 2-hour outage into a 2-minute fix. We audit what you're monitoring and what's missing.
|
|
▸ Incident response planning
|
Slow response turns a minor incident into a crisis |
tabletop workshop |
🔴 Security |
Plain English
What it means: When something goes wrong at 3am — a breach, an outage, a data loss — do you know who to call and what to do? An incident response plan is a fire drill for your infrastructure.
Why it matters: Panic and confusion turn a 30-minute problem into a 3-day disaster. We run a tabletop workshop with your team to test your response and find the gaps before a real incident does. This is a planning exercise, not a legal or compliance certification.
|
|
▸ Supply chain security
|
Compromised dependencies inject malware into your build |
SyftSigstore |
🔴 Security |
Plain English
What it means: Modern software is built on hundreds of open-source libraries. If one of those libraries is compromised (like the SolarWinds or Log4j attacks), your entire product can be infected without you changing a single line of your own code.
Why it matters: Supply chain attacks are the fastest-growing threat vector. We inventory every dependency, verify signatures where possible, and flag unmaintained or risky packages.
|
|
▸ Secrets management
|
Hardcoded passwords, plaintext API keys, no rotation |
VaultSOPS |
🔴 Security |
Plain English
What it means: Passwords and API keys need a safe home — not in a spreadsheet, not in a config file, not in a Git repo. Secrets management means storing them encrypted and rotating them regularly.
Why it matters: A single leaked key can give an attacker access to your entire cloud account. We check how you store, distribute, and rotate secrets, and recommend a system that scales with your team.
|
|
▸ Encryption at rest & in transit
|
Unencrypted data is readable if a disk or backup is stolen |
cloud-native KMS |
🔴 Security |
Plain English
What it means: Encryption "at rest" means your data is scrambled while sitting on a disk. Encryption "in transit" means it's scrambled while moving between servers. If either is missing, a stolen backup or an intercepted request exposes everything.
Why it matters: Encryption is a foundational control expected by customers and referenced in most compliance frameworks. We verify that encryption is enabled everywhere it should be — and that key management is sane.
|
|
▸ Patch management
|
Unpatched OS and middleware are low-hanging fruit |
LynisOpenSCAP |
🔴 Security |
Plain English
What it means: Every server and application needs regular security updates. If you're months behind, you're running software with publicly known holes that any attacker can exploit with a script.
Why it matters: Patching is the single highest-ROI security activity. We audit your patch levels across every server and tell you exactly what's outdated and why it matters.
|
|
▸ MFA & authentication posture
|
Password-only logins are trivially phished and brute-forced |
cloud IAM audit |
🔴 Security |
Plain English
What it means: Multi-factor authentication (MFA) means you need more than just a password to log in — like a code from your phone. Without MFA, a stolen password is enough to break in.
Why it matters: The vast majority of account takeovers are stopped by MFA. We check every user account, service account, and admin console to ensure MFA is enforced where it matters most.
|
|
▸ DDoS resilience
|
A single flood takes your service offline for hours |
CloudflareAWS Shield |
🟡 Uptime |
Plain English
What it means: A DDoS attack is when thousands of computers all try to visit your site at once, overwhelming it so real users can't get in. It's like a mob blocking the entrance to your shop.
Why it matters: Even a small DDoS can take down an unprotected site for hours. We check whether you have protection in place and how quickly you could recover — as a technical observation, not an uptime guarantee.
|
|
▸ WAF & application firewall
|
No WAF means every SQL injection and XSS hits your app |
ModSecurityCloudflare WAF |
🔴 Security |
Plain English
What it means: A Web Application Firewall (WAF) sits in front of your app and blocks common attacks — SQL injection, cross-site scripting, and known bad bots — before they reach your code.
Why it matters: Most web attacks are automated. A WAF stops the noise so your developers can focus on real threats. We check whether you have one, whether it's configured correctly, and what it's missing.
|
|
▸ Rate limiting & abuse prevention
|
Credential stuffing and scraping go unnoticed without limits |
API gatewayRedis |
🔴 Security |
Plain English
What it means: Rate limiting means "you can only try 5 logins per minute." Without it, an attacker can try millions of passwords against your login page until one works.
Why it matters: Credential stuffing attacks (using leaked passwords from other sites) are extremely common and entirely preventable. We check that your APIs and login pages have sensible limits.
|
|
▸ Database exposure & hardening
|
Publicly reachable databases are breached within minutes |
Nmapdb-audit scripts |
🔴 Security |
Plain English
What it means: Databases (MySQL, PostgreSQL, MongoDB, Redis) should never be reachable from the public internet. They should live in a private network, accessible only to your application.
Why it matters: Automated bots scan the entire internet for exposed databases every single day. An exposed database is breached within minutes of discovery. We check every database endpoint and network rule.
|
|
▸ CI/CD pipeline integrity
|
Compromised build pipeline = compromised production |
Sigstorein-toto |
🔴 Security |
Plain English
What it means: Your CI/CD pipeline is the factory that builds and deploys your software. If an attacker can modify the pipeline, they can inject malicious code into everything you ship — without touching your source code.
Why it matters: Pipeline attacks are the new frontier. We audit who can modify your pipeline, whether builds are signed, and whether artifacts are verified before deployment.
|
|
▸ Disaster recovery testing
|
DR plans on paper fail the moment they're needed |
chaos engineering |
🟡 Uptime |
Plain English
What it means: A disaster recovery plan is a document that says "if X breaks, do Y." But if you've never actually practised it, you don't know whether Y works — or whether the person who wrote the plan still works at your company.
Why it matters: When a real disaster hits, panic sets in. A practised plan turns panic into procedure. We help you run a live DR test and document what actually works — as a technical exercise, not a guarantee of recovery outcomes.
|
|
▸ Cost architecture review
|
Wrong instance types and storage tiers inflate every bill |
AWS Compute OptimizerAzure Advisor |
🟢 Cost |
Plain English
What it means: Cloud providers offer dozens of instance types and storage tiers. Choosing the wrong one means paying for performance you don't need — or getting performance you didn't pay for and suffering outages.
Why it matters: Right-sizing your architecture is the single biggest lever for cloud savings. We analyse your workload patterns and recommend the optimal — and cheapest — configuration.
|
|
▸ Reserved instance & savings plan coverage
|
On-demand pricing for steady workloads wastes 40–60% |
AWS Cost ExplorerGCP Committed Use |
🟢 Cost |
Plain English
What it means: Cloud providers charge less if you commit to using a certain amount of compute for 1–3 years. If your workload is steady and you're paying on-demand prices, you're leaving money on the table.
Why it matters: Reserved instances and savings plans can cut compute costs by 40–60%. We analyse your usage and tell you exactly what to commit to — without over-committing.
|
|
▸ Egress & data transfer costs
|
Hidden egress fees silently drain your cloud budget |
AWS Cost ExplorerCloudHealth |
🟢 Cost |
Plain English
What it means: Cloud providers charge you when data leaves their network — egress fees. If your architecture moves a lot of data between regions or to the internet, these fees can be surprisingly large.
Why it matters: Egress is one of the most commonly overlooked cloud costs. We map your data flows and show you where architecture changes could eliminate unnecessary transfer fees.
|
|
▸ Orphaned & unattached resources
|
Forgotten volumes, IPs, and snapshots cost money forever |
Cloud CustodianAWS Config |
🟢 Cost |
Plain English
What it means: When you delete a server, its disk volumes, snapshots, and elastic IP addresses often stick around. Nobody uses them, but you pay for them every month.
Why it matters: Orphaned resources are pure waste. In a typical cloud account, they account for 5–15% of the bill. We find every one and give you a safe-to-delete list.
|
|
▸ Resource tagging & cost allocation
|
Without tags, you can't tell which team or product spent what |
AWS Tag EditorCloudHealth |
🟢 Cost |
Plain English
What it means: Tags are labels you attach to cloud resources — "team: marketing," "project: mobile-app," "environment: production." Without them, your cloud bill is one giant, unassignable number.
Why it matters: You can't optimise what you can't measure. Tagging lets you see exactly which team, product, or customer is driving cost — and hold them accountable. We audit your tagging strategy and fill the gaps.
|