Skip to content

Services

From a one-off assessment to running security operations alongside your team, here is how we help startups and scale-ups secure their cloud.

Custos Secure Baseline

A focused assessment that scores your security across the six functions of the NIST Cybersecurity Framework and maps the path to the minimum baseline enterprise security reviews expect.

What's included

  • A security maturity assessment structured on the NIST Cybersecurity Framework, scored on a five-level scale
  • Your score across all ten dimensions, with Level 2 (Managed) as the target
  • A ranked roadmap to reach it, with a line of sight to ISO 27001 readiness
  • A report that is ready the day investor due diligence starts

M365 Security Assessment

A structured review of your Microsoft 365 environment against industry-recognised best practices, including Microsoft's own security guidance.

What's included

  • A review across identity, email, Teams and SharePoint sharing, data protection, logging and threat detection
  • Findings ranked by risk and the effort to fix, with remediation steps
  • A plain-English report your board and your engineers can both act on
  • A report that also serves investors running technical due diligence

AWS Security Assessment

A structured review of your AWS environment against industry-recognised best practices, including Amazon's own security guidance.

What's included

  • A review across identity, network, data protection, logging and threat detection
  • Findings ranked by risk and the effort to fix, with remediation steps
  • A ranked path to a stronger baseline
  • Evidence that holds up when investors come asking

Azure Security Assessment

A structured review of your Azure environment against industry-recognised best practices, including Microsoft's own security guidance.

What's included

  • A review across identity and access, network, key and secret management, data protection and monitoring
  • Findings ranked by risk and the effort to fix, with practical remediation
  • A ranked route to a stronger baseline
  • Ready to put in front of an investor asking how your cloud is secured

ISO 27001 Readiness

Where you stand against ISO 27001, and a right-sized path to audit-readiness that does not drown you in paperwork.

What's included

  • A gap analysis against the ISO 27001 standard
  • A right-sized roadmap to audit-readiness
  • Help building the policies, controls and evidence auditors expect

SecOps as a Service

Everything around security operations, day to day or project based, from pipeline security controls and monitoring to recurring reviews and on-call support.

What's included

  • Security controls in your pipeline, from image scanning to secure code analysis and SBOM checks
  • Monitoring, logging and SIEM, built or integrated into one clear view
  • Recurring reviews of user access, vulnerabilities and monitoring, on the interval that fits you
  • On-call support from a senior engineer when something serious happens
  • Tools integrated and your environment defined as code with Terraform

Security Awareness and Incident Readiness

Security runs through the choices your people make every day. We help your team work securely, recognise the attacks aimed at them, and be ready to respond when one gets through.

What's included

  • Phishing awareness, with simulations and training on what to spot and report
  • Password, access and data-handling habits across your team
  • Secure coding sessions for your engineers
  • Threat modelling workshops with your engineering team
  • An incident response plan and playbooks tailored to your environment
  • A simulated incident exercise to rehearse the response and the decisions

Dark Web Monitoring

Leaked logins surface in criminal markets and breach dumps long before most companies notice. We watch your domains and your team's credentials and alert you as soon as they surface, so you can shut the door before they are used.

What's included

  • Continuous monitoring of your domains and your team's credentials
  • A fast, clear alert when something surfaces, with what leaked and where
  • A pointer to your first move, resetting or revoking what is affected

Where you stand, and the floor to clear

We rate your security programme on a five-level maturity scale and set the target at Level 2, the floor enterprise security reviews expect. The Custos Secure Baseline is the assessment that scores it.

See how the baseline works

Not sure which one you need?

Start with a discovery call and we will point you to the right place, even if that turns out not to be us.

Book a discovery call