Aller au contenu
ALTIMETRIADEV & TECH

Cybersecurity & Audit

The supplier says it is secure. No one has a record of what was tested, when, or by whom. An assurance that rests on no measurement is not an assurance: it is a hope.

Security is not promised: it is tested, measured and fixed.

Contained exposure

Why an incident stops instead of spreading

Three rings: identities come in, services answer, data stays at the centre. The scene first lights up every conceivable path, then keeps only those with a reason to exist — least privilege, shown by subtraction. One identity turns, a wave starts: the breaker opens a gap, the wave stops at the ring, one sector goes dark and the rest keeps serving. Below, the record builds up, one bar per event. A shape and a movement — no real data, and no attack method.

Cybersecurity & audit

The blast radius

Three rings — identities, services, data — and requests travelling inward. The scene first shows every conceivable path, then keeps only those with a reason to exist. One identity turns, a wave starts; the breaker opens a gap and the wave stops at the ring. One sector goes dark, the rest keeps answering — and the record builds up, one bar per event.

A management team sold security as a bullet list, that would like to see what “least privilege” and “blast radius” actually mean once applied to their own system.

Watch the needless paths vanish, then the wave stop dead at the ring.

Three.js · WebGL · 3 anneaux instanciés · moindre privilège par soustraction · onde arrêtée au disjoncteur · trace immuable · récit en 5 chapitres · repli sans WebGL

What we monitor, and what we refuse to promise

The executive register is visible without a click; the expert register lives in the panel, guardrail on show — that is what separates an honest demonstration from a brochure.

DEV & TECHNOLOGY · RUN

Make the incident visible before it becomes a crisis.

Identity, traces, budgets and alerts share one operational context.

A credible platform can explain what it did, for whom and within which boundary.
HEALTHY · DEGRADED · CIRCUIT OPEN · INCIDENT
Method

Least privilege, immutable audit trail, distributed traces and reliability budgets.

  • RBAC / ABAC · separation of duties
  • Request · user · tenant · version correlation
  • SLO · error budget · saturation
  • Circuit breaker · recovery · idempotency key
  • SBOM · dependencies · patch policy
  • Runbook · escalation · blameless postmortem
When we call a system secure, we give the scope, the threat model, the date and the verified controls.

The four surfaces an audit opens

The method says how we proceed; this says what we open. Four surfaces, and for each the finding we meet most often.

01

What is exposed

The inventory of everything answering from outside: open services, forgotten environments, staging interfaces left reachable, published dependencies.

The most frequent finding is not a flaw: it is a machine nobody knew was still running.

02

Who is allowed what

Identities, roles, service accounts and secrets: who has access, from where, with what, and what stays open after someone leaves.

Permissions are added and never removed — after three years, everyone can do everything.

03

The chain that ships

From the developer's machine to production: library provenance, artefact signing, secrets in build logs, deployment robots' permissions.

The application gets protected while the door that builds it stays open.

04

What would be seen

Logging, its retention, what it allows to reconstruct, and the incident procedure: detect, contain, recover, and know what was reached.

An incident without logs is told, not proven — and what cannot be proven happens again.

Controls that make the error impossible, told without the names

A control that keeps yesterday's measure and alerts on the gap, a boundary where nothing nominative crosses the wall: what we put in place, what it produced, and what was hard. Names removed, volumes kept.

TRACK RECORD · REAL ASSIGNMENTS, NAMES WITHHELD

  1. 01

    A team running its own platform that learns of incidents from its users rather than from its own dashboards.

    When · Put in place in August 2026, run every evening since.

    What we did

    We replaced the measurement that overwrites itself with one that is kept: yesterday's value is dated and retained, the gap is computed and written into the verdict itself, and a drop raises an alert that asks the only question that settles it — is this data, or a rebuildable artefact?

    What it produced

    A dated history per source, a gap computed at every run, and a daily check that reopens the database to read the date of the data actually there — not the job log, not the file timestamp: the data.

    What was hard

    Before this check, one database lost nearly half its volume in a single night. The jobs ran, every check went green, and it was a human who spotted it, by hand, comparing the previous day's map with the evening's figure. A single value cannot be wrong; two values can.

  2. 02

    An organisation that must open part of its analysis to the outside without a single name crossing the wall.

    When · September 2026, in service.

    What we did

    We connected a public interface to an internal analysis service: listening closed to the local loopback, per-caller rate limiting, machine secret read server-side — never typed on a command line, where it would linger in the history and in the process table — and a name-stripping pass run before anything is displayed.

    What it produced

    A bridge test that replays the four decisions (accepted host, rate, served mode, free text) and a bench that injects fabricated names into the chain to verify they come out stripped. Both run with no server switched on, so they actually get run.

    What was hard

    “Internal” was read from a header that any non-browser client sets freely: from the local network, a call could declare itself internal and obtain the full mode. You do not get better at checking who knocks — you close the door that opens onto the street.

No client name is published, with or without their consent. We publish no win rate: it is not measured, and an unmeasured figure is not a reference.

What we do

  • Technical audit: configuration, dependencies, permissions, real exposure.
  • Scoped and authorised penetration testing, with findings you can act on.
  • Code and delivery-pipeline review.
  • Data protection: segmentation, encryption, logging.
  • Remediation plan prioritised by exploitable risk, not by convenience.
  • Dependency and supply-chain review: a vulnerability can sleep for months because nobody opened the tool that reveals it — and we never fix by forcing major versions, which break silently.
  • Hunting three dangers across installed extensions and automations: download followed by execution, irreversible destruction, exfiltration. Every finding carries its proof line by line, and the check counts what it dismissed.
  • Review of secrets and error messages: nothing hard-coded in the source, nothing sensitive in the logs, and an error that teaches nothing to whoever triggered it.
  • Line-by-line permission review after departures and role changes — permissions pile up, they never come off by themselves.

What we deliver

Audit report ranked by criticality
Penetration test findings
Dated & prioritised remediation plan
Inventory of secrets, where they live and when they were last rotated
Permissions & logging policy
Log of dismissed findings, with the reason why
Incident & restoration procedure
Re-audit after remediation

The method

01

Scope

A written, authorised perimeter: nothing is tested outside it.

02

Test

We look for the real way in, not the theoretical vulnerability list.

03

Prioritise

What is exploitable comes first; the rest is dated, not forgotten. And a badly calibrated check is worse than none: three alerts a night, one of them real, and nobody left to read it.

04

Verify

We come back after the fixes — a report without a re-audit proves nothing. Deleting a folder is not uninstalling: as long as the declaration exists, the tool reinstalls itself.

WHAT YOU WILL HAVE IN HAND · The Closing Attack Path

Apply a fix: the severed link, paths still open and retest evidence appear.

Every path leads to the same closing point.

We turn a list of findings into understandable paths: asset, exposure, technique, impact, control and evidence. Priority comes from what is actually exploitable within the authorised scope, not from catalogue severity alone.

The executive sees the path to close, action, owner and test that will establish closure. After remediation, status does not turn green by declaration: it waits for retest evidence.

Open the path

Asset → exposure → technique → control → retest

Rules of engagement, written authorisation, scope, hours, test data, limits, emergency stop and contact chain.

Asset, identity, secret, dependency, Internet exposure and owner inventory.

Threat model: critical assets, trust boundaries, abuse scenarios, ATT&CK v19.1, controls and assumptions.

OWASP ASVS 5.0 and versioned WSTG to derive requirements and application verification cases.

CVSS v4.0 Base, Threat, Environmental and Supplemental, without reducing priority to the base score alone.

CISA KEV, observed exploitability, reachability, business impact, blast radius and SSVC to prioritise response.

RBAC/ABAC, separation of duties, PAM, JIT/JEA, phishing-resistant MFA and service account review.

Secret and key management: vault, rotation, scope, encryption at rest/in transit and usage log.

SAST, DAST, SCA, IaC/container scanning, SBOM, VEX, signing and provenance across the delivery chain.

Security telemetry: structured logs, timestamping, correlation, detection, ATT&CK coverage and retention.

Incident response aligned with CSF 2.0 / SP 800-61r3: preparation, detection, analysis, containment, eradication, recovery and lessons learned integrated into risk.

Remediation plan with owner, deadline, dependency, compensating control, accepted exception, evidence and re-audit.

Where this comes from
  • CISA · Known Exploited Vulnerabilities (cisa.gov)Public catalogue of exploited vulnerabilitiesaccessed 2026-08-01established
  • MITRE ATT&CK (attack.mitre.org)Public techniques and tacticsaccessed 2026-08-01established

The attack path prioritises remediation within the authorised scope; it replaces neither governance’s decision on residual exposure, nor a claim of qualification or accreditation, which fall under a separate scope and separate evidence. No test proves an absolute absence of vulnerability, and an asset, control or retest not furnished remains N.F., never an implicit success.

THE QUESTIONS THAT SET THE PRICE

What we will ask you before we start.

Four questions we ask on every file in this domain. Each comes from an incident someone paid for — us, or a client before us.

When was the dependency audit last run?

A vulnerability can sleep for months because nobody opened the tool that reveals it. We audit after every installation and before declaring a tool safe — and we never fix by forcing major versions, which break silently.

If nobody asks it — Seventeen vulnerabilities, including a remote code execution, discovered by chance.

What downloads and runs code nobody has read?

We scan every extension, every script, every automation for three dangers: download followed by execution, irreversible destruction, exfiltration. Every finding carries its proof line by line, and the check counts what it dismissed.

If nobody asks it — A capability installed in five minutes that reinstalls what was just removed.

Is deleting a folder the same as uninstalling?

No. As long as the declaration exists, the package manager reinstalls — in a loop. The declaration is removed before the folder, and the loop's signature is checked every night.

If nobody asks it — Twenty-two temporary copies in fifteen minutes, a disk full in an hour and forty minutes.

Is a guardrail that accuses wrongly worse than no guardrail?

Yes: a check that cries wolf ends up unread. We calibrate three statuses — failed, passed with reservations, passed — and we count false positives as defects of the check itself.

If nobody asks it — Three alerts a night, one of them real, and nobody left to read it.

CAPABILITY SCENARIO — NOT A CLIENT REFERENCE

When we get the call

A platform in production has never been audited and its permissions have piled up as people left. We assess the real exposure, test the access paths within a written perimeter, then rank the fixes by exploitable risk. A re-audit confirms what was actually closed.

Planning something in Cybersecurity & Audit?

Write to us. We respond with an assessment, not a brochure.

Write to us