Skip to content

Resources

Learn the landscape.

Practical guides on compliance frameworks and cloud security — written for busy teams, not auditors.

Guides

Compliance

SOC2 for startups: the honest timeline

What Type I vs Type II actually means, which controls auditors look at first, and how to get audit-ready in weeks instead of quarters.

Read the guide
Compliance

ISO 27001 in plain English

The Statement of Applicability, Annex A controls, and how to scope your ISMS without drowning your team in paperwork.

Read the guide
Compliance

HIPAA for cloud-native health tech

The Security Rule mapped to AWS, Azure, and GCP services — encryption, access control, audit logging, and BAAs.

Read the guide
Security

The SMB cloud attack surface, explained

Public buckets, over-permissive IAM, exposed management ports, and stale credentials — the four findings behind most SMB breaches.

Read the guide
Security

Reading a CVE like a security engineer

CVSS scores lie without context. How to judge exploitability in your environment and decide what actually needs patching this week.

Read the guide
Security

Your first 90-day security roadmap

A prioritized sequence: visibility first, identity second, exposure third, evidence always. A template leadership will approve.

Read the guide
Identity

MFA coverage: the one identity metric that matters

Why account takeover starts with the accounts you forgot, how to measure coverage across your identity provider, and the admin-without-MFA problem.

Read the guide
Security

Vulnerability management without a security team

You already own the scanners — Defender, Qualys, Rapid7. What to centralize, what to ignore, and how source-owned findings keep dashboards honest.

Read the guide
Security

Agents and agentless: why you want both

Connectors see your clouds and consoles; agents see the device itself — and a discovery agent sees the devices nobody enrolled. How the layers fit together.

Read the guide

Security Essentials, Weekly

A practical weekly briefing on real-world security misconfigurations, why they matter, and how to fix them. Each edition focuses on one actionable issue with clear context, practical remediation guidance, and a straightforward approach to improving security.

One email a week, unsubscribe any time. We use your address only to send the briefing — see our Privacy Policy.

FAQ

Do I have to install agents?
Cloud, identity, and security-platform connections are agentless — read-only APIs, nothing installed. Cybermatic also ships three agents of its own, included on every plan: a signed Device Agent for Windows, macOS, and Linux, the Device Trust app for phones and tablets, and a Discovery Agent that finds unmanaged devices on each network segment. All are report-only and individually revocable — deploy them where you want first-party depth.
Which clouds are supported?
AWS, Microsoft Azure, Google Cloud, and popular SaaS platforms. AWS onboarding uses a one-click CloudFormation template.
Is my data used to train AI models?
No. Your environment data is used only to analyze your posture and generate your documents and answers.
Can Cybermatic change things in my cloud?
No. Access is read-only. Remediation code is generated for your team to review and apply — you keep change control.