Resources
Learn the landscape.
Practical guides on compliance frameworks and cloud security — written for busy teams, not auditors.
Guides
SOC2 for startups: the honest timeline
What Type I vs Type II actually means, which controls auditors look at first, and how to get audit-ready in weeks instead of quarters.
Read the guide ComplianceISO 27001 in plain English
The Statement of Applicability, Annex A controls, and how to scope your ISMS without drowning your team in paperwork.
Read the guide ComplianceHIPAA for cloud-native health tech
The Security Rule mapped to AWS, Azure, and GCP services — encryption, access control, audit logging, and BAAs.
Read the guide SecurityThe SMB cloud attack surface, explained
Public buckets, over-permissive IAM, exposed management ports, and stale credentials — the four findings behind most SMB breaches.
Read the guide SecurityReading a CVE like a security engineer
CVSS scores lie without context. How to judge exploitability in your environment and decide what actually needs patching this week.
Read the guide SecurityYour first 90-day security roadmap
A prioritized sequence: visibility first, identity second, exposure third, evidence always. A template leadership will approve.
Read the guide IdentityMFA coverage: the one identity metric that matters
Why account takeover starts with the accounts you forgot, how to measure coverage across your identity provider, and the admin-without-MFA problem.
Read the guide SecurityVulnerability management without a security team
You already own the scanners — Defender, Qualys, Rapid7. What to centralize, what to ignore, and how source-owned findings keep dashboards honest.
Read the guide SecurityAgents and agentless: why you want both
Connectors see your clouds and consoles; agents see the device itself — and a discovery agent sees the devices nobody enrolled. How the layers fit together.
Read the guideSecurity Essentials, Weekly
A practical weekly briefing on real-world security misconfigurations, why they matter, and how to fix them. Each edition focuses on one actionable issue with clear context, practical remediation guidance, and a straightforward approach to improving security.
FAQ
- Do I have to install agents?
- Cloud, identity, and security-platform connections are agentless — read-only APIs, nothing installed. Cybermatic also ships three agents of its own, included on every plan: a signed Device Agent for Windows, macOS, and Linux, the Device Trust app for phones and tablets, and a Discovery Agent that finds unmanaged devices on each network segment. All are report-only and individually revocable — deploy them where you want first-party depth.
- Which clouds are supported?
- AWS, Microsoft Azure, Google Cloud, and popular SaaS platforms. AWS onboarding uses a one-click CloudFormation template.
- Is my data used to train AI models?
- No. Your environment data is used only to analyze your posture and generate your documents and answers.
- Can Cybermatic change things in my cloud?
- No. Access is read-only. Remediation code is generated for your team to review and apply — you keep change control.