[{"data":1,"prerenderedAt":130},["ShallowReactive",2],{"case-en-cyber-audit":3},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"summary":10,"slug":11,"code":12,"label":13,"tags":14,"challenge":18,"approach":19,"outcome":20,"seo":21,"body":24,"_type":123,"_id":124,"_source":125,"_file":126,"_stem":127,"_extension":128,"sitemap":129},"\u002Fen\u002Fportfolio\u002Fcyber-audit","portfolio",false,"","Security review and hardening","This is a method note: it describes how we approach this kind of problem, not a write-up of a named client.","How we approach it when a company isn't sure where it's exposed — and wants real safety, not just a report.","cyber-audit","M-02","Security",[15,16,17],"Cybersecurity","Review","Compliance","A company handles sensitive data but isn't sure where it's exposed. A checklist audit produces a PDF, not safety.","We map what is actually reachable from the outside, threat-model from the attacker's point of view, fix the few things that matter most, and leave the team able to keep it safe on its own.","Done right, there are fewer ways in, the team understands its own attack surface, and the fixes hold up after we're gone.",{"title":22,"description":23},"Security review and hardening — method note | Ag3","How Ag3 approaches a security review: what's reachable, threat modelling, fixes that hold — instead of a PDF report.",{"type":25,"children":26,"toc":117},"root",[27,34,41,54,60,106,112],{"type":28,"tag":29,"props":30,"children":31},"element","p",{},[32],{"type":33,"value":9},"text",{"type":28,"tag":35,"props":36,"children":38},"h2",{"id":37},"a-report-is-not-safety",[39],{"type":33,"value":40},"A report is not safety",{"type":28,"tag":29,"props":42,"children":43},{},[44,46,52],{"type":33,"value":45},"A checklist tells you what ",{"type":28,"tag":47,"props":48,"children":49},"em",{},[50],{"type":33,"value":51},"should",{"type":33,"value":53}," be in place. It doesn't tell you the path someone would actually take to your data. So we start with a map, not a list.",{"type":28,"tag":35,"props":55,"children":57},{"id":56},"how-we-approach-it",[58],{"type":33,"value":59},"How we approach it",{"type":28,"tag":61,"props":62,"children":63},"ul",{},[64,76,86,96],{"type":28,"tag":65,"props":66,"children":67},"li",{},[68,74],{"type":28,"tag":69,"props":70,"children":71},"strong",{},[72],{"type":33,"value":73},"What's reachable.",{"type":33,"value":75}," We inventory what is genuinely visible and reachable from the internet — often more than the team assumes.",{"type":28,"tag":65,"props":77,"children":78},{},[79,84],{"type":28,"tag":69,"props":80,"children":81},{},[82],{"type":33,"value":83},"From the attacker's side.",{"type":33,"value":85}," We threat-model a few plausible attacks end to end, instead of scoring individual controls in isolation.",{"type":28,"tag":65,"props":87,"children":88},{},[89,94],{"type":28,"tag":69,"props":90,"children":91},{},[92],{"type":33,"value":93},"The few things first.",{"type":33,"value":95}," We fix the paths that matter most before working through the long tail of minor findings.",{"type":28,"tag":65,"props":97,"children":98},{},[99,104],{"type":28,"tag":69,"props":100,"children":101},{},[102],{"type":33,"value":103},"Built to hold.",{"type":33,"value":105}," We equip the team to spot new risk itself — security is a process, not a one-off event.",{"type":28,"tag":35,"props":107,"children":109},{"id":108},"what-changes",[110],{"type":33,"value":111},"What changes",{"type":28,"tag":29,"props":113,"children":114},{},[115],{"type":33,"value":116},"The attack surface shrinks to what's genuinely needed. The team sees its system the way an attacker does for the first time, and knows what to protect and why. When the system next changes, they can judge whether that change is safe.",{"title":7,"searchDepth":118,"depth":118,"links":119},2,[120,121,122],{"id":37,"depth":118,"text":40},{"id":56,"depth":118,"text":59},{"id":108,"depth":118,"text":111},"markdown","content:en:portfolio:cyber-audit.md","content","en\u002Fportfolio\u002Fcyber-audit.md","en\u002Fportfolio\u002Fcyber-audit","md",{"loc":4},1784880623031]