Subtitle Icon
Assessment & Remediation

Six Days from Ground Truth to Closed Findings

Sublato Periculo — the risk, removed. Most security assessments end where the real work begins: a PDF of findings handed to a team that lacks the time or specialization to act on it. Cloudskope SARTUS™ is engineered so that does not happen. Three days of assessment across four parallel workstreams — cloud environment, dark and deep web exposure, ransomware and configuration drift, and active compromise. Three days of done-for-you remediation. One consolidated risk register mapped to NIST SP 800-53 and the CIS Benchmarks. Fixed fee, defined scope, no hourly overrun.

Fintech Solution Meta Icon
Fixed Fee from $10,000
Fintech Solution Meta Icon
NIST · CIS · CMMC · PCI Mapped
Fintech Solution Meta Icon
Done-For-You Remediation
Fintech Hero Icon
40+
Findings Per Engagement
Fintech Hero Icon
60-75%
Closed In Window
Fintech Hero Icon
8
Compliance Frameworks Mapped

As cited in

KrebsOnSecurity · Reuters · ZDNet · CRN · Security Boulevard

A Recent SARTUS Engagement

CLOUDSKOPECONSOLIDATED RISK REGISTERCS-SRT-[REDACTED]FINDINGSConsolidatedRisk RegisterMapped to NIST 800-53, CIS Benchmarks, CMMC, and PCI-DSS.Every finding by section, with framework mapping, remediation status, and executive readout.PREPARED FOR [CLIENT REDACTED] · BY CLOUDSKOPEcloudskope.com

Nine active account compromises. Nine mailboxes in adversary hands. The client’s IT team didn’t know a single one was there.

A mid-market organization with a mature internal IT function engaged Cloudskope for SARTUS. The internal team believed the environment was in a defensible state.

How the attackers got in

The campaign ran on adversary-in-the-middle attacks — a man-in-the-middle technique in which the victim is emailed a link to a fake Microsoft sign-in page hosted by the attacker. When the user typed the password and completed the MFA challenge, the attacker’s proxy relayed both to the real Microsoft login in real time and captured the authenticated session token. The attacker never needed the password. The MFA had already been satisfied. The stolen session opened the mailbox as the user, from the attacker’s browser.

By the time SARTUS engaged, nine accounts had been compromised this way across several months. The longest confirmed dwell time was more than four months.

What SARTUS found inside the tenant

Several compromised mailboxes carried attacker-planted inbox rules that filtered payroll correspondence and specific external senders into hidden folders, marked them read, and stopped further rule processing. The user never saw the messages. One AiTM session pivoted geographically three times in a matter of hours — across three widely separated US states — and accessed multiple financial records including named vendor payment requests and invoice threads. Another intrusion registered a fraudulent Windows device into the client’s Azure AD, so subsequent attacker sign-ins would appear to originate from a compliant, managed endpoint and bypass device-based Conditional Access.

What it had already cost the client

Loss the client had not yet discovered

$150,000+

Wired to attacker-controlled bank accounts across multiple fraudulent transactions through vendor-payment redirections the client did not know had happened. A single wire alone was $57,600. The wires were not the discovery event. The compromise chain was still active. Other transfers were in the queue.

What SARTUS did about it — same day

Every intrusion was identified through forensic reconstruction of millions of M365 audit log events. Every finding was escalated to leadership within hours of discovery. Session tokens were revoked. The rogue Azure AD device was deregistered. Malicious inbox rules were removed. Compromised credentials were rotated to phishing-resistant methods. External password resets were forced across all nine accounts on the same day the compromise was confirmed. Cloud posture, identity configuration, and mail-flow controls were remediated inside the SARTUS remediation window. Structural findings — full endpoint baseline enforcement and credential-theft chain closure — landed in the register with a documented path and a separate quote.

Nine active breaches, in progress, found and remediated inside the same six-day engagement.

This is the gap the engagement was engineered to close. Assessment finds what is already there. Remediation removes what can be removed. Both inside a six-day, fixed-fee window — before the exposure that is already in the environment becomes the incident that reaches the boardroom, the underwriter, or the news cycle.

Names, tenant identifiers, device names, hostnames, dates, and any content that could identify the organization have been redacted or generalized. Report reference available under NDA.

Forensic Reconstruction

How a recent session hijack unfolded — reconstructed from millions of M365 audit log events.

CLOUDSKOPEATTACK TIMELINE RECONSTRUCTIONCS-SRT-ATL-[REDACTED]SESSION HIJACK · RECONSTRUCTIONAdversary-in-the-MiddleSession HijackTarget: [REDACTED] · finance-authorizing role · MFA enrolledT+0Fake Microsoft login page intercepts MFAOrigin: [REDACTED] · attacker proxy relays credentials in real timeT+1mSESSION TOKEN CAPTUREDAttacker inside mailbox as user · MFA already satisfied · no further auth[Impossible travel window · multiple time zones in hours]No behavioral control fired · no session revocationT+4hGeographic pivot → [REDACTED]Session continues from new origin · same authenticated tokenT+4hSecond pivot → [REDACTED]Multiple financial records accessed · vendor payment threads openedIMPACT · WIRE AUTHORIZED$57,600Wired to attacker-controlled bank accountVendor payment redirected · client had no visibilityAdditional transfers were in the queue when SARTUS intervenedANONYMIZED FORENSIC RECONSTRUCTION · CLOUDSKOPEcloudskope.com

For the CFO, GC, or board member reading this

In plain English.

The client’s cybersecurity team believed they had things under control. They did not. Nine of their employees were, unknowingly, sharing their email accounts with attackers — for weeks, and in some cases months. The attackers were reading emails, watching payment conversations, and getting ready to manipulate the systems that authorize wire transfers. Over $150,000 had already been sent to bank accounts controlled by the attackers. The client’s IT team had no idea any of this was happening.

SARTUS is engineered to find exactly this. It examines your Microsoft 365, your Azure Active Directory, your endpoints, and your dark web exposure — and it asks the questions your existing controls, your IT team, and your prior assessments have not been asking. It surfaces the compromises that are already there. Then it removes them.

You may already have an active breach in your environment. You would not know. SARTUS finds it before you become the story.

Ready to find out what’s in your environment?

Book a six-day SARTUS engagement.

Fixed fee from $10,000 · Capacity: 3 engagements per week

CLOUDSKOPEREPRESENTATIVE FINDING MATRIXCS-SRT-MTX-[REDACTED]CONTROL DOMAIN STATUS · POST-ASSESSMENTWhat every SARTUS engagement producesIAMDATCRDCFGVLNEPPDETDNSEXTFAILPARTIALPRESENTEvery finding mapped to NIST 800-53 · CIS Benchmarks · CMMC · PCI-DSSANONYMIZED FROM ACTUAL ENGAGEMENT DELIVERABLE · CLOUDSKOPEcloudskope.com

What SARTUS Is Built to Uncover

A serious engagement does more than list issues. It exposes where risk is compounding — and, in SARTUS, closes what can be closed inside the deployment window.

Enterprise Hero Icon
CRITICAL

Cloud Configuration Drift Across M365 and Azure

Challenges Highlight  Icon
IBM reports that 80% of cloud breaches trace back to basic misconfiguration.
Enterprise Hero Icon

We assess identities, policies, permissions, and configurations across your productivity and identity fabric — benchmarked against the applicable CIS Benchmarks and mapped to NIST SP 800-53 control families.

Enterprise Hero Icon
CRITICAL

Credentials Already Leaked

Challenges Highlight  Icon
Stolen credentials appear in a majority of confirmed breach paths in the Verizon DBIR.
Enterprise Hero Icon

We enumerate your domain, executive identities, and credential material across breach corpuses, combolists, and stealer-log markets — separating stale exposure from live, actionable risk.

Enterprise Hero Icon
CRITICAL

Active Compromise You Haven’t Detected

Challenges Highlight  Icon
Median attacker dwell time is measured in days; discovery is often measured in months (Mandiant M-Trends).
Enterprise Hero Icon

We examine sign-in telemetry, mailbox rules, OAuth grants, persistence mechanisms, and anomalous administrative activity for indicators an adversary is already inside — and escalate immediately to leadership if we find one.

Enterprise Hero Icon
High

Findings That Never Get Closed

Challenges Highlight  Icon
Cloudskope engagement history: the majority of third-party assessment findings remain open beyond ninety days without a closure engagement.
Enterprise Hero Icon

SARTUS measures not just what is exposed, but what is closable. What we can close in three days, we close. What we cannot, we document with a real path forward — never with silence.

What This Engagement Covers

Six days, structured into two parts. Part 1 establishes ground truth across four parallel workstreams. Part 2 closes what can be closed and hands you a compliance-ready artifact for auditors, underwriters, and counterparties.

Services Icon

Cloud Environment Security Assessment & Audit

Identity, email, data, workloads, and logging across Microsoft 365 and Azure.

what we assess

Privileged account inventory, MFA enforcement, legacy authentication exposure, conditional access posture, external sharing controls, mail-flow rules, cloud subscription and tenant structure, network exposure of cloud-hosted services, and audit-log configuration.

why it matters

The productivity and identity fabric is the single most common material-breach entry point for mid-market organizations. Every confirmed breach in recent memory started with an identity that should not have been reachable, an account that should not have had MFA turned off, or an audit log that should not have been rotated at seven days.

typical outputs
Service Feature Icon

MFA & Conditional Access Posture

Service Feature Icon

Email Defense Configuration

Service Feature Icon

External Sharing & Anonymous Link Governance

Service Feature Icon

Workload & Tenant Exposure Map

Service Feature Icon

Audit-Log Coverage & Retention Review

Services Icon

Dark & Deep Web Exposure Analysis

Your organization’s digital footprint outside its perimeter, from breach corpuses to stealer-log markets.

what we assess

Credentials, brand references, executive identities, and infrastructure exposed on the dark web, deep web, forums, marketplaces, and stealer-log markets.

why it matters

Adversaries purchase or scrape exposure long before they touch your environment. An organization’s real attack surface includes what has already leaked, not just what it operates. Senior-analyst triage separates stale, low-risk exposure from live, actionable risk.

typical outputs
Service Feature Icon

Credential & Stealer-Log Exposure

Service Feature Icon

Brand & Executive Identity Monitoring

Service Feature Icon

Infrastructure & Document Leakage

Service Feature Icon

Analyst Triage & Remediation-Queue Feed

Services Icon

Internal IT Ransomware & Configuration Drift Assessment

The internal-estate conditions that determine whether ransomware is an inconvenience or an existential event.

what we assess

Endpoint protection coverage across servers and workstations, operating-system and third-party patch posture on ransomware-favored vulnerability classes, internal privileged access hygiene, service-account sprawl, domain administrator exposure, and configuration drift measured against the applicable CIS baseline.

why it matters

Ransomware success is decided by conditions inside the environment long before an attacker arrives. The gap between a contained event and an existential one is measured not in the attacker’s sophistication but in the defender’s baseline hygiene.

typical outputs
Service Feature Icon

Endpoint Protection Coverage & Gaps

Service Feature Icon

Patch Posture on KEV-Listed Vulnerabilities

Service Feature Icon

Privileged Access & Service-Account Hygiene

Service Feature Icon

CIS Baseline Drift Measurement

Service Feature Icon

Incident Response Readiness

Services Icon

Active Compromise Assessment

Sign-in telemetry, OAuth grants, and persistence mechanisms — searching for indicators someone is already inside.

what we assess

Sign-in telemetry, mailbox rules, OAuth grants, persistence mechanisms, and anomalous administrative activity across the cloud and internal environments — searching for indicators of active or historical compromise.

why it matters

The most important question this engagement answers is also the one most executive teams have never formally asked with evidence: is someone already inside? Where indicators surface, we triage to distinguish benign misconfiguration from adversary activity, and where compromise is identified, we help identify root cause. Immediate escalation to leadership happens ahead of and separate from any written report.

typical outputs
Service Feature Icon

Indicator Review Across Cloud and Internal Estate

Service Feature Icon

Benign-vs-Adversary Triage

Service Feature Icon

Root-Cause Identification

Service Feature Icon

Immediate Leadership Escalation Protocol

Service Feature Icon

Scope Mapping for Follow-On Response

Services Icon

SARTUS™ Remediation Deployment — Done-For-You

Done-for-you closure of Part 1 findings — configuration, policy, and administrative correction under change control.

what we assess

The Part 1 findings — which are closable through configuration, policy, and administrative correction inside the three-day deployment window, and which require structural work that will be scoped separately.

why it matters

Most assessments end where the real work begins. SARTUS is engineered so it does not. Cloudskope engineers execute the approved remediation queue under customer-approved change control. High-risk changes are scheduled in customer maintenance windows. Every change is logged and reversible wherever technically feasible.

typical outputs
Service Feature Icon

Configuration Hardening & Policy Enforcement

Service Feature Icon

Identity & Access Corrections

Service Feature Icon

Exposure Closure (Cloud, Identity, Endpoint)

Service Feature Icon

Before-and-After Evidence Per Finding

Service Feature Icon

Reversibility Record & Change Log

Services Icon

Consolidated Risk Register & Executive Readout

Every finding mapped to NIST 800-53 and CIS Benchmarks as the universal baseline — with CMMC, PCI-DSS, SCuBA, MCSB, NIST 800-171, and NSA overlays applied where your regulatory footprint requires.

WHAT WE ASSESS

Every finding — open and closed — outlined, prioritized, and mapped to control frameworks. NIST SP 800-53 and CIS Benchmarks anchor every register as the universal baseline. Additional crosswalks — NIST SP 800-171, CMMC, PCI-DSS, CISA SCuBA, MCSB, and NSA — are layered in based on your regulatory footprint. Residual risk, insurability posture, and a recommended forward roadmap translated from technical record into business terms.

WHY IT MATTERS

A compliance-ready artifact for auditors, underwriters, and counterparties. The register survives a board meeting, a cyber-insurance renewal, and a diligence buyer’s technical reviewer — because it names what was closed, what remains, and what it will take to close the rest.

typical outputs
Service Feature Icon

Full Prioritized Risk Register

Service Feature Icon

NIST 800-53 & CIS Baseline; CMMC, PCI, SCuBA, MCSB, 800-171, NSA Overlays

Service Feature Icon

Residual-Risk Analysis

Service Feature Icon

Insurability Posture Review

Service Feature Icon

Recommended Forward Roadmap

The Difference

Most assessments hand you a PDF. SARTUS closes what’s closable.

Three business days of engineer-led remediation across configuration, identity, policy, and administrative controls — under your change control, executed before you receive the report. The part every other vendor scopes as a separate engagement is included in the fixed fee.

Beyond SARTUS

A serious engagement should not end in a report that sits on a shelf. It should change what leadership can defend, what auditors can verify, and what buyers can price.

Enterprise Hero Icon

Ground Truth Established

Leadership has evidence, not belief. Every finding is timestamped, sourced, and defensible in front of a board or an underwriter.

Evidence Over Belief

Timestamped and Sourced
Enterprise Hero Icon

Findings Actually Closed

Remediation is delivered, not just recommended. What can be closed in three days is closed. What cannot is documented with a real path forward.

Closure Delivered

Not Just Recommended
Enterprise Hero Icon

Board-Defensible Artifact

The NIST 800-53 and CIS-mapped risk register survives a board meeting, a cyber-insurance renewal, and a diligence buyer’s technical reviewer.

Register That Holds Up

Auditors, Underwriters, Buyers
Enterprise Hero Icon

Path Forward Priced

Structural work — new hardware, new licensing, network re-architecture — is quoted separately with real numbers, not “TBD.”

Real Numbers

Not TBD
Subtitle Icon
FAQ

Frequently Asked Questions

Answers to the most common questions about SARTUS scope, process, boundaries, and what the deliverables actually enable.

1
What makes SARTUS different from a standard cyber risk assessment?
2
Is this a penetration test?
3
What happens if you find an active compromise during the assessment?
4
What happens to findings that can’t be closed inside six days?
5
Is SARTUS a replacement for MDR or vCISO?
6
How much does SARTUS cost, and what does it include?
Subtitle Icon
Ready to Chat?

What Happens Next

Every SARTUS engagement is scoped to your environment, priorities, and the deliverables you need after remediation closes. The engagement is time-bound: three business days of assessment, three business days of remediation, executive readout on the following week.

A Simple Path From Ground Truth to Closed Findings

Enterprise Hero Icon

Kickoff

Scope confirmation, escalation contacts, and provisioning of least-privilege, read-only assessor access.

Access Provisioned
Enterprise Hero Icon

Assess

Three business days across four parallel workstreams. Any indicator of active compromise is escalated to leadership on discovery.

4 Parallel Workstreams
Enterprise Hero Icon

Remediate

Approved remediation queue executed in three business days under customer-approved change control.

Done-For-You Closure
Enterprise Hero Icon

Readout

Executive briefing with the consolidated risk register, residual-risk analysis, and recommended forward roadmap.

NIST + CIS Mapped

Assessment. Closure. Evidence. In six days.

If your organization has never formally answered where are we exposed, are we already compromised, and who is going to fix it — SARTUS answers all three in one engagement, in one week, at one fixed fee.

The Guarantee

If SARTUS does not identify at least one material exposure your current controls missed, the engagement is free.

Capacity: 3 SARTUS engagements per week · Contact us for current availability