Six Days from Ground Truth to Closed Findings
Sublato Periculo — the risk, removed. Most security assessments end where the real work begins: a PDF of findings handed to a team that lacks the time or specialization to act on it. Cloudskope SARTUS™ is engineered so that does not happen. Three days of assessment across four parallel workstreams — cloud environment, dark and deep web exposure, ransomware and configuration drift, and active compromise. Three days of done-for-you remediation. One consolidated risk register mapped to NIST SP 800-53 and the CIS Benchmarks. Fixed fee, defined scope, no hourly overrun.
As cited in
KrebsOnSecurity · Reuters · ZDNet · CRN · Security Boulevard
A Recent SARTUS Engagement
Nine active account compromises. Nine mailboxes in adversary hands. The client’s IT team didn’t know a single one was there.
A mid-market organization with a mature internal IT function engaged Cloudskope for SARTUS. The internal team believed the environment was in a defensible state.
How the attackers got in
The campaign ran on adversary-in-the-middle attacks — a man-in-the-middle technique in which the victim is emailed a link to a fake Microsoft sign-in page hosted by the attacker. When the user typed the password and completed the MFA challenge, the attacker’s proxy relayed both to the real Microsoft login in real time and captured the authenticated session token. The attacker never needed the password. The MFA had already been satisfied. The stolen session opened the mailbox as the user, from the attacker’s browser.
By the time SARTUS engaged, nine accounts had been compromised this way across several months. The longest confirmed dwell time was more than four months.
What SARTUS found inside the tenant
Several compromised mailboxes carried attacker-planted inbox rules that filtered payroll correspondence and specific external senders into hidden folders, marked them read, and stopped further rule processing. The user never saw the messages. One AiTM session pivoted geographically three times in a matter of hours — across three widely separated US states — and accessed multiple financial records including named vendor payment requests and invoice threads. Another intrusion registered a fraudulent Windows device into the client’s Azure AD, so subsequent attacker sign-ins would appear to originate from a compliant, managed endpoint and bypass device-based Conditional Access.
What it had already cost the client
Loss the client had not yet discovered
$150,000+
Wired to attacker-controlled bank accounts across multiple fraudulent transactions through vendor-payment redirections the client did not know had happened. A single wire alone was $57,600. The wires were not the discovery event. The compromise chain was still active. Other transfers were in the queue.
What SARTUS did about it — same day
Every intrusion was identified through forensic reconstruction of millions of M365 audit log events. Every finding was escalated to leadership within hours of discovery. Session tokens were revoked. The rogue Azure AD device was deregistered. Malicious inbox rules were removed. Compromised credentials were rotated to phishing-resistant methods. External password resets were forced across all nine accounts on the same day the compromise was confirmed. Cloud posture, identity configuration, and mail-flow controls were remediated inside the SARTUS remediation window. Structural findings — full endpoint baseline enforcement and credential-theft chain closure — landed in the register with a documented path and a separate quote.
Nine active breaches, in progress, found and remediated inside the same six-day engagement.
This is the gap the engagement was engineered to close. Assessment finds what is already there. Remediation removes what can be removed. Both inside a six-day, fixed-fee window — before the exposure that is already in the environment becomes the incident that reaches the boardroom, the underwriter, or the news cycle.
Names, tenant identifiers, device names, hostnames, dates, and any content that could identify the organization have been redacted or generalized. Report reference available under NDA.
Forensic Reconstruction
How a recent session hijack unfolded — reconstructed from millions of M365 audit log events.
For the CFO, GC, or board member reading this
In plain English.
The client’s cybersecurity team believed they had things under control. They did not. Nine of their employees were, unknowingly, sharing their email accounts with attackers — for weeks, and in some cases months. The attackers were reading emails, watching payment conversations, and getting ready to manipulate the systems that authorize wire transfers. Over $150,000 had already been sent to bank accounts controlled by the attackers. The client’s IT team had no idea any of this was happening.
SARTUS is engineered to find exactly this. It examines your Microsoft 365, your Azure Active Directory, your endpoints, and your dark web exposure — and it asks the questions your existing controls, your IT team, and your prior assessments have not been asking. It surfaces the compromises that are already there. Then it removes them.
You may already have an active breach in your environment. You would not know. SARTUS finds it before you become the story.
Ready to find out what’s in your environment?
Book a six-day SARTUS engagement.
Fixed fee from $10,000 · Capacity: 3 engagements per week
What SARTUS Is Built to Uncover
A serious engagement does more than list issues. It exposes where risk is compounding — and, in SARTUS, closes what can be closed inside the deployment window.
What This Engagement Covers
Six days, structured into two parts. Part 1 establishes ground truth across four parallel workstreams. Part 2 closes what can be closed and hands you a compliance-ready artifact for auditors, underwriters, and counterparties.
The Difference
Most assessments hand you a PDF. SARTUS closes what’s closable.
Three business days of engineer-led remediation across configuration, identity, policy, and administrative controls — under your change control, executed before you receive the report. The part every other vendor scopes as a separate engagement is included in the fixed fee.
Beyond SARTUS
A serious engagement should not end in a report that sits on a shelf. It should change what leadership can defend, what auditors can verify, and what buyers can price.
Ground Truth Established
Leadership has evidence, not belief. Every finding is timestamped, sourced, and defensible in front of a board or an underwriter.
Findings Actually Closed
Remediation is delivered, not just recommended. What can be closed in three days is closed. What cannot is documented with a real path forward.
Board-Defensible Artifact
The NIST 800-53 and CIS-mapped risk register survives a board meeting, a cyber-insurance renewal, and a diligence buyer’s technical reviewer.
Path Forward Priced
Structural work — new hardware, new licensing, network re-architecture — is quoted separately with real numbers, not “TBD.”
Frequently Asked Questions
Answers to the most common questions about SARTUS scope, process, boundaries, and what the deliverables actually enable.
Two things: fixed fee and built-in remediation. A cyber risk assessment ends in a report. SARTUS ends in closure — three days of assessment across four parallel workstreams, then three days of done-for-you fixes across every finding whose closure is achievable through configuration and policy correction. You end the week with fewer open issues than you started, not more.
No. SARTUS is an assessment and remediation engagement, not adversarial testing. We do not exploit systems or attempt to breach controls. Penetration testing — external, internal, web application, and social engineering — is available as a separate engagement.
We escalate to leadership immediately, ahead of and separate from any written report. Full incident response — containment, eradication, forensic investigation, litigation support, and breach-counsel coordination — is scoped as a separate engagement under written change order before that work proceeds. The compromise assessment inside SARTUS identifies whether adversary activity is present; it does not commit to full DFIR inside the six-day window.
They land in the consolidated risk register with a documented path and, where you request, a separate quote. SARTUS remediation covers what can be closed through configuration, policy, and administrative correction inside the deployment window. Findings requiring new hardware, software, licensing, third-party vendor involvement, or structural projects — network re-architecture, migration, new tooling — are scoped as follow-on work. Nothing is closed silently; nothing is left off the register.
No. SARTUS is a project. MDR and vCISO are ongoing programs. SARTUS fixes what’s broken today; MDR watches what happens tomorrow; vCISO governs both. Many organizations start with SARTUS to establish ground truth, then transition into MDR and vCISO oversight for continuous protection and executive-level advisory. The risk register becomes the working document for both.
SARTUS is priced as a fixed fee starting at $10,000, scoped to your environment’s complexity. That covers all four Part 1 workstreams, the three-day remediation deployment, and the full deliverable set including the NIST 800-53 and CIS Benchmark-mapped risk register and the executive readout. No hourly billing, no scope-driven surprises.
What Happens Next
Every SARTUS engagement is scoped to your environment, priorities, and the deliverables you need after remediation closes. The engagement is time-bound: three business days of assessment, three business days of remediation, executive readout on the following week.
A Simple Path From Ground Truth to Closed Findings
Kickoff
Scope confirmation, escalation contacts, and provisioning of least-privilege, read-only assessor access.
Assess
Three business days across four parallel workstreams. Any indicator of active compromise is escalated to leadership on discovery.
Remediate
Approved remediation queue executed in three business days under customer-approved change control.
Readout
Executive briefing with the consolidated risk register, residual-risk analysis, and recommended forward roadmap.
Assessment. Closure. Evidence. In six days.
If your organization has never formally answered where are we exposed, are we already compromised, and who is going to fix it — SARTUS answers all three in one engagement, in one week, at one fixed fee.
The Guarantee
If SARTUS does not identify at least one material exposure your current controls missed, the engagement is free.
Capacity: 3 SARTUS engagements per week · Contact us for current availability
.png)