EssentialAutomated on platform
Web Security Audit
OWASP ZAP and nmap assessment of exposed web apps and assets.
Spider + active scan with QA policy
OWASP Top 10 and CWE mapping
HTML/PDF deliverable report
Scope bounded by authorization
EssentialAutomated on platform
Vulnerability Analysis
Discovery, CVSS prioritization, and finding tracking in the SOC.
Authorized remote scanning
Findings explorer with filters
AI recommendations (Bedrock)
CSV / JSON / PDF export
EssentialAutomated on platform
Attack Surface Assessment
Map what is exposed on the internet before an attacker does.
Dedicated attack-surface report
Authorized vs discovered comparison
Unusual port detection
Reduction recommendations
EssentialAutomated on platform
Technical Vulnerability Reports
Detailed findings for IT: evidence, CVSS, and remediation steps.
OWASP and nmap templates
Evidence and host tables
PDF export via Lambda
ES / EN language
EssentialAutomated on platform
Executive Reports for Leadership
Board-ready summaries of risk, impact, and recommended next steps.
Narrative generated with Bedrock Haiku
Top 3 business risks
Severity bars and traffic light
Confidential format ready for the board
EssentialHuman consulting
Remediation and Improvement Plans
Prioritized action plans by business impact, not just severity.
Prioritization by CVSS and business
AI recommendations per finding
Exportable for tracking
Aligned to CIS/OWASP controls
EssentialAutomated on platform
Phishing Simulations
Controlled email campaigns to measure who clicks and who reports.
Templates and landing pages
Engagement funnel
Auto-enroll into training
Metrics by department
EssentialAutomated on platform
Ransomware Simulations
Tabletop and technical exercises for containment and recovery.
Ransomware campaign type
Human-response measurement
Human-risk integration
Results report
EssentialPlatform + consulting
Short Training Modules
Bite-size lessons your team can finish without stopping work.
Lightweight modules in cwAWARE
Quizzes and certificates
Downloadable documents
Ideal for reinforcement campaigns
EssentialPlatform + consulting
Security Procedure Design
Written procedures your team can follow during incidents.
S3 library + SEO
Versioning and controlled download
Reusable templates
Distribution to employees
EssentialPlatform + consulting
Security Policy Design
Policies aligned to how your organization actually works.
Policy templates
Published in Academy docs
Framework alignment
Role-based access
EssentialPlatform + consulting
End-user Security Guides
Clear guides for employees: passwords, email, remote work.
SEO slugs and sitemap
Clear, actionable format
PDF/DOC download
Fits onboarding
EssentialPlatform + consulting
Awareness Metrics and Tracking
Who completed training, who failed simulations, who has not started.
Human Risk Score
Trends by department
Phishing + training correlation
Internal benchmarks
EssentialAutomated on platform
Dark Web / OSINT Analysis
Look for leaked credentials, mentions, and exposed company data.
OSINT connector kind
external_security_events intake
HIBP / Dehashed / Flare compatible
Review and triage in the panel
AdvancedAutomated on platform
Smishing Simulations
SMS-based social engineering tests against your workforce.
160-character SMS body
Send via Twilio
Tracked links (optional Bitly)
Unified funnel in the SOC
AdvancedAutomated on platform
Vishing Simulations
Voice-based social engineering exercises for high-risk roles.
Script and scenario objective
Planned state without auto-send
Results per recipient
Metrics in PhishFunnel
AdvancedAutomated on platform
Social Engineering Simulations
Broader human-risk scenarios beyond email and SMS.
Evidence logging
Campaign linkage
Lessons-learned report
Coordination with awareness
AdvancedPlatform + consulting
Custom Awareness Campaigns
Campaigns tailored to your industry, language, and risk profile.
Audience segmentation
Custom content
Send calendar
Agreed KPIs
AdvancedPlatform + consulting
Awareness Platform Rollout
Deploy and operate awareness platforms for your organization.
Connectors to leading platforms
Metrics sync
Unified view in Cyberware
Onboarding support
AdvancedPlatform + consulting
End-to-end Campaign Management
We run the full awareness cycle: design, send, measure, improve.
Unified dashboard
Annual calendar
Reporting to leadership
Data-driven continuous improvement
AdvancedPlatform + consulting
Training Content Development
Custom modules, videos, and quizzes for your threat landscape.
Instructional design
Upload to cwAWARE
Quizzes and certificates
ES / EN localization
AdvancedAutomated on platform
Periodic Security Audits
Recurring authorized scans so findings do not go stale.
scan_schedules table
ConnectorPoll cron
Prior authorization required
Comparable history
AdvancedAutomated on platform
Preventive Security Review
A scheduled checkup of controls before an incident forces one.
Downloadable checklist
Bounded scan
Gap report
Prioritized recommendations
AdvancedHuman consulting
Technical Project Support
Security accompaniment for migrations, launches, and new systems.
Milestone tracking
Checkpoint reviews
Progress reports
Coordination with the SOC
With partnerCertified partnerHuman consulting
Email Configuration Audit
SPF, DKIM, DMARC, and mailbox security review.
Email authentication analysis
Tenant hardening
Findings report
Certified partner in scope
With partnerCertified partnerHuman consulting
Infrastructure and Network Audit
Authorized review of hosts, services, and network exposure.
On-prem / hybrid scope
Judgment on critical findings
Technical + executive report
Certified expert supervision
With partnerCertified partnerHuman consulting
Firewall Configuration Review
Rule hygiene, unused openings, and least-privilege checks.
Rulebase review
Overly permissive rule detection
Hardening plan
Executed with a certified partner
With partnerCertified partnerHuman consulting
Microsoft 365 Audit
Identity, sharing, and tenant hardening for Microsoft 365.
CIS / Microsoft baseline
Identity and access
M365 maturity report
Partner with M365 expertise
With partnerCertified partnerHuman consulting
Active Directory Audit
Privileged accounts, GPOs, and common AD attack paths.
Tier-0 / privileges
Critical misconfig detection
Hardening roadmap
CRTE/CRTP specialists
With partnerCertified partnerHuman consulting
Backup Audit
Verify backups exist, restore, and would survive ransomware.
Backup policy review
Controlled restore tests
Resilience report
Coordination with operations
With partnerCertified partnerHuman consulting
Security Tooling Review
Are the tools you already pay for actually covering the risk?
Coverage and configuration review
Detection gaps
Recommendations by vendor
Multi-vendor partner
With partnerCertified partnerHuman consulting
Cybersecurity Maturity Assessment
A practical maturity snapshot for leadership and IT.
Agreed framework
Stakeholder workshops
Executive scorecard
Prioritized improvement plan
With partnerCertified partnerHuman consulting
Cybersecurity Consulting
Human advisory for decisions that a scanner cannot make.
Custom scope
CISO-as-a-service advisory
Progress reports
Certified partner by domain
With partnerCertified partnerHuman consulting
Data Protection Advisory
Practical guidance on personal data handling and exposure.
Technical gap analysis
Privacy controls
Evidence documentation
Coordination with DPO/counsel
With partnerCertified partnerHuman consulting
Awareness Program Design
A year-long plan: topics, cadence, metrics, and ownership.
Initial diagnosis
Calendar and channels
KPIs and governance
Execution with the SOC
With partnerCertified partnerHuman consulting
Cybersecurity Training for Companies
Team training that connects to labs, rooms, and certificates.
Custom syllabi
Live sessions
Materials and assessment
Attendance certificates
With partnerCertified partnerHuman consulting
Secure Onboarding Training
Day-one security habits for new hires.
Academy path
First-month checklist
Completion metrics
In-person option with partner