Problem
Cybersecurity without inventory is a wish list. First: what exists, who has access, what is logged, what an analyst would actually see.
Scope
- Windows and Linux hardening in an agreed scope
- turning on and sorting logs before buying another “XDR”
- service exposure review (not a full pentest, not a certified audit)
- mapping what is visible to what can be escalated
Result
Controls that exist in configuration — and a list of what we deliberately did not cover.