BRACEWorks - Cloud & AI Security
Defense in Depth for Cloud Infrastructure
Our engagements start with an assessment that establishes a baseline of an organization's current cloud services and infrastructure architecture. Based on the underlying services a customer's applications actually use, we identify security gaps and translate them into a clear, prioritized implementation plan.
Establishing the baseline
The engagement begins with a Cloud Security Posture Assessment that inventories the services in use and examines security controls across containers, Kubernetes, virtual machines, networks, applications and APIs, data and identity protection, secure development practices, and vulnerability management.
Prioritizing by risk
Based on the risks identified, we present an improvement roadmap with the right priorities, higher risk first. The recommendations include practices and solutions tailored to the customer's environment, with the objective of reducing its attack surface and adopting solutions for quick identification when something goes wrong.
What defense in depth means here
The aim is to establish a defense-in-depth architecture, applying multiple layers of protection across the environment, consistent with NIST's definition of defense in depth. The recommendations address coding errors, vulnerable components, malicious code, and software supply chain attacks.
Why software supply chain security deserves special attention
Most modern software is not built from scratch. The Linux Foundation's Census II research estimates that open-source software accounts for 70% to 90% of a modern application stack. In practice, this means an organization's security also depends on external components and libraries it did not develop and may have limited control over.
Without a disciplined process to identify these components and check them against known vulnerabilities before adoption and throughout their use, an organization can unknowingly build or continue running applications on software that attackers already know how to exploit. Secure development practices and vulnerability management help identify this exposure and guide remediation. Protecting against malicious components or compromised software updates also requires checking where software comes from and how it is built and delivered.
The 2023 compromise of the MOVEit file transfer platform shows what this exposure looks like in practice. The Cl0p ransomware gang exploited a SQL injection vulnerability in MOVEit Transfer to deploy a web shell and steal data directly from customer databases, affecting organizations that had no direct relationship with the attacker and no way to know the vulnerability existed until it was disclosed. See the joint CISA and FBI advisory for the full technical breakdown. Software supply chain attacks like this one continue to make headlines, with new incidents documented through 2026.
Remediation: a Zero Trust architecture
The remediation phase proposes an architecture aligned with NIST's Zero Trust principles, using SP 800-207 and SP 800-207A for cloud-native applications across multicloud environments. The proposed architecture includes access controls based on user and workload identity, least-privilege access, increased traffic visibility, and encryption to protect connections and data in transit.
Application and API security
This phase also includes a review of application and API security practices. We recommend controls tailored to the customer's application, such as virtual patching and Web Application and API Protection (WAAP), to reduce exposure to vulnerabilities that can be exploited through web and API traffic while permanent fixes are developed and deployed. These controls provide an additional layer of protection, but their coverage must be evaluated for each vulnerability.
Continuous monitoring
Finally, the proposal includes continuous infrastructure monitoring, using tools like Cloud Security Posture Management (CSPM), vulnerability scanning and patch management, Software Composition Analysis (SCA) and dependency monitoring, and SIEM (Security Information and Event Management) to detect suspicious activity, including possible exploitation of vulnerabilities that have not yet been remediated. It also defines containment mechanisms to limit the impact of an incident.
This is the same progression we apply under the BRACE methodology's Baseline, Risk, and Cloud stages. See our Cloud Security Posture Assessment & Enhancement service for how this translates into an engagement.