Security posture kits — what a compromised account, token or workflow can actually reach
One question, asked per platform: if one account, one token or one workflow were compromised right now, what could it reach, and would you know? Nine kits share five modules and one blast-radius scale — Microsoft 365, Google Workspace, Okta, Salesforce, GitHub and GitLab, AI-built app stacks, Android, iOS, and Docker with Kubernetes — so a mixed estate is assessed with one method and a board gets comparable numbers. Each kit weights its own platform’s blind spot highest: the licence tier that gates what you can see, the OAuth token that needs no login, the guest user with no password, the workflow that runs untrusted code with trusted permissions, the pod token that pivots to the cloud account. Scores are a prioritisation aid, not a certification.
What practitioners need to know
Lifted verbatim from the kits below, each attributed to the product that says it.
-
Licence-tier-aware blast-radius scoring. Advanced Audit, risk policies, PIM, auto-labelling and single-pane correlation are each gated behind E5, Entra ID P2 or a Purview add-on — so the same settings score differently on E3 and E5. Confirming the tier is step one, and the tool changes its arithmetic when you do.
— M365 Security Posture Kit -
One compromised standard-user account, thirteen control questions across five surfaces — mailbox, file & collaboration, app consent, identity, detection — resolving to a single score, a band, and a closure list ranked by risk-weighted points.
— M365 Security Posture Kit -
Conditional Access, Entra ID Protection and PIM in one identity review instead of three disconnected checklists: 19 weighted controls rolling into one posture score.
— M365 Security Posture Kit -
A CIS Microsoft 365 Foundations Benchmark-aligned hardening baseline scored gap-to-target rather than pass/fail, so partial progress shows.
— M365 Security Posture Kit -
The commonest data-governance gap, named: DLP live on Exchange and never extended to Teams, which now carries the same sensitive content without the same guardrails.
— M365 Security Posture Kit -
A granted OAuth token needs no fresh login to be used. Login-audit review — the first place most admins look — is structurally blind to it. An attacker whose token was authorised weeks ago never signs in again.
— Google Workspace Security Posture Kit -
Shared-drive membership propagation is a false-positive trap in both directions. Reviewed carelessly it reads as bulk external sharing; reviewed too casually, real exposure is waved through as "just a shared drive thing".
— Google Workspace Security Posture Kit -
Business Plus has Vault but no DLP and no Context-Aware Access. Assuming retention implies data-loss protection is the commonest finding on a mid-market tenant, and the edition tab is step one for that reason.
— Google Workspace Security Posture Kit -
Workspace has no Defender XDR equivalent: the Security Investigation Tool queries six sources and merges none of them. File 06 says so as a platform ceiling rather than hiding it in a score.
— Google Workspace Security Posture Kit -
Same five modules and the same scoring bands as the M365 kit, so a vCISO on a mixed-tenant client uses one mental model twice.
— Google Workspace Security Posture Kit
Kits that cover it
13 products, cheapest first.
M365 Security Posture Kit
Assess what a compromised Microsoft 365 account can actually reach, and close the gaps, before an insurer or auditor asks. Licence-tier-aware blast-radius scoring, a CIS-aligned hardening baseline, and one identity review covering Conditional Access, Entra ID Protection and PIM.
Google Workspace Security Posture Kit
Assess what a compromised Google Workspace account can actually reach, scored against your edition, and close the gaps before an insurer or auditor asks. The Workspace counterpart to the M365 kit, built around the two blind spots a login audit cannot see: a granted OAuth token, and shared-drive sharing that looks like a leak.
Okta / Identity Provider Security Posture Kit
What a compromised Okta account or a leaked API token can reach — not one suite's mailbox and files, but every downstream application Okta fronts. The identity-provider layer of the Cloud Identity Posture set, with API tokens and OAuth scope creep weighted the way a trust root deserves.
Salesforce Security Posture Kit
What a misconfigured Salesforce org actually exposes — to a compromised user, a malicious OAuth grant, or an anonymous visitor who never logged in. The 2025–2026 breach wave did not start with a compromised account, and this kit scores the two entry points that did it above the one the other posture kits share.
GitHub / GitLab Security Posture Kit
What a leaked CI/CD secret, a poisoned Action tag or an overprivileged pipeline token can actually reach, and whether you would know before your published packages did. The 2025–2026 supply-chain incidents needed no compromised identity at all, and this kit scores the workflow mechanics that let them through.
AI-Built / Vibe-Coded App Security Posture Kit
Your AI builder shipped fast. Did it also ship a public database, a leaked API key, and a coding agent that will run whatever it reads next? A stack assessment, not a platform one — builder, database, hosting, AI coding tool and MCP, embedded agent — for the founder who needs to know what is exposed before it becomes an incident.
Android Application Security Posture Kit
What a decompiled APK, a rooted device or an intercepted connection can actually reach, scored against OWASP MASVS v2.0 rather than a generic checklist. Hardcoded secrets pass Play Protect; only a review catches them. The Android half of a mobile pair whose scores are directly comparable with the iOS kit.
iOS Application Security Posture Kit
A locked-down platform does not mean a locked-down app. What a jailbroken device, a decompiled IPA or an intercepted connection can actually reach, scored against OWASP MASVS v2.0. App Store review does not catch a hardcoded key either. The iOS half of a mobile pair whose scores are directly comparable with the Android kit.
Docker & Kubernetes Security Posture Kit
An exposed dashboard with no password, a pod's auto-mounted token, a wildcard RBAC binding, an etcd port on the internet: one attack chain from container to cloud account. Docker and Kubernetes assessed together in a single pass, scored against both CIS benchmarks, for the platform team that inherited the cluster.
AWS Cloud Infrastructure Posture Kit
Three in four scanned AWS accounts have something publicly exposed right now. What one exposed S3 bucket, one over-permissioned IAM role or one leaked access key can actually reach — scored against the CIS AWS Foundations Benchmark v3.0.0. First of a three-cloud trilogy on one scoring scale.
Azure Cloud Infrastructure Posture Kit
One compromised identity reached Key Vault, Storage and Virtual Machines in minutes, in a chain Microsoft's own security team documented in 2026. Azure's dominant risk is identity, not raw exposure, and this kit is shaped for it: Key Vault and Storage weighted highest, both the CIS Azure and Microsoft Cloud Security Benchmarks cited, and no re-run of the Entra ID review M365-01 already did. Second of the three-cloud trilogy on one scoring scale.
Google Cloud Platform Posture Kit
Google Cloud has the best network-exposure numbers of the three clouds by a wide margin, and almost exactly the same identity problem as the other two. This kit is about the gap between those facts: 8% exposed, 87% with weak IAM. Scored against CIS GCP Foundation Benchmark v4.0.0, with an AI/ML workload surface the other two cloud kits do not have. Third of the trilogy on one scoring scale.
Enterprise Data Warehouse & AI Pipeline Security Posture Kit
Every table in your warehouse was access-controlled for the analyst who queries it by hand. None of that was written for a nightly retraining job, a RAG layer or a write-back agent. One assessment across Snowflake, Databricks, BigQuery or Redshift and the AI layered on top — with two blast-radius surfaces no other kit has: what the RAG layer can reach, and who can rewrite what the AI tells every employee.
Bundles
5 bundles cover this alongside adjacent work — always below the sum of the parts.
M365 Posture + Response
The M365 Security Posture Kit plus the IR Runbook Library. Know what a compromised account can reach, and have the runbook ready when one is. 15% off buying separately.
Vibe-Coded App + Pipeline
The AI-Built / Vibe-Coded App Security Posture Kit plus the GitHub / GitLab Security Posture Kit. The app stack and the pipeline that ships it, assessed with one method. 15% off buying separately.
Mobile App Security Posture Bundle
The Android and iOS Application Security Posture Kits together. One MASVS v2.0 backbone, one set of scoring bands, each platform's own controls — so a product that ships on both gets directly comparable numbers. 15% off buying separately.
Cloud Infrastructure Posture Bundle
The AWS, Azure and Google Cloud Infrastructure Posture Kits together. Three clouds whose top misconfigurations barely overlap, assessed with the same five modules on one scoring scale, so a multi-cloud estate gets three directly comparable numbers. 20% off buying separately.
Cloud Identity Posture Bundle
The M365, Google Workspace, Okta, Salesforce and GitHub / GitLab security posture kits together, for the vCISO or MSP whose clients run any mix of them. One mental model, five platforms: the front door, both suites, the CRM and the pipeline. 25% off buying separately.
Other regimes: EU AI Act · HIPAA · DORA & NIS2 · PCI DSS · Third-party risk · Critical infrastructure · Post-quantum
Working to a date? The compliance calendar. Not legal advice.