Cloud Identity Posture Bundle
The M365, Google Workspace, Okta, Salesforce and GitHub / GitLab security posture kits together, for the vCISO or MSP whose clients run any mix of them. One mental model, five platforms: the front door, both suites, the CRM and the pipeline. 25% off buying separately.
What this actually gives you
- Why the set: the Okta kit sees the grant, the suite and CRM kits see what happened after it, and the pipeline kit sees how the code got there. One executive page with five columns rather than five reports that disagree.
Most practices do not get to choose which cloud suite a client runs, what fronts it, where the customer data sits, or how the code ships. This is all five posture kits — the same five modules, the same blast-radius bands, each built around its own platform's blind spots — so a mixed estate is assessed with one method rather than five.
M365 Security Posture Kit — licence-tier-aware blast-radius scoring across mailbox, file & collaboration, app consent, identity and detection; a Conditional Access / Entra ID Protection / PIM identity review; a CIS-aligned hardening baseline; data governance and detection readiness.
Google Workspace Security Posture Kit — edition-aware blast-radius scoring across Gmail, Drive & Docs, OAuth / Marketplace and detection; a Context-Aware Access / 2SV / admin-roles identity review; a CIS Google Workspace-aligned baseline; Vault and DLP governance and the Security Investigation Tool readiness matrix.
Okta / Identity Provider Security Posture Kit — the front door in front of both: blast radius across the whole downstream app catalogue, API tokens and third-party integrations weighted as a trust root deserves, a CIS Controls v8 baseline, directory and non-human-identity governance, and an executive page with the downstream footprint.
Salesforce Security Posture Kit — the platform where the 2025–2026 breach wave actually landed, and the kit whose risk model differs: three entry points, with the unauthenticated guest user and the OAuth connected app weighted above the compromised account; a Health Check-aligned baseline; Shield governance; and the one-day-retention detection finding.
GitHub / GitLab Security Posture Kit — the pipeline behind all of it, where the supply-chain incidents needed no compromised identity at all: third-party Actions and elevated-context triggers weighted highest, both CIS benchmarks cited, secrets-in-history governance, the Advanced Security licensing finding, and a dual-audience executive page for the engineering team as well as the board.
Why the set: the Okta kit sees the grant, the suite and CRM kits see what happened after it, and the pipeline kit sees how the code that runs on all of them got there. The full attack chain needs every layer. And the executive summary template in each kit is the same page, so a client gets one board-ready output with five columns rather than five reports that disagree.
What's in this bundle
M365 Security Posture Kit
Assess what a compromised Microsoft 365 account can actually reach, and close the gaps, before an insurer or auditor asks. Licence-tier-aware blast-radius scoring, a CIS-aligned hardening baseline, and one identity review covering Conditional Access, Entra ID Protection and PIM.
Google Workspace Security Posture Kit
Assess what a compromised Google Workspace account can actually reach, scored against your edition, and close the gaps before an insurer or auditor asks. The Workspace counterpart to the M365 kit, built around the two blind spots a login audit cannot see: a granted OAuth token, and shared-drive sharing that looks like a leak.
Okta / Identity Provider Security Posture Kit
What a compromised Okta account or a leaked API token can reach — not one suite's mailbox and files, but every downstream application Okta fronts. The identity-provider layer of the Cloud Identity Posture set, with API tokens and OAuth scope creep weighted the way a trust root deserves.
Salesforce Security Posture Kit
What a misconfigured Salesforce org actually exposes — to a compromised user, a malicious OAuth grant, or an anonymous visitor who never logged in. The 2025–2026 breach wave did not start with a compromised account, and this kit scores the two entry points that did it above the one the other posture kits share.
GitHub / GitLab Security Posture Kit
What a leaked CI/CD secret, a poisoned Action tag or an overprivileged pipeline token can actually reach, and whether you would know before your published packages did. The 2025–2026 supply-chain incidents needed no compromised identity at all, and this kit scores the workflow mechanics that let them through.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee