ciso.diy
Google Cloud Platform Posture Kit preview
Compliance Google CloudGCPcloud securityIAM

Google Cloud Platform Posture Kit

Google Cloud has the best network-exposure numbers of the three clouds by a wide margin, and almost exactly the same identity problem as the other two. This kit is about the gap between those facts: 8% exposed, 87% with weak IAM. Scored against CIS GCP Foundation Benchmark v4.0.0, with an AI/ML workload surface the other two cloud kits do not have. Third of the trilogy on one scoring scale.

What this actually gives you

  • 8% exposed, 87% with weak IAM — same dataset. Google Cloud has the best network posture of the three clouds by a wide margin and almost exactly the same identity problem: unused keys in 29% of accounts, default VPC in 29%, project-wide SSH keys in 26%, Shielded VM off in 21%.
  • The default Compute Engine service account's Editor role is a structural risk with no AWS or Azure equivalent. It and long-lived JSON keys where Workload Identity Federation should be are the two highest-weighted rows.
  • A cloud-to-AI-agent pivot is the fourth surface. A 2026 Vertex AI Agent Engine vulnerability exposed a deployed agent's service credentials and scopes through the metadata service; the AI/ML surface is N/A without Vertex AI and meets the vibe-coded app kit at the application layer.
  • Google automatically disables a detected exposed key by default — a built-in response the other clouds do not match, named plainly, with Google's own caveat that it does not replace anomalous-IAM detection.
  • Scored against CIS GCP Foundation Benchmark v4.0.0, the standard Security Command Center's detectors map to. Third of the trilogy on one scoring scale, and the trilogy ships as one bundle.

Good number, bad number, same dataset. A 2026 index built from live configuration data across roughly three thousand organisations found only 8% of Google Cloud accounts had a publicly exposed service — against 76% on AWS and 64% on Azure. The same dataset found weak IAM controls in 87% of them, a risk profile the underlying analysis describes as overwhelmingly tied to identity: unused service account keys in 29% of accounts, the default VPC still in use in 29%, project-wide SSH keys unblocked in 26%, Shielded VM off in 21%. None of those is individually catastrophic. Together they show that the best-performing cloud in the comparison still treats identity hygiene as an open problem, and this kit closes the trilogy on that counterintuitive note.

The structural risk with no AWS or Azure equivalent. The default Compute Engine service account has historically carried the broad Editor role, so every VM that never had its service account changed runs with far more than it needs. That, and long-lived service account JSON keys where Workload Identity Federation should be, are the two rows weighted highest in the scoring tool. Google's own 2026 threat report documents the practical version: a leaked personal access token plus an anomalous CI/CD service account creating a new admin role — an identity-layer event that early detection would have stopped, and Google's own recommendation is to monitor for public credential leaks and anomalous IAM activity.

One surface the other cloud kits do not have. A 2026 vulnerability in Vertex AI's Agent Engine showed a deployed agent's call to the metadata service exposing the service agent's credentials, the hosting project's identity and the scopes available to the machine — a cloud-to-AI-agent pivot — and a separate 2026 incident tied exposed Gemini-environment API keys to billing abuse. File 03's fourth blast-radius surface is AI/ML workload exposure, N/A for orgs without Vertex AI, and it meets the Vibe-Coded App Security Posture Kit at the application layer.

Scored against the benchmark Security Command Center maps to. The CIS Google Cloud Platform Foundation Benchmark v4.0.0 — over a hundred controls — is condensed to the highest-impact ones with section references per row. No invented framework, no substitution.

The detection finding names a genuine advantage, and its limit. Google Cloud automatically disables a detected exposed service account key by default — a built-in response neither of the other clouds matches, and file 06 says so plainly. It also carries Google's own caveat: that does not replace proactive detection of anomalous IAM activity, which needs Security Command Center Premium and active rule configuration, and that correlation is the gap the threat report keeps pointing at.

What you get

01 Assessment Methodology (DOCX) — the counterintuitive story, the identity-first incident pattern, the cloud-to-AI-agent pivot, the five modules, run order, cross-links and assumptions.

02 Identity & Access Review Workbook (XLSX) — Corporate Credentials (Cloud Identity or Workspace only, MFA for every human account, central provisioning and deprovisioning), Service Account & Role Hygiene (precise roles over primitive ones, the default Compute Engine service account, JSON keys minimised in favour of Workload Identity Federation, IAM Policy Analyzer on a cadence), IAM Conditions & Org Policy (source-IP and time-window conditions, Organization Policy constraints, review cadence) and Federation & Cross-Project Access (external pipelines on Workload Identity Federation, impersonation chains scoped, cross-project grants reviewed), rolling into one identity posture score.

03 Blast Radius Scoring Tool (XLSX) — the flagship module. Record the Org Structure first — single project or Organization, AI/ML workloads in use, primary workload — then answer the control questions across service account keys, network configuration (default VPC removed, no 0.0.0.0/0 to management ports, instance-level SSH keys), compute & storage (Shielded VM, uniform bucket-level access, public access prevention at the organisation level) and AI/ML workload exposure. One score, a band on the same bands as every posture kit, and a closure list ranked by risk-weighted points.

04 CIS-Aligned Hardening Checklist (XLSX) — IAM, Networking, Compute & Storage and Logging & Monitoring (Admin Activity and Data Access audit logs retained and exported, log sinks to a controlled destination, Security Command Center with leak monitoring, Organization Policy restricting key creation), scored gap-to-target with a hardening percentage per family.

05 Data Governance Review (DOCX) — Cloud Storage and Cloud SQL encryption, whether uniform bucket-level access actually means what it says, and BigQuery dataset-level access scope.

06 Detection Readiness Matrix (XLSX) — Admin Activity logs (always on; export and retention are the question), Data Access logs (off by default, per service), automated key-exposure disabling, Security Command Center correlation and public-source leak monitoring, each row stating whether it is on by default and whether a native automated response exists.

07 Executive Summary Template (DOCX) — one page: the four module scores, top five findings, plain-language meaning, remediation timeline, and the note that this closes the trilogy — run the AWS and Azure kits alongside for a multi-cloud estate on the same bands.

gcp01.json — scoring bands, surfaces, org-structure components, the benchmark and the module map.

A worked example throughout. Fernbridge Analytics, a fictional data-analytics company with heavy BigQuery use and growing Vertex AI features, whose CI/CD pipeline uses Workload Identity Federation while two older integrations still carry JSON keys.

Where it sits. The AWS and Azure Cloud Infrastructure Posture Kits are the trilogy siblings, all on the same bands, and the trilogy is cheaper than buying all three. A GKE cluster inherits this project's IAM risk — the Docker & Kubernetes Security Posture Kit follows the chain from the pod to here. The GitHub / GitLab Security Posture Kit covers the pipeline on Workload Identity Federation; the Google Workspace Security Posture Kit covers the Workspace tenant Cloud Identity usually is. The IR Runbook Library is the response layer; run it against a vendor's project with the TPRM Program Kit; hand file 07 to the Director's Cyber Oversight Kit.

Written against Google Cloud service names, defaults, published statistics, incident reporting and CIS GCP Foundation Benchmark v4.0.0 as of Q3 2026, marked verify. Benchmark references are section mappings to a condensed control set. Not a replacement for Security Command Center — the posture and prioritisation layer above it. Not a penetration test. Scores are a prioritisation aid, not a certification, an audit opinion or an insurance-underwriting determination. Not legal advice.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-09
Pages 7