Skip to content
CloudSecOps
Document · v1.0Updated 2026-08-09

The CloudSecOps Methodology

How an engagement runs, stage by stage — what automation does, what senior engineers do, and what you receive at each step.

5 min read · free to read, no gate

Every consultancy now claims AI acceleration. Almost none will tell you what the AI does, what it doesn't, or where your money goes. This document is our pipeline, published in full so you can judge the engineering before you buy it.

The shape of an engagement

Six stages, from a scoping call to a verified fix. Automation absorbs the work that used to justify a large team — enumeration, correlation, evidence collection, regression retesting. What remains is the work that needs seniority, and that is what you are paying for.

Findings are reported as they are confirmed, not held for a delivery date. The engagement ends when a fix is verified, not when a report is delivered.

Stage 01 — Scope

Owner: AI + engineers

Inputs. An architecture walkthrough, your account inventory, and your top three worries.

What automation does. Public-surface reconnaissance and rough asset counts before the call, so we arrive informed rather than asking you to describe your own estate.

What engineers do. The engineer who will do the work runs the call, argues with your assumptions, and writes the scope. Fixed scope, fixed price — or an honest "you don't need this yet."

What you get. A written scope with explicit in/out boundaries, destructive-action rules, and a price that does not move.

Stage 02 — Inventory and reconnaissance

Owner: automated

Inputs. Scoped read access, issued by you and revocable.

What automation does. Identity, resource, network-reachability and data-path enumeration across accounts and projects. Configuration state, policy documents, logging coverage and exposure mapping, collected into one graph.

What engineers do. Nothing yet. This is the work that used to consume the first week of a traditional engagement.

What you get. A complete environment graph — whether or not we find anything interesting in it.

Stage 03 — AI-assisted analysis

Owner: AI + engineers

Inputs. The environment graph, plus current threat intelligence.

What automation does. Correlation across signals that humans read serially: which permissive role is reachable from which exposed service, which finding matters because of what sits behind it. First-pass triage ranks candidates by exploitability rather than scanner severity.

What engineers do. Every candidate is reviewed. Machine output is never forwarded to you — it is the starting point for the next stage, not a deliverable.

What you get. Nothing directly. The ranked candidate list is an internal artifact whose only job is to direct human attention.

Stage 04 — Human validation

Owner: engineers

Inputs. The ranked candidates, and the parts of your architecture that worry us.

What automation does. Nothing. This stage is where the fee goes.

What engineers do. Exploit chains built and proven end to end. Threat models drawn against how your system actually behaves. Business-logic and multi-step attacks that no scanner enumerates. Findings that do not survive scrutiny are dropped, not padded into the report.

What you get. Confirmed findings with reproducible steps, reported as they are confirmed.

Stage 05 — Findings and remediation engineering

Owner: engineers

Inputs. Confirmed findings, your stack, your constraints.

What automation does. Report assembly, evidence collection and cross-referencing.

What engineers do. Each finding is written by the engineer who found it — impact, path, and a fix designed for your environment. Where the fix is code or policy, we write the code or policy. Where it is an architectural change, we draw it.

What you get. The report, remediation artifacts, and an executive summary that states impact without inflating it.

Stage 06 — Verify

Owner: automated

Inputs. Your deployed fixes.

What automation does. Re-execution of the original proof for each finding, plus regression checks on the surrounding surface.

What engineers do. Judgment on partial fixes. We say so plainly when a mitigation reduces risk without removing it.

What you get. Each finding marked fixed, partially fixed or accepted, with evidence.

The rules we work by

Automation earns its place or it goes. We automate work that is repetitive and verifiable. We do not automate judgment, and we do not ship you machine output with our name on it.

Findings arrive when they are confirmed. If something is critical on day two, you hear about it on day two — usually with a suggested mitigation before the report exists.

The engineer on the call is the engineer on the engagement. There is no bench, no handoff to a junior team, and no account manager between you and the work. That constrains how much we take on, which is the trade we have chosen.

We say when you don't need us. Some enquiries end with a recommendation to fix three things yourself and call back in six months. That costs us a project and earns a client.

What we do not do

  • Staff augmentation or bodyshop placements
  • 24/7 monitoring or managed SOC services
  • Reselling security tools for commission
  • Compliance certification audits — we prepare you; auditors audit
  • Azure-specific engagements. Our cloud practice is AWS and Google Cloud, and we would rather say so than sell you a thinner engagement

Scope of this document

This describes how we work. It is not a contract, and it is not a guarantee of outcome. Durations quoted on the website are indicative ranges; actual scope, schedule and price are fixed in writing after a scoping call. Security testing requires written authorisation, and we do not test any system without it.

Module: document_request

Take the PDF.

The full document is on this page already — you do not need to fill anything in to read it. The form is for the PDF, and for us to know who is reading.

To be straight about it: this is lead capture, not access control. Once the link is issued it is an ordinary URL that can be forwarded. We are not going to pretend otherwise on a security site.

Prefer not to? Just email us and we will send it.