Resources
The «how» of cybersecurity, explained
We explain how each capability of the platform works underneath: what problem it solves, why it is done that way and what changes when the context travels attached to the data. No smoke, and no untranslated acronyms.
Capabilities
One page per capability
Each one explains the concept in general and then how Cloud Fortress solves it. Grouped by the area they belong to.
Digital risk and brand
Vulnerabilities and defence
- Vulnerability managementWhy CVSS is only half the story and how priority is set with exposure and business value.
- SOC monitoringThe hidden cost of switching screens, and what changes when the alert arrives with its context.
- Threat huntingFinding whoever is already inside and made no noise, from hypotheses and over an inventory you know.
- Asset inventoryThe quiet foundation: what an SBOM is, what a CBOM is and why shadow IT is a blind spot.
Glossary
The acronyms, translated
The terms that appear across the rest of the site, defined in one line. Taken from the platform's functional catalogue.
- CVE
- Common Vulnerabilities and Exposures. The public, unique identifier of a specific vulnerability, and the name the whole industry uses for it.
- CVSS
- The standard scoring system for a vulnerability's criticality, in versions 3.1 and 4.0. It measures severity in the abstract, not the risk it poses to your organisation.
- CPE
- Common Platform Enumeration. The standard platform identifier: the vocabulary used to match vulnerabilities to assets.
- SBOM
- Software Bill of Materials. An inventory of the installed software and the components it is built from. It is what tells you whether a CVE in a library affects you.
- CBOM
- Cryptographic Bill of Materials. An inventory of the cryptographic algorithms and keys the organisation uses.
- RMM
- Remote Monitoring and Management. On the platform, the inventory of devices and their status.
- SOC
- Security Operations Centre. The team and the set of tools that watch the organisation continuously to detect and respond to incidents.
- Threat hunting
- The proactive search for threats that have slipped past the automatic defences. It starts from hypotheses instead of waiting for an alert to fire.
- Defacement
- An unauthorised change to the content of a website.
- Takedown
- The process of removing malicious infrastructure that impersonates the organisation: a domain, a cloned site, a fake profile.
- Typosquatting
- Registering a domain that mimics the legitimate one with a letter changed, to catch whoever mistypes or does not look closely.
- Kill chain
- The seven phases of an attack, from reconnaissance through to impact.
- MTTR
- Mean Time To Respond. The average time to respond to an incident.
- ENS
- Esquema Nacional de Seguridad, Spain's National Security Framework. Regulated by Royal Decree 311/2022, it sets the cybersecurity requirements for the Spanish public sector and its suppliers, in three categories: basic, medium and high.
- vCISO
- Virtual Chief Information Security Officer. The security leadership layer —risks, priorities, roadmap— without needing a full-time post.
- Agent
- Software deployed on an endpoint that reports its inventory and status to the platform.
- Q-Day
- The day quantum computing breaks today's asymmetric cryptography. It is the reason the cryptographic inventory (CBOM) exists.
Would you rather see it than read it?
30 minutes with a scenario close to yours. We show you the platform and answer whatever you need.