Container & cloud posture (CSPM / KSPM)
Find misconfigurations in cloud accounts, containers and Kubernetes.
Overview
Cloud Security Posture Management (CSPM) and Kubernetes Security Posture Management (KSPM) check your cloud and container environments against security best practices and benchmarks.
Most cloud breaches come from misconfiguration, not exotic exploits — these scans catch the open buckets, over-permissive roles and risky defaults before attackers do.
How it works
SecNxt evaluates your cloud/container/Kubernetes configuration against a library of security checks and reports each violation as a finding with remediation guidance.
Container image scanning additionally flags known-vulnerable OS and application packages baked into images.
How to use it
- 1Choose the relevant scan type (CSPM, KSPM or Container) on the New scan screen.
- 2Connect the cloud account, cluster or image you want assessed.
- 3Run the scan.
- 4Work through misconfigurations starting with the highest severity.
When to use it
- Proving cloud configuration meets a compliance benchmark.
- Catching public storage or over-broad IAM permissions.
- Hardening container images in your pipeline.
Tips & best practices
- Re-run posture scans on a schedule — cloud config drifts constantly.
- Fix identity and exposure issues first; they have the widest blast radius.
FAQ
- Is access read-only?
- Posture assessment only needs read access to evaluate configuration.
Related guides
Running a scan
Point SecNxt at a target and get prioritised findings in minutes.
Self-hosted runner
Scan private and internal targets without exposing them publicly.
Compliance
Use SecNxt's evidence to support your compliance programmes.
Vulnerabilities & findings
One prioritised inbox for every issue across every scan.