Kensho · Kubernetes & OpenShift security

Kubernetes security audit: would your clusters pass?

We assess your Kubernetes and OpenShift clusters in a structured audit against CIS Benchmark, BSI APP.4.4 and NSA/CISA. You receive a prioritized action plan your team can implement right away.

CKSCIS BenchmarkBSI APP.4.4

10 years of Kubernetes · 11 years of containers · 14 years of Linux

Sound familiar?

Six signs your clusters need an audit

Kubernetes is not securely configured out of the box. The question is not whether vulnerabilities exist, but which of them are exploitable today.

Config grown over years

Misconfigurations and excessive permissions, accumulated over years. Nobody knows anymore which of them are actually needed.

Secrets & privileges

Secrets in images, privileged pods, open defaults: nobody checks these systematically until something happens.

Compliance without evidence

NIS2, DORA, ISO 27001, BSI: auditors and customers want evidence, not declarations of intent.

No complete picture

Dashboards report green. Still, nobody has the complete view of the platform's actual state.

Questionnaire blocks the deal

An enterprise customer's security questionnaire is on the table: over 100 questions, a tight deadline, the deal on hold.

No outside perspective

Your clusters carry critical workloads, yet nobody has ever assessed them from the outside. Operational blindness sets in by itself.

The threat landscape

Attackers do not wait for your next audit

The BSI situation report and independent studies show how short your window really is.

18minutes

is the average time until a freshly provisioned cluster sees its first attack attempt.

80 %

of attacks reported to the police hit small and medium-sized businesses, for example with ransomware.

46 %

of the clusters examined run outdated Kubernetes versions without security updates. Maybe yours too.

The German NIS2 implementation act has been in force since 6 December 2025. Your management must personally direct and monitor its implementation (sec. 38 BSIG). The organization faces fines of up to EUR 10 million (sec. 65 BSIG). A Kubernetes security audit provides documented technical evidence for your NIS2 risk management.

There is a better way.

The solution

Scanners find symptoms. Senior experts find the causes.

Kensho combines automated scans with expert validation: for Kubernetes and OpenShift, on-premises, in the cloud or hybrid. The result is security findings plus recommendations that make your platform better.

We work without changing production systems: least-privilege read access, time-boxed and documented. And we train CKS candidates: the attack patterns and hardening mistakes we teach there are exactly what we look for in your cluster.

Scans plus senior review

Automated scans cover the breadth, senior engineers validate every finding. You will never get an unfiltered tool report from us.

No risk to operations

Least-privilege read access, time-boxed and transparently documented: no changes to production systems.

Prioritized, not overwhelming

Findings sorted by impact and exploitability, with quick wins from day one. Your team always knows what comes first.

Kensho fits if …

you operate a production Kubernetes or OpenShift platform

you need evidence: for auditors, customer questionnaires or your own peace of mind

you want to implement the plan yourself or hand it to us: the action plan supports both

Kensho is not the right fit if …

no cluster is in operation yet: our Kubernetes consulting is the better fit then

you are looking for a penetration test with active exploitation: Kensho audits without touching operations

you want to hand over operations for good: that is what our ongoing Mamori support is for

How it works

Four steps to a prioritized action plan

From scoping to the results workshop: transparent, plannable and without touching production.

  1. Kick-off & scoping

    We capture your goals and prioritize together which audit areas are critical for your situation. Scope, access and schedule are fixed in writing. After that, the fixed price stands.

  2. Analysis

    Automated scans across all agreed areas, plus configuration and pipeline reviews by senior engineers. Least-privilege read access: time-boxed, documented, no changes to operations.

  3. Validation & prioritization

    Every finding is validated by hand and rated by impact and exploitability. False positives are dropped, quick wins go straight to your team, strategic measures get planned.

  4. Results workshop & roadmap

    We walk through the report and action plan with your team, answer open questions and prioritize together. You implement it yourself or together with us.

You receive the first quick wins during the audit, not only with the final report.

Certified: CKA, CKAD, CKS
Least-privilege read access, NDA as a matter of course
DevNinjas GmbH from Germany

What Kensho audits

Seven angles. One security picture.

Grouped by attack surface: from the container image through the supply chain into day-to-day operations.

Cluster & runtime

Benchmarks & hardening

Systematic comparison against CIS, NSA/CISA, BSI APP.4.4 and Pod Security Standards. The base of every Kensho audit. For OpenShift additionally checked against SCCs and routes.

Cluster & runtime

Manifests & RBAC

Security context, least privilege, secrets

Cluster & runtime

Network & policies

Segmentation, network policies, zero trust

Build & supply chain

Image security & SBOM

CVE scans, supply chain, license compliance

Build & supply chain

CI/CD & supply chain

GitOps, signing, approval gates, rollback

Operations & efficiency

Observability & incidents

Logs, metrics, traces and how much they actually tell you

Operations & efficiency

Resources & FinOps

Right-sizing, over-provisioning, throttling

7 audit areas, over 40 controls. During scoping we decide together what matters. No area is mandatory.

No finding without a next step: everything lands prioritized in the report, with effort and business impact.

6 deliverables · in every tier

What you hold in your hands at the end.

  • Audit report with prioritized findings and security scoring

  • Action plan with effort and business impact

  • Platform recommendations: anomalies, missing building blocks and sensible next steps

  • Technical evidence with control mapping: CIS and NSA/CISA, extended per tier

  • Quick-win list, actionable from day one

  • Results session with your team

kensho-audit-report.pdfPage 3 / 42

Finding: RBAC wildcard in prod namespace

HIGH

Recommendation

Severity distribution

CriticalHighMediumLow

From our audit practice

Where a Kubernetes security assessment makes the difference

Three anonymized moments from our audit and consulting practice: finding gaps, putting the CIS Kubernetes Benchmark in context, prioritizing risks.

The silent finding

A management endpoint had been reachable from the entire corporate network for months: not an exotic vulnerability, but a cluster default that nobody ever questioned. The fix was a single network policy. The gap was not found by chance, but because someone looked systematically. That is exactly what an audit does: it makes visible what daily operations stopped seeing long ago.

HIGH

kind: NetworkPolicy

Fix: 1 network policy

The questionnaire

An enterprise customer's security questionnaire was on the table: well over a hundred questions on RBAC, networking and hardening, a few days' deadline, a deal hanging in the balance. With the audit report and control mapping, answering became assembly instead of research. Every answer could be proven instead of claimed. Sales could commit without the platform team losing a week.

Answers evidenced from the report

The priority

Hundreds of findings from their own scanner, plus open CVEs without context: the list was long, the urgency unclear, the starting point impossible. The audit condensed it into a few assessed items, sorted by exploitability and effort, with quick wins for the first sprints. The ability to act does not come from more alerts, but from the right order.

Sorted by exploitability and effort

Consulting · workshops · training

An average of 4.9 out of 5 stars from over 1,000 training reviews. The same standard applies to every security assessment and hardening we deliver.

Audit tiers

How much audit depth does your Kubernetes cluster need?

All tiers combine automated scans with expert validation and deliver the prioritized report. They differ in manual depth, interviews and management output. The fixed price stands after scoping: before you commit, without hidden effort. We tell you the concrete fixed-price range within the first minutes of the free scoping call.

Focus

The focused base audit

For the first structured check

Automated scans · expert validation · typically 2 weeks

  • Scans across all seven audit areas
  • Scope focused together in the kick-off
  • Prioritized evaluation by senior engineers
  • Report, quick wins and remote results session
Request Focus directly
Deep DiveRecommended

The technical deep dive

Under NIS2, Deep Dive is the typical starting point, Focus the preliminary check. For most production platforms.

Standard scope for production platforms · typically 3–4 weeks

  • Everything in Focus, plus:
  • Manual senior reviews: architecture, RBAC, GitOps, secrets
  • Control mapping: BSI APP.4.4/SYS.1.6 and ISO 27001
  • 1 remediation retest included
  • Management summary + half-day results workshop
Request Deep Dive directly
360°

The full-platform audit

For regulated industries and governance duties

Complete assessment incl. GRC · scope agreed during scoping

  • Everything in Deep Dive, plus:
  • NIS2 and DORA evidence package with multi-framework mapping
  • Threat model, DR/BCM validation and maturity assessment
  • Board deck, results presentation and Kensho attestation
Request 360° directly
Compare all features in detail
FeatureFocusDeep Dive360°
Automated scansFocus: Yes, focused scopeDeep Dive: Yes, complete360°: Yes, complete
Manual deep analysisFocus: Scan validation, no manual reviewsDeep Dive: Code & architecture reviews360°: + GRC analysis
Team interviewsFocus: Not includedDeep Dive: Engineers360°: + stakeholders
Threat analysisFocus: Not includedDeep Dive: Attack paths to critical workloads360°: + platform threat model
Technical audit reportFocus: Yes, with quick-win listDeep Dive: + architecture sketches360°: + maturity assessment
Management reportingFocus: Not includedDeep Dive: Management summary360°: Board deck + results presentation
Results sessionFocus: Remote sessionDeep Dive: Half-day workshop360°: + prioritization workshop
RoadmapFocus: Quick-win listDeep Dive: + prioritized remediation roadmap360°: + 12–24-month roadmap
Control mapping per findingFocus: CIS, NSA/CISADeep Dive: + BSI APP.4.4/SYS.1.6, ISO 27001 (A.8)360°: + NIS2 (sec. 30), DORA
Evidence packageFocus: Base evidence (scans, benchmarks)Deep Dive: + implementation evidence per control360°: + input for sec. 31 and management processes
Remediation retestFocus: Available as add-onDeep Dive: 1 retest included360°: Retest + verification documentation
Kensho attestationFocus: Not includedDeep Dive: Not included360°: After verified retest
Scoping-Agreement.pdf1 / 1

Clearly agreed before the start

Fixed price

Written offer with a fixed price after scoping

Scope of work

Audit depth, deliverables and schedule fixed

Scope limits

Limits and exclusions transparently documented

Access

Least privilege, time-boxed, documented

NDA

Confidentiality, on request before the first call

Critical findings

Immediate notification already during the audit

You receive your fixed-price offer after scoping.
Vincent Sturm - DevNinjas

Your contact

Vincent Sturm

Key Account Manager

Vincent works out scope, audit depth and the fixed price with you. And after the audit we do not leave you alone: a dedicated contact, answers to follow-up questions and regular health checks on request.

WhatsApp Chat

Get started

Want to know where your clusters really stand?

In the free audit scoping call we clarify goals, scope and audit depth. You then receive scope, fixed price and schedule: in writing and before you commit.

Scoping call (30 min)

We clarify cluster scope, goals and framework.

Written fixed-price offer

Audit scope, schedule and price: fixed before you commit.

Audit start

Without touching operations, NDA possible beforehand.

Vincent Sturm

Vincent Sturm

Your contact · Key Account

In the call we clarify:

Your attack surface and critical audit areas

The right audit depth: Focus, Deep Dive or 360

Scope, schedule and next steps

Already decided? Request directly and we reply with the offer

30 min · calendar opens directly · reschedulable · NDA possible beforehand

And afterwards? Many customers turn the audit into a quarterly rhythm: the easiest entry into our ongoing Mamori support