
Kensho · Kubernetes & OpenShift security
Kubernetes security audit: would your clusters pass?
We assess your Kubernetes and OpenShift clusters in a structured audit against CIS Benchmark, BSI APP.4.4 and NSA/CISA. You receive a prioritized action plan your team can implement right away.
10 years of Kubernetes · 11 years of containers · 14 years of Linux
Sound familiar?
Six signs your clusters need an audit
Kubernetes is not securely configured out of the box. The question is not whether vulnerabilities exist, but which of them are exploitable today.
Config grown over years
Misconfigurations and excessive permissions, accumulated over years. Nobody knows anymore which of them are actually needed.
Secrets & privileges
Secrets in images, privileged pods, open defaults: nobody checks these systematically until something happens.
Compliance without evidence
NIS2, DORA, ISO 27001, BSI: auditors and customers want evidence, not declarations of intent.
No complete picture
Dashboards report green. Still, nobody has the complete view of the platform's actual state.
Questionnaire blocks the deal
An enterprise customer's security questionnaire is on the table: over 100 questions, a tight deadline, the deal on hold.
No outside perspective
Your clusters carry critical workloads, yet nobody has ever assessed them from the outside. Operational blindness sets in by itself.
The threat landscape
Attackers do not wait for your next audit
The BSI situation report and independent studies show how short your window really is.
is the average time until a freshly provisioned cluster sees its first attack attempt.
of attacks reported to the police hit small and medium-sized businesses, for example with ransomware.
of the clusters examined run outdated Kubernetes versions without security updates. Maybe yours too.
The German NIS2 implementation act has been in force since 6 December 2025. Your management must personally direct and monitor its implementation (sec. 38 BSIG). The organization faces fines of up to EUR 10 million (sec. 65 BSIG). A Kubernetes security audit provides documented technical evidence for your NIS2 risk management.
There is a better way.
The solution
Scanners find symptoms. Senior experts find the causes.
Kensho combines automated scans with expert validation: for Kubernetes and OpenShift, on-premises, in the cloud or hybrid. The result is security findings plus recommendations that make your platform better.
We work without changing production systems: least-privilege read access, time-boxed and documented. And we train CKS candidates: the attack patterns and hardening mistakes we teach there are exactly what we look for in your cluster.
Scans plus senior review
Automated scans cover the breadth, senior engineers validate every finding. You will never get an unfiltered tool report from us.
No risk to operations
Least-privilege read access, time-boxed and transparently documented: no changes to production systems.
Prioritized, not overwhelming
Findings sorted by impact and exploitability, with quick wins from day one. Your team always knows what comes first.
Kensho fits if …
you operate a production Kubernetes or OpenShift platform
you need evidence: for auditors, customer questionnaires or your own peace of mind
you want to implement the plan yourself or hand it to us: the action plan supports both
Kensho is not the right fit if …
no cluster is in operation yet: our Kubernetes consulting is the better fit then
you are looking for a penetration test with active exploitation: Kensho audits without touching operations
you want to hand over operations for good: that is what our ongoing Mamori support is for
How it works
Four steps to a prioritized action plan
From scoping to the results workshop: transparent, plannable and without touching production.
Kick-off & scoping
We capture your goals and prioritize together which audit areas are critical for your situation. Scope, access and schedule are fixed in writing. After that, the fixed price stands.
Analysis
Automated scans across all agreed areas, plus configuration and pipeline reviews by senior engineers. Least-privilege read access: time-boxed, documented, no changes to operations.
Validation & prioritization
Every finding is validated by hand and rated by impact and exploitability. False positives are dropped, quick wins go straight to your team, strategic measures get planned.
Results workshop & roadmap
We walk through the report and action plan with your team, answer open questions and prioritize together. You implement it yourself or together with us.
You receive the first quick wins during the audit, not only with the final report.
What Kensho audits
Seven angles. One security picture.
Grouped by attack surface: from the container image through the supply chain into day-to-day operations.
Cluster & runtime
Benchmarks & hardening
Systematic comparison against CIS, NSA/CISA, BSI APP.4.4 and Pod Security Standards. The base of every Kensho audit. For OpenShift additionally checked against SCCs and routes.
Cluster & runtime
Manifests & RBAC
Security context, least privilege, secrets
Cluster & runtime
Network & policies
Segmentation, network policies, zero trust
Build & supply chain
Image security & SBOM
CVE scans, supply chain, license compliance
Build & supply chain
CI/CD & supply chain
GitOps, signing, approval gates, rollback
Operations & efficiency
Observability & incidents
Logs, metrics, traces and how much they actually tell you
Operations & efficiency
Resources & FinOps
Right-sizing, over-provisioning, throttling
7 audit areas, over 40 controls. During scoping we decide together what matters. No area is mandatory.
No finding without a next step: everything lands prioritized in the report, with effort and business impact.
6 deliverables · in every tier
What you hold in your hands at the end.
Audit report with prioritized findings and security scoring
Action plan with effort and business impact
Platform recommendations: anomalies, missing building blocks and sensible next steps
Technical evidence with control mapping: CIS and NSA/CISA, extended per tier
Quick-win list, actionable from day one
Results session with your team
Finding: RBAC wildcard in prod namespace
HIGHRecommendation
Severity distribution
From our audit practice
Where a Kubernetes security assessment makes the difference
Three anonymized moments from our audit and consulting practice: finding gaps, putting the CIS Kubernetes Benchmark in context, prioritizing risks.
The silent finding
A management endpoint had been reachable from the entire corporate network for months: not an exotic vulnerability, but a cluster default that nobody ever questioned. The fix was a single network policy. The gap was not found by chance, but because someone looked systematically. That is exactly what an audit does: it makes visible what daily operations stopped seeing long ago.
kind: NetworkPolicy
Fix: 1 network policy
The questionnaire
An enterprise customer's security questionnaire was on the table: well over a hundred questions on RBAC, networking and hardening, a few days' deadline, a deal hanging in the balance. With the audit report and control mapping, answering became assembly instead of research. Every answer could be proven instead of claimed. Sales could commit without the platform team losing a week.
Answers evidenced from the report
The priority
Hundreds of findings from their own scanner, plus open CVEs without context: the list was long, the urgency unclear, the starting point impossible. The audit condensed it into a few assessed items, sorted by exploitability and effort, with quick wins for the first sprints. The ability to act does not come from more alerts, but from the right order.
Sorted by exploitability and effort
Consulting · workshops · training
An average of 4.9 out of 5 stars from over 1,000 training reviews. The same standard applies to every security assessment and hardening we deliver.
Audit tiers
How much audit depth does your Kubernetes cluster need?
All tiers combine automated scans with expert validation and deliver the prioritized report. They differ in manual depth, interviews and management output. The fixed price stands after scoping: before you commit, without hidden effort. We tell you the concrete fixed-price range within the first minutes of the free scoping call.
The focused base audit
For the first structured check
Automated scans · expert validation · typically 2 weeks
- Scans across all seven audit areas
- Scope focused together in the kick-off
- Prioritized evaluation by senior engineers
- Report, quick wins and remote results session
The technical deep dive
Under NIS2, Deep Dive is the typical starting point, Focus the preliminary check. For most production platforms.
Standard scope for production platforms · typically 3–4 weeks
- Everything in Focus, plus:
- Manual senior reviews: architecture, RBAC, GitOps, secrets
- Control mapping: BSI APP.4.4/SYS.1.6 and ISO 27001
- 1 remediation retest included
- Management summary + half-day results workshop
The full-platform audit
For regulated industries and governance duties
Complete assessment incl. GRC · scope agreed during scoping
- Everything in Deep Dive, plus:
- NIS2 and DORA evidence package with multi-framework mapping
- Threat model, DR/BCM validation and maturity assessment
- Board deck, results presentation and Kensho attestation
Clearly agreed before the start
Fixed price
Written offer with a fixed price after scoping
Scope of work
Audit depth, deliverables and schedule fixed
Scope limits
Limits and exclusions transparently documented
Access
Least privilege, time-boxed, documented
NDA
Confidentiality, on request before the first call
Critical findings
Immediate notification already during the audit

Your contact
Vincent Sturm
Key Account Manager
Vincent works out scope, audit depth and the fixed price with you. And after the audit we do not leave you alone: a dedicated contact, answers to follow-up questions and regular health checks on request.
Get started
Want to know where your clusters really stand?
In the free audit scoping call we clarify goals, scope and audit depth. You then receive scope, fixed price and schedule: in writing and before you commit.
Scoping call (30 min)
We clarify cluster scope, goals and framework.
Written fixed-price offer
Audit scope, schedule and price: fixed before you commit.
Audit start
Without touching operations, NDA possible beforehand.

Vincent Sturm
Your contact · Key Account
In the call we clarify:
Your attack surface and critical audit areas
The right audit depth: Focus, Deep Dive or 360
Scope, schedule and next steps
30 min · calendar opens directly · reschedulable · NDA possible beforehand