# Report on the state of your technical security controls _with confidence_

Prelude gives you live reporting on control coverage, configuration, and performance across your environment, so you can answer frameworks, questionnaires, and leadership questions without scrambling for screenshots and spreadsheets.

## The problem

### Technical control evidence rarely matches reality

Risk teams are accountable for how technical security controls perform, but rarely own the tools that run them. Evidence lives in email threads, exports, and screenshots across teams that is out-of-date by the time it's pulled together.

#### Evidence is often point-in-time

Auditors, questionnaires, and leadership all expect ongoing assurance, but evidence captured as-needed isn't an accurate picture of security.

#### Data is scattered across people and platforms

Answering basic questions means chasing down siloed IT, security, and compliance teams and stitching together reports.

#### No single trusted source of truth

Every audit kicks off new ad-hoc data collection that are difficult to defend as the true reality of your controls.

## The solution

### Turn technical control data into _defensible evidence_

Prelude gives risk teams a live, trusted view of how technical controls are deployed and configured with easy to deploy, build, and share reporting capabilities.

#### Constantly monitor control performance

Prelude surfaces insights into which devices and users are secured and which aren't. Teams can easily evaluate how key controls are deployed, configured, and what they cover.

.webp)

#### Purpose-built reporting

Build reusable reports for executives, auditors, and internal risk committees from the same data to give the right stakeholders the right data, whenever they need it.

#### Answer detailed questions with ease

Pull control views that map cleanly to relevant technical requirements like MITRE ATT&CK and NIST so you can see where (and with who) your greatest risk lies as a business.

#### Prioritize your remediation efforts

Spend less time reconciling data and more time reviewing and prioritizing risk decisions of which tools need to be improved and which teams need additional training.

## The process

### How Prelude _makes it easy_ to build reports about your security risk and exposure

Prelude helps you establish the fundamentals of coverage and configuration to lay the groundwork for effective testing exercises.

#### Agentless deployment

Prelude aggregates data from API, read-only integrations to the tools you're already using.

#### Data normalization

Prelude automatically de-duplicates and normalizes your data so you always look at the same device across platforms.

#### Exception management

Seamlessly filter out the outdated data, irrelevant policies, and focus on the insights that matter most to your business right now.

### _It’s a huge pain when you’re attempting to compare lists and try to find which devices are missing from which tools. Before Prelude, I was doing this sort of work in spreadsheets. It’s miserable._

Mason Janzen  
ISO, Republic Bank of Chicago

## Understand your risk

### Stop chasing answers about your security posture. _Just ask Prelude._

Prelude makes it easy to report on the state of your technical security controls to auditors, insurers, and executives.

Know with certainty.
