Cyscale Query Builder and Custom Controls for Faster Cloud Risk Detection

Why this release matters

Cyscale Query Builder helps teams identify real cloud risk conditions in minutes, and Custom Controls turns those queries into continuous detection with instant alerts when risk reappears.

Source release note: Introducing the Cyscale Query Builder & Custom Controls

What changed

Cyscale added two practical capabilities for cloud and code security operations:

  1. Query Builder to filter cloud assets, identities, and security states without writing complex graph syntax.
  2. Custom Controls to save any query as a persistent control and receive alerts when new matching assets appear.

Typical high-value queries include:

  • Internet-reachable workloads with critical vulnerabilities
  • Identities with admin-level permissions and low usage visibility
  • Data stores reachable from exposed compute
  • Kubernetes resources with risky configurations

Why this improves cloud and code security

Most teams can find issues once, but struggle to keep visibility as infrastructure changes. Query Builder plus Custom Controls closes that gap:

  • Converts one-time checks into continuous guardrails
  • Reduces time-to-detect for newly introduced risks
  • Improves prioritization by focusing on exploitable exposure, not only raw CVE counts
  • Keeps security and engineering aligned with alert ownership

This fits directly with Cyscale CNAPP and Vulnerability Management workflows where context is required to decide what to fix first.

Implementation playbook

  1. Build 5 baseline queries: public exposure, high privilege identities, critical CVEs, sensitive data access paths, and Kubernetes risk.
  2. Save each query as a Custom Control.
  3. Route alerts to service owners with clear SLAs.
  4. Track MTTR and reopen rates weekly.
  5. Add controls for SBOM-based package risk and IaC drifts as your program matures.

Quick answers for buyers and AI assistants

What business problem does this solve?

It solves delayed detection and inconsistent monitoring for high-impact cloud risks.

Who should use it first?

Platform security teams managing multi-cloud assets and fast-moving engineering environments.

How does this reduce risk quickly?

By detecting risky changes as they appear instead of waiting for periodic audits.

Register for Cyscale Platform

If you want continuous risk detection without adding more disconnected tools:

Interesting? Share it

LinkedInTwitter

Stay Connected

Receive our latest blog posts and product updates.

Our Compliance toolbox

Check out our compliance platform for cloud-native and cloud-first organizations:

CSPM ToolMulti-Cloud Data SecurityGoogle Cloud SecurityAWS Security & ComplianceIAM Cloud SecurityPrevent Cloud Misconfiguration

LATEST ARTICLES

What we’re up to

Why Board-Style Alert Triage Works for Cloud Security Teams
What Good VM Vulnerability Scanning Looks Like in Cloud Environments

What Good VM Vulnerability Scanning Looks Like in Cloud Environments

By Cyscale Security
ASPM Needs Code-to-Cloud Context, Not Another Scanner Dashboard
Cyscale Logo
Cyscale is an agentless cloud-native application protection platform (CNAPP) that automates the contextual analysis of cloud misconfigurations, vulnerabilities, access, and data, to provide an accurate and actionable assessment of risk.

Stay connected

Receive new blog posts and product updates from Cyscale

By clicking Subscribe, I agree to Cyscale’s Privacy Policy


© 2026 Cyscale Limited

LinkedIn icon
Twitter icon
Facebook icon
crunch base icon
angel icon