Configuration-Focus

Introducing the new Configurations experience in Upwind

Danilo Michelucci September 24, 2026

Compliance should not be a fire drill! Ask a security team how audit season goes and you will often hear a version of the same story.

Someone pulls a list of cloud accounts. Someone else exports findings into a spreadsheet that is already outdated by the time it is shared. Screenshots get pasted into a document. A compliance number gets agreed on. Everyone moves on until the next audit, when the process starts all over again.

The problem was never a lack of effort. Compliance has traditionally been treated as a snapshot of an environment that may have changed several deployments ago.

Today, we are introducing a rebuilt Configurations experience in Upwind, created around a simple idea:

Your compliance posture should be something you can see, not something you have to assemble.

Configuration-Focus-02-1-scaled

See Your Complete Compliance Posture

Most organizations are measured against several standards at once. These may include CIS benchmarks, NIST and ISO standards, European Union regulations, United States government requirements, and industry frameworks. Different stakeholders may care about different standards, often on different timelines.

Upwind continuously evaluates your environment against every relevant framework and provides a live compliance score for each one.

Teams can filter results across AWS, Microsoft Azure, Google Cloud, Oracle Cloud, Kubernetes, and on premises environments. They can focus on the views they use most and share those views with colleagues, executives, or auditors without exporting another spreadsheet.

When someone asks, “Are we ready for our ISO audit?” you no longer need to generate a special report.

You can simply look.

Compliance requirements also continue to evolve. Benchmarks are revised, new regulations take effect, and a framework your organization satisfied last year can quietly change.

Upwind treats its framework library as a living part of the platform. We continuously introduce new frameworks, including recent additions such as ISO/IEC 42001 and the EU AI Act. We also update existing frameworks as new versions and revisions are published.

Every framework displays its version and latest update. This gives teams confidence that they are being evaluated against the current requirements rather than an outdated benchmark.

You do not have to track which standard changed. That is our job.

Configuration-Focus-01-1-scaled

Focus on the Fixes That Matter Most

Finding configuration issues is only the beginning. The more difficult question is deciding what to fix first.

Traditional backlogs may contain thousands of findings without showing which remediations will create the greatest improvement. Upwind’s Score Journey makes that impact clear.

Every finding shows how much its remediation could improve your compliance score, how many resources it affects, and how difficult the fix is, from Easy to Hard.

This changes how teams prioritize work. A medium severity logging gap affecting dozens of clusters might improve the overall score more than a critical finding affecting a single resource.

Teams can sort findings by potential impact, identify easy wins, and enter the next compliance review with a clear and defensible remediation plan.

Behind every score are individual rules mapped to the frameworks and controls they support. Each rule includes its compliance score, severity, platform coverage, and latest evaluation time.

Upwind also separates configuration findings from security issues. This helps teams distinguish between a policy gap and an active risk.

When an auditor asks how you know a specific control is being met, the evidence is only a search away.

Connect Every Gap to an Owner

An organization wide score is useful for reporting, but it does not always tell teams what to do next.

Nobody owns “83% compliant.”

Upwind scores each cloud account separately, connecting every compliance gap to a specific environment, scope, and responsible team.

Instead of giving teams a broad instruction to improve compliance, security leaders can see exactly where a gap exists, who owns the affected resources, and which action will help close it.

The goal is not to make compliance exciting. It is to make it boring in the best possible way.

Compliance should be continuous instead of episodic, visible instead of reconstructed, owned instead of orphaned, and prioritized according to measurable impact.

When your posture is always available, audit preparation stops being a recurring fire drill.

The new Configurations experience is available now in Upwind.

Contents

Further Reading

What You Could Build If IAM Let You

What You Could Build If IAM Let You: New Policies From Undocumented Condition Keys

In the previous post, we mapped 36 condition keys that the IAM engine evaluates but has never documented. The decomposition model, the service-specific resource identifiers, the organizational metadata - all of it sitting in the request context, invisible unless you probe for it. That post was about discovery. This one is about what you can…
Show Me the Context

Show Me the Context: Building the Full Request Context for AWS IAM

This post was written in early August 2026, ahead of our fwd:cloudsec Europe talk. On August 25, AWS launched the Access Troubleshooter (currently in public preview), a first-party feature that surfaces the request context for denied requests. We've updated this post to account for it. When the IAM engine evaluates your request, it matches your…
AI LABS

Building the Future: Introducing the Upwind AI Security Lab

I have always been fascinated by what comes next. Growing up, I watched technology reinvent itself again and again, from early gaming and the dot-com era to SaaS, cloud, and modern software development. I remember wondering when I would get the chance to help build what came next. At the time, I was mostly watching…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS