Skip to main content
GenioCT

Platform

Govern Azure as one system

Security posture, cost, access, governance and compliance each live in their own Azure blade and their own export. Governator reads them into one model of what exists, who owns it, what it costs, what is risky, and what has to happen next.

What Governator does

Governator collects configuration, security, access, cost and activity data from your Azure subscriptions and resolves it into a single representation of your environment. Every module below reads that same representation, which is why a cost line, a role assignment and a compliance gap can point at the same resource and the same owner.

Overview

Where the environment stands today: risk, spend, exposure, recent change, and what needs attention first across every subscription in scope.

FinOps

Cost with the environment around it. Allocation to the teams and services that pay for it, budgets tied to ownership, commitment coverage, anomalies, and drill-down from an invoice line to the resource.

Security

Defender findings, public exposure, WAF and firewall configuration, NSG analysis and attack paths, scored and prioritised rather than listed.

Identity and access

Who holds which role, at which scope, and why. Assignments nobody has used, standing privilege, and the combinations that only become dangerous together.

Compliance and assurance

CyFun, NIS2 and DORA control mapping with interpretation, an evidence trail with attestations and review dates, and audit-ready export.

Governance

Policy compliance, tagging quality, ownership, exceptions, and the workflow that closes findings instead of reporting them.

Governator home showing needs-attention findings ranked by severity, spend this month, external exposure and audit readiness, with per-domain cards for security, FinOps, compliance, operations and resources.
One view across the domains: what needs attention first, the month's spend, external exposure and audit readiness, with what moved in the last seven days beside it.

One model under the modules

Those six are not separate tools behind one login. Azure exposes configuration through Resource Graph, security through Defender, spend through Cost Management, access through RBAC and change through the Activity Log, each with its own identifiers, its own shape, and its own idea of what a resource is. Governator normalises them into one representation it owns, so a subscription, a resource, an owner and a cost line mean the same thing in every module.

That is what makes the cross-domain questions answerable. Which resources without an owner are also the expensive ones. Whether the role assignment that failed a control belongs to the same team paying for an idle environment. Which of last month's changes moved the spend and the risk at the same time.

FinOps, and where Azure Cost Management stops

Azure Cost Management is the system of record for what Azure charged you, and Governator does not replace it. Governator reads that data and adds the operating model around it: who pays for it, against which budget, under whose ownership, with the resource and governance context attached.

Azure Cost Management Governator FinOps
What did Azure charge? Who should be paying for it?
Subscription, resource group and resource views Allocation to the structure the organisation actually runs on
Azure budgets Budgets tied to named ownership
Cost breakdown Cost with resource, governance and security context
Reservation and commitment data Commitment coverage inside the operating model
Tags as Azure metadata Tags checked against who is accountable
A cost anomaly An anomaly with its owner, resource and change history

Closed months are reconciled against the billing data and published as final. The current month is a provisional view, replaced when the invoice closes, so a monthly surprise can be traced to a named resource and a named owner while there is still time to act on it.

Governator FinOps overview showing monthly spend, trend, allocation coverage and budget status across subscriptions.
FinOps overview: spend and trend, allocation coverage, budget status, and the findings worth acting on this month.
Governator FinOps explorer showing one month of cost grouped by service, with each group's share and its change against the previous month.
Explorer: a month of cost grouped by service, each line with its share, the movement against last month, and the evidence behind the number.
Governator RBAC view showing total role assignments split across service principals, users and groups, the count of privileged accounts, a role distribution chart, and a privileged access table listing principal, role and scope.
Role assignments in one view: how many belong to service principals rather than people, which roles dominate, and the privileged access table with principal, role and scope.
Governator attack path analysis tracing a critical path from a public IP through an NSG, a VM and VNet peering to Key Vault and storage, with risk factors and the fixes that break the path.
A critical path traced from a public IP through to Key Vault and storage, with the fixes that break it and the CyFun control each one satisfies.

Who it is for

Security teams

Day-to-day operational security: WAF assessment, public exposure analysis, RBAC audit, Defender finding triage, exemption workflows, drift alerting, cleanup tracking. The output is a prioritised worklist with owners rather than another dashboard.

Platform and finance teams

Cost allocated the way the organisation is actually structured, budget ownership that survives a reorganisation, commitment coverage, tagging quality, and the drill-down that turns a monthly surprise into a resource and an owner.

Management and audit

Compliance evidence, CyFun/NIS2 mapping, board reporting, audit-ready exports, gap narratives. Proof and accountability for the people who need to sign off.

How it works

Data collection

  • Resource Graph (subscriptions, resources, tags, properties)
  • Defender for Cloud (CSPM assessments, secure scores)
  • Azure Policy (compliance states, definition resolution)
  • RBAC (role assignments, principal resolution via MS Graph)
  • Activity Log (90-day activity per resource)
  • Cost Management (billing data, service breakdown)
  • WAF Policies (CRS rules, paranoia level, exclusions)
  • Azure Firewall (rule collection groups, DNAT exposure)
  • Storage Metrics (transactions, capacity, egress)
  • Tag Compliance, Cleanup Detection, Change Detection

AI-powered assessment

  • Per-control gap narrative generated for auditor review
  • Storage account deep inspection with PII detection
  • Resource criticality and data sensitivity classification
  • WAF security assessment with effective protection scoring
  • Defender exemption justification drafting

How Governator is different

Defender / Policy / Secure Score tell you

  • What is misconfigured
  • What is exposed
  • What is non-compliant technically

Governator adds

  • CyFun/NIS2 control mapping with interpretation
  • Ownership and remediation workflow per finding
  • Evidence trail with attestations and review dates
  • Executive summary and audit-ready export
  • One place to track technical and compliance meaning

Compliance depth, kept

Defender tells you what is wrong. Governator tells you what it means for CyFun or NIS2, who owns it, what changed since the last assessment, and what evidence proves it. That was the problem Governator was built for, and broadening the platform has not diluted it.

Control mapping runs against the CCB CyberFundamentals framework, NIS2 Article 21 requirements and DORA ICT risk obligations, with interpretation attached to each control rather than a raw list to work through.

Example: from Defender finding to audit evidence

1

Defender for Cloud flags a storage account with public blob access enabled

2

Governator maps it to CyFun PR.AC-3 (access control) and NIS2 Art. 21(2)(d) (access management policies)

3

The finding is assigned to the subscription owner with a 14-day remediation SLA

4

If the public access is intentional, the owner files an exemption with business justification and review date

5

The corrected or exempted state is included in the next audit evidence pack with full history

Governator issue lifecycle view showing detection, ownership, evidence, and resolution states for findings.
Issue lifecycle: detect, assign an owner, attach evidence, resolve. The timestamp trail an auditor will ask for.

From recurring audit costs to continuous assurance

NIS2 and DORA are both ongoing obligations; neither is a one-off certification. NIS2 Article 21 measures must be implemented and maintained, with annual progress reports under the Belgian regime. DORA requires continuous ICT risk management, mandatory operational resilience testing, and an up-to-date third-party register. The audit never really ends.

Most organisations meet that with recurring readiness assessments: every twelve months, an external consulting engagement, a fresh PDF, and another budget cycle. The drift between assessments is where most failures show up. Governator inverts the model. A one-time assessment to baseline, then continuous assurance as a managed service. Evidence regenerates on demand. The recurring spend goes into tooling that produces auditor-ready output instead of commissioning a new consulting deliverable every year.

  • Replaces the annual external readiness engagement with continuous data collection.
  • Generates fresh evidence packs on demand for the next audit, snapshot review, or board update.
  • Alerts on drift between assessments, where the actual failures happen.
  • Keeps the recurring budget inside the toolchain instead of in repeat consultancy fees.
Governator compliance timeline showing percentage tracked week by week against CyFun and NIS2 controls.
Compliance percentage tracked continuously, including between audits.

Assessment or continuous assurance?

Governator powers both. A CyFun/NIS2 Readiness Assessment is a one-time engagement that uses Governator to produce a point-in-time compliance picture with expert interpretation. For organisations that need ongoing visibility, Governator runs continuously as a managed service with regular collection, drift detection, and management reporting.

Most organisations start with an assessment and move to continuous assurance when they see the value of the evidence trail.

Start with a Governator-powered Azure Health Check

Not sure where to begin? A quick architecture review gives you a clear picture. No obligation.

  • Risk scorecard across identity, network, governance, and security
  • Top 10 issues ranked by impact and effort
  • 30-60-90 day roadmap with quick wins