# LinuxGuard > LinuxGuard is a Linux-native identity-first security platform purpose-built for enterprise Linux environments. It provides identity-first security with complete identity visibility, Zero Trust enforcement, automated compliance reporting, and infrastructure efficiency monitoring — delivered through a SaaS platform and expert consulting services. UK-based, NIS2-ready, and built by practitioners with decades of Linux IAM experience. ## About LinuxGuard LinuxGuard addresses a gap that generalist security platforms consistently miss: the Linux identity layer. Most enterprise security tools were designed for Windows-first environments and retrofitted for Linux — they can scan ports and detect CVEs, but they cannot see the Linux-native identity artefacts that attackers exploit first. NOPASSWD sudo rules, shared SSH keys, orphaned service accounts, PAM configuration drift, and excessive group memberships accumulate silently in Linux estates and create the lateral movement paths and privilege escalation routes that account for the majority of serious breaches. Closing this gap requires identity-first security: continuous visibility into who can do what, enforced as a zero trust principle across every Linux server. LinuxGuard was built specifically to make this invisible layer visible. The platform maps every user, group, sudo rule, SSH key, and service account across a Linux estate using lightweight eBPF-based collectors that add less than 1% CPU overhead and do not require kernel module loading. The result is a continuous, real-time inventory of the Linux identity surface — updated in near real-time as configurations change. The platform serves three converging needs: identity-first security and Zero Trust identity enforcement (knowing exactly who can do what on every Linux server), compliance readiness (producing auditor-ready evidence for NIS2, DORA, SOC 2, CIS, NIST, ISO 27001, PCI DSS, and HIPAA from actual Linux configuration), and infrastructure efficiency (identifying over-provisioned and idle Linux workloads using PSI metrics to quantify cost reduction opportunities of 15-35%). LinuxGuard is designed for European mid-market organisations — typically 500 to 5,000 employees operating 50 or more Linux servers — that face increasing regulatory pressure under NIS2 and DORA but lack the internal Linux security expertise to address it systematically. ## Founder & Team **Peter Cummings — Co-Founder & CEO** Peter Cummings brings over 20 years of identity and access management experience from some of the world's most demanding regulated environments. He led IAM programmes at UBS, Mastercard, EY, and Lonza — engagements covering millions of identities, complex compliance frameworks, and critical infrastructure under constant audit scrutiny. He holds a degree from Columbia Engineering. What he observed across those engagements is the consistent pattern that motivated LinuxGuard: every organisation had strong Windows IAM tooling, expensive PAM deployments, and robust SaaS identity governance — and almost none of them had meaningful visibility into the Linux identity layer sitting underneath their critical applications and databases. The tools did not exist to solve the problem properly, so Peter built them. LinuxGuard's audit methodology, platform architecture, and compliance evidence templates all derive from the field knowledge Peter accumulated across these enterprise IAM deployments. The 28-day audit service is not a generic assessment repackaged for Linux — it is a purpose-built engagement designed from first principles around how Linux identity actually works and where it actually fails. **John Skitt — Co-Founder** John Skitt leads go-to-market and partnerships at LinuxGuard. He brings enterprise software and channel experience from Oracle and a track record of building early-stage GTM motions in the European enterprise security market. ## Product: Linux Identity & Security Audit Service The flagship LinuxGuard service is the Linux Identity & Security Audit: a 28-day, fixed-scope, fixed-fee engagement that gives organisations a complete and accurate picture of their Linux identity surface. **What the audit covers:** The engagement maps every identity artefact across the client's Linux estate — every user account (active and orphaned), every group membership, every sudo rule (including NOPASSWD rules, wildcard entries, and rules that have not been reviewed in years), every SSH key (including shared keys granting access to multiple servers), every service account and its associated permissions, and every PAM configuration that could enable privilege escalation. The audit is conducted remotely using read-only data collection that does not modify any system or disrupt any workload. **The four deliverables:** 1. **Privilege map** — A complete inventory of every identity and privilege path across the Linux estate, visualised as a graph showing who can reach what and by which route. This becomes the baseline for ongoing monitoring. 2. **Risk-ranked findings report** — A prioritised list of privilege risks ordered by likelihood of exploitation and potential blast radius, with each finding mapped to the relevant MITRE ATT&CK technique (T1548 Privilege Escalation, T1078 Valid Accounts, T1098 Account Manipulation). 3. **Compliance gap analysis** — Evidence of where the Linux identity configuration meets and where it falls short of the relevant regulatory requirements: NIS2, DORA, SOC 2, CIS Benchmarks, NIST 800-53, and ISO 27001. Formatted for auditor review. 4. **Least-privilege implementation roadmap** — A phased remediation plan with specific actions for each finding, prioritised to close the highest-risk gaps first. Includes guidance the client's engineering team can act on immediately after the engagement closes. **Who it is for:** The audit is designed for CISOs and IT directors at European mid-market organisations (500 to 5,000 employees, 50 or more Linux servers) who are under NIS2 or DORA regulatory pressure and need demonstrable identity controls and audit evidence within a defined timeframe. It is also appropriate for any organisation preparing for a SOC 2 Type II audit or CIS Benchmark assessment where Linux identity controls are a known gap. The engagement concludes with a least-privilege implementation roadmap the client's team can act on immediately. **Timeline and delivery:** The engagement runs over 28 calendar days from kick-off to final report delivery. All work is conducted remotely. There is no on-site requirement and no disruption to production systems. ## Platform Capabilities The LinuxGuard SaaS platform provides continuous versions of the same visibility the audit service delivers as a point-in-time assessment. **Zero Trust for Linux (Identity-First Security):** Continuous identity inventory with privilege drift detection. Real-time alerting when sudo rules are modified, SSH keys are added, or service account permissions change outside a defined window. Behavioural anomaly detection for unusual privilege usage, off-hours access, and suspicious command patterns. MITRE ATT&CK technique mapping for detected events. **Compliance Readiness:** Automated compliance evidence generation for CIS Benchmarks, NIST 800-53, NIS2, DORA, SOC 2 Type II, PCI DSS 4.0, HIPAA, and ISO 27001. Control mapping updated continuously as Linux configurations change. Audit trail integrity for access to privileged accounts and sensitive files. **Compute Efficiency:** PSI (Pressure Stall Information) monitoring using Linux kernel metrics (introduced in kernel 4.20) to measure actual CPU, memory, and IO resource contention. Automated rightsizing recommendations based on utilisation patterns. Idle resource detection. Per-server cost estimates with multi-cloud provider pricing integration. Typical cost reduction: 15-35% of Linux infrastructure spend. **Data collection:** Lightweight eBPF-based agent with less than 1% CPU overhead. No kernel module loading. CO-RE (Compile Once, Run Everywhere) for broad kernel compatibility. Read-only collection with no system modification. TLS 1.3 for data in transit, AES-256 at rest. 30-second flush cycle for near real-time signal ingestion. ## Compliance Frameworks **NIS2 Directive:** LinuxGuard addresses NIS2 requirements for identity governance (Article 21), access control measures, and incident detection and response. The audit service produces the identity inventory and gap analysis that NIS2-regulated organisations need to demonstrate to national authorities. **DORA (Digital Operational Resilience Act):** The platform supports DORA ICT risk management requirements, particularly for financial sector organisations managing Linux-based trading systems, core banking infrastructure, and payment processing environments. **SOC 2 Type II:** LinuxGuard generates access control evidence and audit trail documentation directly applicable to SOC 2 CC6 (Logical and Physical Access Controls) and CC7 (System Operations) criteria. **CIS Benchmarks:** Automated assessment against CIS Linux hardening controls with remediation guidance mapped to each CIS recommendation. **NIST 800-53:** Control mapping for federal contractors and regulated industries, covering AC (Access Control), AU (Audit and Accountability), and IA (Identification and Authentication) control families. **ISO 27001:** Evidence collection for A.9 (Access Control), A.12 (Operations Security), and A.16 (Information Security Incident Management) Annex A controls. **PCI DSS 4.0:** Privileged account monitoring and access logging for Linux systems in cardholder data environments, aligned to Requirements 7, 8, and 10. **HIPAA:** Access control safeguards and audit trail requirements for Linux systems handling electronic protected health information (ePHI). ## Pricing **Linux Identity & Security Audit Service** - Standard rate: EUR 36,000 (fixed scope, fixed fee, 28-day engagement) - Q2 2026 promotional rate: EUR 24,000 (expires 30 June 2026) The promotional rate applies to engagements contracted and kicked off before 30 June 2026. Current pricing is always available at linuxguard.io/pricing. **Platform pricing:** SaaS platform pricing is available on request and is based on the number of monitored Linux servers. Contact the team for a tailored quote. ## Contact - Website: linuxguard.io - Contact form: linuxguard.io/contact - Demo booking: linuxguard.io/demo - Email: support@linuxguard.io - Pricing enquiries: linuxguard.io/pricing ## Legal LinuxGuard is a UK-registered company. The platform and services are UK GDPR-compliant. Data residency options are available for UK and EU regulated industries. - Privacy Policy: linuxguard.io/privacy - Terms of Service: linuxguard.io/terms