---
title: Shadow-Soft 4C’s Framework Addresses Technology Attacks and Vulnerabilities
description: Cyber attacks happen every 39 seconds costing trillions of dollars, requiring a new security framework from Cloud to Cluster to Container to Code. ATLANTA, GA, UNITED STATES, May 2, 2023 — Shadow-Soft, a Kubernetes system integrator, is drawing attention to…
image: https://shadow-soft.com/hubfs/Imported_Blog_Media/cropped-shadow-soft-logo-linkedin.png
---

[Skip to content](https://shadow-soft.com/content/4cs-framework-addresses-technology-attacks-and-vulnerabilities#main-content)

This is a search field with an auto-suggest feature attached.

- There are no suggestions because the search field is empty.

[![](https://shadow-soft.com/hs-fs/hubfs/Shadow-Soft-Logo-1.png?width=1878&height=431&name=Shadow-Soft-Logo-1.png)](https://shadow-soft.com)

- What We Do
  
   Expertise 
  
    - [Modern Infrastructure](https://shadow-soft.com/expertise/modern-infrastructure)
    - [Automation](https://shadow-soft.com/expertise/automation)
    - [Observability & Monitoring](https://shadow-soft.com/expertise/observability-monitoring)
    - [Cloud Engineering](https://shadow-soft.com/expertise/cloud-engineering)
    - [Security & Compliance](https://shadow-soft.com/expertise/security-compliance)
    - [AI Infrastructure](https://shadow-soft.com/expertise/ai-infrastructure)
  
  
   Technologies 
  
    - [Red Hat OpenShift](https://shadow-soft.com/expertise/openshift)
    - [Kubernetes](https://shadow-soft.com/expertise/kubernetes)
    - [Red Hat Ansible](https://shadow-soft.com/expertise/ansible)
    - [HashiCorp Terraform](https://shadow-soft.com/hashicorp-terraform-consulting)
    - [Dynatrace](https://shadow-soft.com/expertise/dynatrace)
    - [Icinga](https://shadow-soft.com/icinga)
  
  
  Solutions
  
  [**VMware to Red Hat Migration**](https://shadow-soft.com/solutions/vmware-migration-program)  
  Need a strategic path forward as VMware licensing costs rise?
  
  [**IT Operations Automation**](https://shadow-soft.com/solutions/it-operations-automation-program)  
  Transform IT operations into a resilient, cost-efficient foundation
  
  [**Unified Observability**](https://shadow-soft.com/solutions/unified-observability-program)  
  Stop firefighting with 6+ monitoring tools that don't talk to each other.<https://shadow-soft.com/services/embedded-staffing-services>
- Who We Serve
  
    - [Enterprises](https://shadow-soft.com/solutions/enterprises)
    - [Software Companies](https://shadow-soft.com/solutions/software-vendors)
    - [IT Solution Providers](https://shadow-soft.com/solutions/it-solution-providers)
- Resources
  
    - [Client Stories](https://shadow-soft.com/client-stories)
    - [Insights](https://shadow-soft.com/content-hub)
    - [Events](https://shadow-soft.com/events)
    - [Platform Pulse Newsletter](https://shadow-soft.com/platform-pulse)
    - [Academy](https://shadow-soft.com/academy-home)
- About
  
    - [About Shadow-Soft](https://shadow-soft.com/about)
    - [Partners](https://shadow-soft.com/partners)
    - [Careers](https://shadow-soft.com/careers)
    - [Newsroom](https://shadow-soft.com/newsroom)
    - [Contact](https://shadow-soft.com/contact)

[Let's Talk](https://shadow-soft.com/contact)

![Search icon](https://5018647.fs1.hubspotusercontent-na1.net/hubfs/5018647/Design/Icons/Font%20Awesome/search.svg)

[Let's Talk](https://shadow-soft.com/contact)

[All posts](https://shadow-soft.com/content/all)

 May 2, 2023

# Shadow-Soft 4C’s Framework Addresses Technology Attacks and Vulnerabilities

    Shadow-Soft Team  ·   1 minute read

Cyber attacks happen every 39 seconds costing trillions of dollars, requiring a new security framework from Cloud to Cluster to Container to Code.

ATLANTA, GA, UNITED STATES, May 2, 2023 — Shadow-Soft, a Kubernetes system integrator, is drawing attention to cyber attacks that are happening every 39 seconds on average according to the non-profit Information Security Forum.

James Chinn, CEO of Shadow-Soft, observed, “With supply chain businesses like manufacturing, logistics, retail, and finance increasingly reliant on digital systems, they are likely to be a significant portion of the $10 trillion cybercrime losses projected in 2025.”

As malicious actors constantly evolve their tactics, targeting vulnerabilities in software, hardware, and networks, businesses rely on patching their systems which takes an average of 250 days to detect and contain a breach. Chinn remarked, “Twitter, PayPal, AT&T, T-Mobile, and even The House of Representatives experienced technology attacks this year. This defensive posture is not sustainable.”

> **“Companies can’t patch and pray. That’s not a strategy. Fortunately, Kubernetes lets you build in security from Cloud to Cluster to Container to Code. Because the best defense is a good offense.”**
> 
> — James Chinn, Shadow-Soft CEO

To proactively defend against attacks, Nick Marcarelli, Head of Consulting, tasked his engineering team to create a 4C’s Security Framework to rethink Kubernetes security. “For every business leveraging the power of Kubernetes and especially those businesses just getting started with Kubernetes, you need to consider security at the Cloud, Cluster, Container, and Code level or what we call the 4C’s” advised Marcarelli.

As part of this new paradigm, Shadow-Soft recommends:

1. Treat each Kubernetes cluster and container as its own security boundary  
2. Upgrade to Layer 7 inspection/detection; Layer 4 is insufficient  
3. Internal security (East-West) is as important as perimeter security (North-South)  
4. Zero Trust through automation needs to be established as default

To help educate the market, Shadow-Soft is making its “Kubernetes: A CISO User Guide Using A Cloud to Code Framework” available for free. [Download the Framework](https://shadow-soft.com/kubernetes-ciso-guide/) to learn how to think through attack vectors and how to build proactive security.

**About Shadow-Soft**

Shadow-Soft is an award-winning Kubernetes systems integrator, specializing in helping organizations adopt and optimize the use of open source technologies. With a team of experienced, certified consultants, and proprietary Kubernetes methodologies, Shadow-Soft is the partner of choice for companies looking to leverage their legacy infrastructures and applications to Make Optimal Possible©.

**Media Contact**

Ross Beard  
Shadow-Soft  
+1 678-842-8715  
rbeard@shadow-soft.com

Share: [linkedin-in icon](http://www.linkedin.com/shareArticle?mini=true&url=https://shadow-soft.com/content/4cs-framework-addresses-technology-attacks-and-vulnerabilities) [twitter icon](https://twitter.com/intent/tweet?url=https://shadow-soft.com/content/4cs-framework-addresses-technology-attacks-and-vulnerabilities) [envelope icon](mailto:?body=https://shadow-soft.com/content/4cs-framework-addresses-technology-attacks-and-vulnerabilities)

## Is Your Platform Ready for What's Next?

Get unfiltered perspectives on modern platforms, automation, and observability. The Platform Pulse newsletter delivers actionable insights to help you build with confidence.

[Get the insights](https://shadow-soft.com/content/4cs-framework-addresses-technology-attacks-and-vulnerabilities#popform_hero)

### Subscribe to Platform Pulse

 One email per month. Unfiltered perspectives on modern platforms, automation, and observability.

[![](https://shadow-soft.com/hs-fs/hubfs/Shadow-Soft-Logo-1.png?width=1878&height=431&name=Shadow-Soft-Logo-1.png)](https://shadow-soft.com)

Shadow-Soft is a Red Hat Specialized Partner and Dynatrace Premier Partner helping mid-to-large enterprises modernize infrastructure through Kubernetes platforms, VMware to OpenShift Virtualization migrations, infrastructure automation, and observability solutions. Headquartered in Atlanta and serving enterprises nationwide.

**Address:** 4501 North Point Pkwy, Suite 110

Alpharetta, GA 30022 USA

🔔 [Subscribe to Platform Pulse Newsletter](https://shadow-soft.com/platform-pulse)

[linkedin-in icon](https://www.linkedin.com/company/shadow-soft/) [Follow us on Facebook](https://www.youtube.com/c/Shadow-soft)

**Company**

<https://shadow-soft.com/about>

 

[About](https://shadow-soft.com/about)

[Contact](https://shadow-soft.com/contact)

[Careers](https://shadow-soft.com/careers)

[Content Hub](https://shadow-soft.com/content-hub)

[Case Studies](https://shadow-soft.com/client-stories)

[Icinga Support](https://shadow-soft.com/icinga)

[Privacy Policy](https://shadow-soft.com/privacy)

**Services**

<https://shadow-soft.com/solutions/it-automation>

[VMware to OpenShift Migration](https://shadow-soft.com/solutions/vmware-red-hat-openshift-virtualization-migration)

[Red Hat Consulting](https://shadow-soft.com/expertise/red-hat)<https://shadow-soft.com/solutions/it-automation><https://shadow-soft.com/expertise/ansible><https://shadow-soft.com/expertise/openshift>

[OpenShift Consulting](https://shadow-soft.com/expertise/openshift)<https://shadow-soft.com/expertise/ansible>

[Kubernetes Consulting](https://shadow-soft.com/expertise/kubernetes)

[Ansible Consulting](https://shadow-soft.com/expertise/ansible)

[Observability Consulting](https://shadow-soft.com/expertise/observability-monitoring)

[Dynatrace Consulting](https://shadow-soft.com/expertise/dynatrace)

[HashiCorp Terraform Consulting](https://shadow-soft.com/hashicorp-terraform-consulting)

**Solutions**

<https://shadow-soft.com/solutions/it-automation>

<https://shadow-soft.com/solutions/it-automation>[VMware Alternative](https://shadow-soft.com/solutions/vmware-migration-program)  
<https://shadow-soft.com/expertise/ansible>

[Automate IT Operations](https://shadow-soft.com/solutions/it-operations-automation-program)

[Unified Observability](https://shadow-soft.com/solutions/unified-observability-program)

 

**Workshops**

[VMware Migration Workshop](https://shadow-soft.com/vmware-migration-workshop)

[Observability Workshop](https://shadow-soft.com/observability-tool-sprawl-assessment)

[Automation Strategy Workshop](https://shadow-soft.com/automation-strategy-workshop)

 

Copyright © 2026, Shadow-Soft

![](https://www.facebook.com/tr?id=433738280336898&ev=PageView&noscript=1)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Shadow-Soft Team",
    "url" : "https://shadow-soft.com/content/author/shadow-soft-team"
  },
  "dateModified" : "2024-08-28T15:38:21.209Z",
  "datePublished" : "2023-05-02T13:42:00.000Z",
  "headline" : "Shadow-Soft 4C’s Framework Addresses Technology Attacks and Vulnerabilities",
  "image" : [ "https://shadow-soft.com/hubfs/Imported_Blog_Media/cropped-shadow-soft-logo-linkedin.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://shadow-soft.com/content/4cs-framework-addresses-technology-attacks-and-vulnerabilities",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://shadow-soft.com/hubfs/Shadow-Soft-Logo-1.png"
    }
  }
}
```