Assurance & compliance

Cloud Security

A review of how your cloud is actually configured, against how it should be. We look at identity and permissions first — that is where the compromise usually starts — then network exposure, data storage, logging and the infrastructure-as-code that produces all of it. Findings come with the specific change to make, not a link to a benchmark.

At a glance

Timeline

Two to four weeks for a typical estate. Multi-account organisations take longer to enumerate than to assess, so the number of accounts drives the calendar more than their size.

You get

  • A full inventory across every account, subscription and region
  • Identity findings, including every privilege-escalation path we found
  • Public exposure review of storage, network and management planes
Who needs this

If any of these is your week, this is the service.

Permissions were granted quickly and never revisited

Something did not work, someone widened a policy to unblock it, and that policy is still there two years later.

What we do

An identity and permissions review that finds over-privilege, unused credentials and every path to privilege escalation.

You are not sure what is publicly reachable

Buckets, databases and management interfaces get exposed by a default nobody read, and stay exposed until someone looks.

What we do

A full exposure review across every account and region, including the ones nobody remembers creating.

You migrated and kept the on-prem mental model

A perimeter design ported to a cloud where identity is the perimeter leaves controls that protect nothing.

What we do

An architecture review against how the platform actually enforces things, not how the old data centre did.

Your infrastructure is code and nobody reviews it for security

A misconfiguration in a module is not one mistake — it is every environment that module builds.

What we do

Review of the Terraform or CloudFormation itself, so the fix lands at the source instead of drifting back.

How it works

Every step, and what leaves our hands at the end of it.

  1. 01

    Enumerate

    Read-only access across every account, subscription and project — including the ones outside the main organisation.

    → Account & resource inventory

  2. 02

    Identity review

    Roles, policies, trust relationships, keys and federation. Over-privilege and escalation paths, worked as an attacker would.

    → Identity findings & escalation paths

  3. 03

    Exposure review

    Network reachability, public storage, management planes and anything answering the internet that should not be.

  4. 04

    Data & logging

    Encryption at rest and in transit, key management, backup integrity, and whether your logs would survive an incident.

  5. 05

    Infrastructure as code

    The templates and modules that generate the estate, so a fix lands at the source rather than drifting back next deploy.

  6. 06

    Report & remediate

    Findings with the exact configuration change for each, sequenced so the highest-risk ones can ship first.

    → Report + prioritised fixes

What you get

Deliverables.

  • A full inventory across every account, subscription and region
  • Identity findings, including every privilege-escalation path we found
  • Public exposure review of storage, network and management planes
  • Encryption, key management and logging assessment
  • Infrastructure-as-code findings, so fixes land at the source
  • The specific configuration change for each finding, ranked by risk
What we need

Before we can quote.

  • 01Read-only access across every account, subscription or project
  • 02Which providers and regions are in use, including any you inherited
  • 03Repository access if you want the infrastructure-as-code reviewed
  • 04Your architecture documentation and data-flow diagrams, if they exist
  • 05Any compliance framework the environment has to satisfy

Do not worry about having all of it. Send what you have and we will work out the rest on the scoping call.

Questions

Cloud Security, answered.

Do you need write access?

No. Read-only throughout. We report the change to make; you make it, through your own change process.

We already run a cloud posture tool. Why this?

A posture tool tells you a setting differs from a benchmark. It cannot tell you that three medium findings chain into a path from a public endpoint to your production database. Chaining is the part that needs a person.

Can you cover more than one provider?

Yes, and cross-provider trust relationships get specific attention — federation between clouds is a common gap because each side assumes the other is enforcing something.

Next step

Scope a Cloud Security.

Cloud Security is already selected below. Tell us what you are trying to protect and what is driving the timing — if a different service fits better, we will say so rather than sell you this one.

Scope a Cloud Security1 business day

By submitting you agree to be contacted about your enquiry. We never share your details.