Cloud Security Assessment
Configuration review for AWS, Azure, and GCP against CIS Benchmarks and cloud provider best practices — the misconfigurations that cause most cloud breaches, not exotic zero-days.

What We Review
IAM Policy Review
Overly permissive roles, unused privileged accounts, and missing MFA on privileged access.
Storage Exposure
Public S3 buckets, Azure Blob containers, and GCS buckets with unintended public access.
Network Configuration
Security groups, NSGs, and VPC/VNet design for unintended internet exposure.
Logging & Monitoring
CloudTrail, Azure Monitor, and GCP Cloud Audit Logs coverage and alerting gaps.
Secrets Management
Hardcoded credentials in code, environment variables, or configuration versus a secrets manager.
Container & Kubernetes
Cluster RBAC, exposed dashboards, image scanning, and pod security policy gaps.
Serverless Functions
Over-privileged execution roles and insecure environment variable handling.
CIS Benchmark Alignment
Scored against the relevant CIS Foundations Benchmark for your provider.
Data Encryption
Encryption at rest and in transit for databases, storage, and inter-service traffic.
Read-Only, No Production Risk
Configuration review
We request a read-only IAM role scoped to your account or subscription. This is a configuration audit, not exploitation against live infrastructure, so there's no risk to uptime or billing.
Optional live testing
Where useful, we combine this with active network testing of anything internet-facing — see Network Penetration Testing.
Cloud Assessment Questions
What access do you need?
A read-only IAM role or security-audit role scoped to the account(s) in scope. We provide the exact policy JSON during scoping.
Will this affect our cloud bill or production workloads?
No — configuration review is read-only against the control plane and has no impact on running workloads or cost.
Do you support multi-cloud environments?
Yes — AWS, Azure, and GCP can be assessed together in one engagement if your environment spans more than one provider.
Ready to Review Your Cloud Environment?
Tell us your provider and we'll scope the right engagement.