Assessment
Cloud Security
Configuration review for AWS, Azure, and Google Cloud environments.
The majority of cloud security incidents trace back to configuration rather than platform vulnerabilities. Storage left publicly readable, over-permissive identity roles, management interfaces exposed to the internet, logging switched off or never reviewed. A cloud security review looks for exactly these.
What a cloud review examines
A review works through your cloud environment against the provider's own best-practice framework and general hardening standards. Typical areas: identity and access management, including over-privileged roles and long-lived credentials; network configuration and what is reachable from the internet; storage permissions and encryption; secrets handling; logging and audit trail coverage; and, where relevant, container and Kubernetes configuration. Multi-account and multi-subscription estates get particular attention, since drift between environments is common — production is hardened, a forgotten development account is not. The output should map findings to specific resources and give the configuration change needed, not just name the category of problem. 'Over-permissive IAM' is not actionable. 'This role grants full administrative access and is attached to a service that needs read access to one bucket' is.
Who needs it
- Teams that migrated to cloud quickly and never went back to review the configuration
- Organisations running multiple cloud accounts or subscriptions with inconsistent standards
- Companies asked to evidence cloud security controls during customer due diligence
- Engineering teams where infrastructure has grown organically without a security review
What you get
Platform-appropriate matching
AWS, Azure, and Google Cloud have materially different security models. We match on the platform you actually run.
Scoped access arrangements
Clarity upfront on what read-only access the reviewer needs, so the engagement is not delayed at the start.
Findings tied to resources
Proposals specify whether output identifies specific resources and remediation steps, rather than generic categories.
Frequently asked questions
Is a cloud security review the same as a penetration test?
No. A review is a configuration assessment, usually performed with read-only access to your cloud account — it examines how things are set up. A penetration test attempts active exploitation from the outside. For cloud environments the review typically finds more, faster, because most cloud exposure is misconfiguration rather than exploitable software flaws.
What access does the reviewer need?
Normally a read-only role scoped to the accounts in question — a security auditor role in AWS, a reader role in Azure, or equivalent. No write access is required for a standard configuration review. Agree and provision this before the engagement starts.
Do the cloud providers' own tools cover this?
Partly. AWS Security Hub, Azure Defender for Cloud, and Google Security Command Center will flag many issues and are worth enabling. What they do not do is prioritise findings against your specific business context, or catch design-level problems like an architecture that requires over-permissive access to function.
We use a managed service provider. Is that covered?
It is worth checking rather than assuming. Managed service contracts vary widely in what security responsibility they actually accept, and the boundary between provider responsibility and yours is often less clear than either party assumes. An independent review makes the gap visible.