Cloud Security
Assessment and continuous monitoring of AWS, Azure, GCP and hybrid estates, focused on the misconfigurations that actually lead to compromise.
What you receive
- Configuration review against CIS benchmarks
- Identity and privilege-path analysis
- Continuous drift detection
When you need this
Three situations that call for it. If none of them is yours, it probably is not the right spend.
Nobody can say who can reach production
In cloud the perimeter is identity, and the dangerous path is usually a chain: a build principal that can assume a role, that can pass a second role, that can read the data. Answering that needs the graph of who can become whom, not a user list.
The estate grew faster than anyone mapped it
Accounts and subscriptions get created per team, per project and per acquisition, each with its own logging settings and its own idea of a default. The first useful output is which ones exist, who pays for them, and which have no owner at all.
The running estate no longer matches the code
Someone fixed an outage in the console and the template was never updated, so the next apply either reverts the fix or makes the drift permanent. Reviewing templates alone tests intent; the assessment has to read what is actually running too.
How it runs
Scoping call
Thirty minutes with an engineer, not a sales development rep. We establish what you actually need and tell you plainly if it is not us.
Written proposal
Fixed scope, fixed price, named delivery team, and the rules of engagement in writing before anyone touches a system.
Delivery
Weekly written status and a direct channel to the delivery lead. Critical findings are escalated the moment they are confirmed, never held back for the report.
Readout and retest
A working session with your team, an executive summary for your board, and a remediation retest included in the original scope rather than quoted separately.
No lock-in
Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.
Who turns up
The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.
Scope
What this does not cover
This covers the cloud control plane and its configuration, not the applications running on it — that testing is Application Security.
We assess and report. We do not take administrative ownership of your accounts or make changes in your tenancy on our own initiative.
SaaS you consume but do not host sits outside this scope, apart from the identity federation that connects it back to your estate.
- CIS AWS Foundations Benchmark
- A prescriptive configuration baseline for the account itself — logging, identity, storage defaults — not for what runs inside it.
- ISO/IEC 27017:2015
- Cloud-specific implementation guidance based on ISO/IEC 27002, written separately for cloud service providers and cloud service customers, with additional controls that apply only in the cloud case.
If the scope is wrong
Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.
Questions
The ones we are actually asked.
Is a CIS benchmark score a useful measure of risk?
It is a consistent baseline and auditors accept it, which is worth something. It also weights a publicly readable bucket the same as a log-retention setting, so the percentage moves for reasons unrelated to your actual exposure.
Our provider says they handle security. Is that wrong?
They secure the infrastructure underneath, and generally they do it well. What stays with you is identity policy, network exposure, key management and what you choose to expose — which is the side of the line this work is about.
Can you assess a hybrid estate, or only public cloud?
Hybrid is the usual case, and the join is where the interesting failures are. A directory federated into a cloud tenancy means a compromise on one side is a compromise on the other, so trust is assessed in both directions.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.