Cloud Configuration Review
Quoted on scope, fixed price.
Teams who have had us test their systems
What this covers
Cloud is easy to misconfigure and hard to audit. One over-permissioned IAM role, one storage bucket left public, one security group opened for a migration and never closed - each is a single setting, and none of them announces itself. This is a configuration review, not a penetration test. We take read-only access, run the CIS Benchmark for your provider, and then read the results ourselves: IAM roles, users, policies and service accounts; storage buckets, disks and databases; compute, containers and serverless; networking and CDN; logging and detection coverage. Nothing is exploited and nothing is changed - the whole engagement is observation. The value is not the scan, which you could run yourself. It is the pass afterwards: which failures matter in your accounts, which are deliberate and should be recorded as accepted, what to fix this week against what can wait, and the exact Terraform or CloudFormation change for each one. You get a benchmark score per service, a list of every publicly reachable resource, and a remediation plan in the order your platform team should work through it.
- Know exactly which S3 buckets, storage accounts, and disks are publicly accessible
- Lock down IAM so a single compromised key doesn't give away the kingdom
- Pass cloud security requirements in enterprise and compliance audits
- Stop paying for security tools you configured but forgot to turn on
Scope
What gets reviewed
Ten areas, agreed on the scoping call and written into the rules of engagement before anything starts.
IAM & Identity
Role and policy review, over-broad permissions, unused credentials, MFA enforcement, cross-account trust policies.
Storage & Databases
S3/Blob/GCS public access audit, RDS/Cosmos/Cloud SQL exposure, encryption, backup policies, data lifecycle.
Compute & Serverless
EC2/VM security groups, Lambda IAM roles, ECS/EKS/AKS/GKE configuration, image registry settings, host hardening options.
Networking & CDN
VPC/VNet security groups, public IP enumeration, load balancer config, CDN/WAF rules, DDoS protection.
Kubernetes & Containers
Pod security policies, network policies, RBAC audit, secrets management, image registry security, admission control.
Logging & Detection
CloudTrail/Audit Logs coverage, GuardDuty/Security Center, alerting rules, compliance alignment.
Azure Security Stack
Firewall, WAF, Log Analytics, Sentinel and Defender for Cloud - whether each is switched on, and whether its rules cover what you assume.
GitHub Security
Repository access, branch protection, secret scanning, Dependabot, CodeQL, Actions workflows, CI/CD hardening.
Entra ID / Azure AD
Global admin audit, Conditional Access, MFA enforcement, legacy auth, OAuth app permissions, identity risk detection.
CIS Benchmarks
The full benchmark for your provider, scored per service, with every failure triaged by hand before it reaches you.
Methodology
How the work is done
Repeatable, documented, and recorded step by step so you can see what has been looked at.
- 01
Read-only access
A reader role in each account - nothing that can change a setting. We inventory resources across every region and subscription, so the review covers what is actually deployed rather than what the diagram says.
- 02
Benchmark run
The CIS Benchmark for your provider, run across the estate. This part is automated, and we tell you which tool produced which result so nothing is presented as hand-checked when it was not.
- 03
Manual pass
A reviewer reads every result. False positives are removed, deliberate exceptions are recorded as accepted with your reason, and what is left is ordered by what it would mean here rather than by the rule’s default severity.
- 04
Report and walkthrough
Findings, the benchmark score per service, and the Terraform or CloudFormation change for each one - then a call to walk your platform team through it. A re-review after you have made the changes is included.
Why it matters
What you get out of it
IAM Deep-Dive
Every role, policy, user and service account read for excessive permissions, unused credentials, missing MFA and over-broad trust policies.
Storage & Data Exposure
S3 bucket/Blob/GCS public access audit, database exposure checking, encryption-at-rest verification, and backup configuration review.
Compute & Container Security
EC2/VM hardening settings, Lambda and Function permissions, ECS/EKS/AKS/GKE configuration, privileged containers and image registry settings.
Network Configuration
Security group/NSG/firewall rule audit, VPC/VNet peering review, public IP enumeration, CDN/WAF configuration, and DDoS protection validation.
Logging & Detection Gaps
CloudTrail/Azure Monitor/Cloud Audit Logs coverage review, guard duty/security center configuration, and alerting rule validation.
Infrastructure-as-Code Fixes
Every finding includes a Terraform/CloudFormation/Pulumi code snippet to fix it. We work in your IaC language, not ours.
What you receive
Delivered as documents at the end of the engagement, with a call to walk your team through them.
- Configuration findings report - each finding with the setting, why it matters here, and what to change
- CIS Benchmark score - per service and per account, with the gaps listed
- Public exposure summary - every publicly reachable storage, compute and database resource
- IAM permission review - roles, users, service accounts and what each one can currently do
- IaC fix snippets - Terraform, CloudFormation or Pulumi, in the language you already use
- Drift summary - where the deployed configuration no longer matches your IaC
- Re-review report - the same benchmark run again after your changes
Standards we review against
Coverage is recorded against these control by control, so “what did you actually check” has an answer.
- CIS AWS Foundations Benchmark
- CIS Azure Foundations Benchmark
- CIS Google Cloud Foundation Benchmark
- CIS Kubernetes Benchmark
Pricing
What changes the price
Every engagement is quoted on scope rather than hours. These are the four things that move it, and they are what we work through on the call.
Accounts
Subscriptions or projects
Services
What is actually running
Identity
Roles and principals
Pipelines
CI/CD in scope or not
FAQ
Questions about cloud configuration review
Do you need admin access to our cloud environment?
No. We work with read-only access - typically a read-only IAM role, Storage Account Reader, or GCP Viewer. We never need write access to assess your configuration. If you want us to also validate that fixes have been applied, we'll need the same read-only access again for the re-assessment.
How is this different from running AWS Inspector or Azure Security Center?
It is not a different scan - we run the same class of tool, and you could too. The difference is what happens to the output. Built-in tools produce hundreds of findings with one severity per rule, the same severity whether the bucket holds marketing images or customer records. We validate each one by hand, remove the false positives, record the deliberate exceptions as accepted with your reason, and hand back a shorter list in the order it should be worked through - with the Terraform change for each. The two are complementary: the built-in tools are continuous and broad, this is point-in-time and considered.
We're multi-cloud (AWS + Azure) - can you review both in one engagement?
Yes, and the benchmark is run against each. We also compare the two configurations where they meet - a trust policy in AWS that names an Entra ID app registration, for example - because those relationships are set up once and rarely looked at again.
Do you review our Kubernetes clusters too?
Yes, and it is in scope by default. We check pod security policies, network policies, RBAC, secrets management (do you have secrets in ConfigMaps?), image registry security, admission control, and whether containers run as root. EKS, AKS, GKE, and self-managed - we cover all of them.
What if we use infrastructure-as-code (Terraform, Pulumi, CDK)?
That makes our job easier - and yours. We review your IaC templates as part of the assessment and provide fix snippets in the same language you use. We also check whether your deployed infrastructure matches your IaC definitions - drift detection is a common source of security gaps.
How often should we reassess our cloud security?
Cloud environments change daily - new services spun up, IAM policies updated, security groups modified. We recommend a formal assessment at least annually, with quarterly health checks for fast-moving teams. An annual programme can include quarterly re-assessments, with each one exported against the framework you report into so the change between them is visible.
Scope your cloud configuration review engagement.
Thirty minutes on a call and you have a fixed price, a start date and a clear picture of what the cloud configuration review will cover.





