When you need it
Your cloud grew faster than its guardrails. Nobody can say for sure who has admin access, what is exposed to the internet or whether logging would catch an incident, and every audit or customer security questionnaire turns into a scramble.
What sets the quote
- One cloud per check: AWS, Microsoft Azure or Google Cloud.
- Sized from a free read-only inventory query you run (AWS Resource Explorer, Azure Resource Graph or Google Cloud Asset Inventory); you send us only the counts.
- One week: up to 500 resources, 10 workloads reviewed in depth, 2 regions and 10 networks (VPCs or VNets) without hybrid links.
- Two weeks: up to 2,000 resources, 30 workloads, 4 regions and 30 networks, including VPN, Direct Connect, ExpressRoute or Cloud Interconnect links, plus a cost review.
- Larger estates, or more than one cloud, are quoted after the sizing query.
What changes
- You know your ten biggest risks and what fixing each one takes.
- Every finding comes with evidence, so your team can act without investigating again.
- You have a 90-day plan ordered by risk and effort, ready for your backlog.
What you get
- CIS benchmark results for your cloud (CIS AWS Foundations, CIS Microsoft Azure Foundations or CIS Google Cloud Platform Foundation), pass or fail per control
- Findings report with severity, affected resources, evidence, business impact and the fix
- One-page summary of the ten biggest risks for management
- 90-day roadmap ordered by risk and effort
- All findings as a CSV file for your ticket system
- A 90-minute readout with your team
What we cover on each cloud
| Area | AWS | Azure | Google Cloud |
|---|---|---|---|
| Organisation and guardrails | OU structure, SCPs and RCPs, Control Tower where used, delegated administrators | Management group hierarchy, Azure Policy assignments, subscription placement | Folder hierarchy, Organization Policy constraints, project placement |
| Identity and access | IAM Identity Center, IAM users and access keys, admin roles, cross-account trust | Entra roles and PIM, Azure RBAC at every scope, service principals, managed identities | IAM bindings at organisation, folder and project level, service accounts and keys, workload identity |
| Network | Security groups, Transit Gateway, VPC endpoints, public exposure, egress | Network security groups, Azure Firewall or Virtual WAN, private endpoints, public IPs | Firewall policies, Shared VPC, Cloud NAT, Private Service Connect, external IPs |
| Logging and detection | CloudTrail, AWS Config, GuardDuty and Security Hub coverage | Activity log, diagnostic settings, Defender for Cloud plans | Cloud Audit Logs, log sinks, Security Command Center |
| Data protection | S3 public access, KMS keys, encryption, backups | Storage access, Key Vault, encryption, backups | Bucket access, Cloud KMS, encryption, backups |
| Change control | Terraform or CloudFormation, pipelines, drift | Terraform or Bicep, pipelines, drift | Terraform, pipelines, drift |
See what you get: a sample report for a fictional company.
Not included
- Fixing the findings (quoted separately, often as a landing zone or guardrails package)
- Penetration testing (we can refer you to a certified partner)
- Application code review
- Compliance certification or audit opinions
What we need from you
- AWS: read-only access with the SecurityAudit and ViewOnlyAccess policies across the organisation.
- Azure: Reader and Security Reader at the root management group, plus the Entra Global Reader role.
- Google Cloud: Viewer and Security Reviewer at organisation level.
- Two 60-minute interviews: your platform owner and your security owner.
How it works
Free 30-minute call, then the sizing query and a written fixed quote.
Automated benchmark scan plus manual review of identity, network, logging and change control.
Interviews to confirm context and priorities.
Report, roadmap and a 90-minute readout.
At a glance
- Duration
- 1–2 weeks
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect
Related services
Zero Trust network review
A one-week review of how traffic enters, leaves and crosses your AWS, Azure or Google Cloud networks, with evidence for every finding, a target Zero Trust design and a prioritised roadmap.
Migration check
In 1–2 weeks, we assess what you run on-premises or in another cloud, with a migration approach per application, a wave plan and a cost estimate for AWS, Azure or Google Cloud.
Cloud cost quick wins
Lower your AWS, Azure or Google Cloud bill in one to two weeks by changing how the platform is built, from NAT and data transfer paths to commitments, with the quick wins delivered as code.