Skip to content
All services
Cloud foundations & networkingAssess

Cloud foundation check

In 1–2 weeks, we review your AWS, Azure or Google Cloud foundation against the CIS benchmark and tie every finding to evidence, the affected resources and a fix.

When you need it

Your cloud grew faster than its guardrails. Nobody can say for sure who has admin access, what is exposed to the internet or whether logging would catch an incident, and every audit or customer security questionnaire turns into a scramble.

What sets the quote

  • One cloud per check: AWS, Microsoft Azure or Google Cloud.
  • Sized from a free read-only inventory query you run (AWS Resource Explorer, Azure Resource Graph or Google Cloud Asset Inventory); you send us only the counts.
  • One week: up to 500 resources, 10 workloads reviewed in depth, 2 regions and 10 networks (VPCs or VNets) without hybrid links.
  • Two weeks: up to 2,000 resources, 30 workloads, 4 regions and 30 networks, including VPN, Direct Connect, ExpressRoute or Cloud Interconnect links, plus a cost review.
  • Larger estates, or more than one cloud, are quoted after the sizing query.

What changes

  • You know your ten biggest risks and what fixing each one takes.
  • Every finding comes with evidence, so your team can act without investigating again.
  • You have a 90-day plan ordered by risk and effort, ready for your backlog.

What you get

  • CIS benchmark results for your cloud (CIS AWS Foundations, CIS Microsoft Azure Foundations or CIS Google Cloud Platform Foundation), pass or fail per control
  • Findings report with severity, affected resources, evidence, business impact and the fix
  • One-page summary of the ten biggest risks for management
  • 90-day roadmap ordered by risk and effort
  • All findings as a CSV file for your ticket system
  • A 90-minute readout with your team

What we cover on each cloud

AreaAWSAzureGoogle Cloud
Organisation and guardrailsOU structure, SCPs and RCPs, Control Tower where used, delegated administratorsManagement group hierarchy, Azure Policy assignments, subscription placementFolder hierarchy, Organization Policy constraints, project placement
Identity and accessIAM Identity Center, IAM users and access keys, admin roles, cross-account trustEntra roles and PIM, Azure RBAC at every scope, service principals, managed identitiesIAM bindings at organisation, folder and project level, service accounts and keys, workload identity
NetworkSecurity groups, Transit Gateway, VPC endpoints, public exposure, egressNetwork security groups, Azure Firewall or Virtual WAN, private endpoints, public IPsFirewall policies, Shared VPC, Cloud NAT, Private Service Connect, external IPs
Logging and detectionCloudTrail, AWS Config, GuardDuty and Security Hub coverageActivity log, diagnostic settings, Defender for Cloud plansCloud Audit Logs, log sinks, Security Command Center
Data protectionS3 public access, KMS keys, encryption, backupsStorage access, Key Vault, encryption, backupsBucket access, Cloud KMS, encryption, backups
Change controlTerraform or CloudFormation, pipelines, driftTerraform or Bicep, pipelines, driftTerraform, pipelines, drift

See what you get: a sample report for a fictional company.

Not included

  • Fixing the findings (quoted separately, often as a landing zone or guardrails package)
  • Penetration testing (we can refer you to a certified partner)
  • Application code review
  • Compliance certification or audit opinions

What we need from you

  • AWS: read-only access with the SecurityAudit and ViewOnlyAccess policies across the organisation.
  • Azure: Reader and Security Reader at the root management group, plus the Entra Global Reader role.
  • Google Cloud: Viewer and Security Reviewer at organisation level.
  • Two 60-minute interviews: your platform owner and your security owner.

How it works

  1. Free 30-minute call, then the sizing query and a written fixed quote.

  2. Automated benchmark scan plus manual review of identity, network, logging and change control.

  3. Interviews to confirm context and priorities.

  4. Report, roadmap and a 90-minute readout.

At a glance

Duration
1–2 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Assess

Zero Trust network review

A one-week review of how traffic enters, leaves and crosses your AWS, Azure or Google Cloud networks, with evidence for every finding, a target Zero Trust design and a prioritised roadmap.

Duration:1–2 weeks
Assess

Migration check

In 1–2 weeks, we assess what you run on-premises or in another cloud, with a migration approach per application, a wave plan and a cost estimate for AWS, Azure or Google Cloud.

Duration:1–2 weeks
Assess

Cloud cost quick wins

Lower your AWS, Azure or Google Cloud bill in one to two weeks by changing how the platform is built, from NAT and data transfer paths to commitments, with the quick wins delivered as code.

Duration:1–2 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.