Skip to content
All services
Security hardening & assuranceAssess

Zero Trust assessment

In 1–2 weeks, a review of identity for people, devices and workloads, cloud guardrails and CI/CD, with every control checked as declared, refused and in effect, ending in a maturity rating per area and a roadmap.

When you need it

You have MFA, cloud policies and a CI pipeline, but nobody can say which controls actually hold. Some policies still only report problems instead of blocking them, and when a customer, auditor or board asks how you apply Zero Trust, the answer is a guess.

What sets the quote

  • Covers the whole organisation: identity for people, devices and workloads, cloud guardrails and CI/CD.
  • Sized from counts you send us (identity providers, privileged identities, device management tools, clouds and CI pipelines), plus a free read-only inventory query for the cloud side (AWS Resource Explorer, Azure Resource Graph or Google Cloud Asset Inventory).
  • One week: one identity provider, one device management tool, one cloud, up to 50 privileged identities and one CI platform with up to 10 pipelines tested in depth.
  • Two weeks: up to 2 identity providers, 2 clouds, 150 privileged identities and 2 CI platforms with up to 25 pipelines tested in depth.
  • Larger or more mixed estates are quoted after sizing.

What changes

  • You know which controls exist only on paper and which ones the platform actually enforces.
  • Each area has a maturity rating backed by test results, so progress can be measured at the next review.
  • Gaps are ranked by risk and effort in a roadmap your team can start on straight away.
  • You can answer customer and auditor questions about Zero Trust with evidence, not promises.

What you get

  • Control matrix showing, for every control, whether it is declared, refused and in effect, with the evidence
  • Test log of every non-compliant change or sign-in we tried, and whether the platform blocked it
  • Maturity rating for each area (people, devices, workloads, guardrails and CI/CD)
  • Findings mapped to the NIST SP 800-207 tenets, the CIS benchmark for your cloud and the OWASP Top 10 CI/CD Security Risks
  • Roadmap ordered by risk and effort, from quick fixes to larger changes
  • All findings as a CSV file for your ticket system
  • A 90-minute readout with your technical and business leads

What we cover on each cloud

AreaAWSAzureGoogle Cloud
Identity for peopleIAM Identity Center, root user, IAM usersEntra ID, Conditional Access, PIMCloud Identity or workforce identity federation, super administrators
Workload identityIAM roles, access keys, OIDC roles for CI/CDManaged identities, service principals, workload identity federationService accounts, service account keys, workload identity federation
GuardrailsSCPs and RCPsAzure PolicyOrganization Policy
Example refusal testCreating an IAM user or access key is denied by an SCPCreating a public IP address is denied by Azure PolicyCreating a service account key is denied by Organization Policy

Devices and CI/CD are tested the same way on every cloud, for example with a sign-in from an unmanaged device or a merge to the main branch without review.

Not included

  • Fixing the gaps (quoted separately, often as a guardrails, identity or secure CI/CD package)
  • Penetration testing (we can refer you to a certified partner)
  • An in-depth network segmentation review (a separate package)
  • Compliance certification or audit opinions

What we need from you

  • AWS: read-only access with the SecurityAudit and ViewOnlyAccess policies across the organisation.
  • Azure: Reader and Security Reader at the root management group, plus the Entra Global Reader role, which also gives read-only access to Intune.
  • Google Cloud: Viewer and Security Reviewer at organisation level.
  • Read-only access to your IaC repositories, CI/CD settings and any other identity provider in scope. A sandbox account, subscription or project under the same guardrails, where a test identity may try changes that should be refused.
  • Two 60-minute interviews: your identity or IT owner and your platform or security owner.

How it works

  1. Free 30-minute call, then the sizing counts and a written fixed quote.

  2. Declared: read the IaC, guardrails, Conditional Access policies and pipeline settings.

  3. Refused: try non-compliant changes and sign-ins in the sandbox and record what the platform blocks.

  4. In effect: check the live estate for drift, exemptions and report-only settings, and confirm context in the interviews.

  5. Maturity ratings, roadmap and a 90-minute readout.

At a glance

Duration
1–2 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Assess

Threat modelling workshop

A STRIDE threat model of one system or major feature, built with your team in two half-day sessions over one to two weeks, with a data-flow diagram, trust boundaries and prioritised mitigations in your backlog.

Duration:1–2 weeks
Build Popular

OS hardening baseline

Linux and Windows Server hardened to CIS Benchmarks Level 1 in two to six weeks, built as code with golden images, enforced settings, drift checks and compliance evidence for every host.

Duration:2–6 weeks
Build

Vulnerability management setup

Scanning for hosts, containers, Kubernetes, serverless functions and code dependencies, with triage rules, fix deadlines by severity, ticket integration and a weekly report, set up in two to five weeks.

Duration:2–5 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.