Skip to content
All services
Cloud foundations & networkingAssess

Zero Trust network review

A one-week review of how traffic enters, leaves and crosses your AWS, Azure or Google Cloud networks, with evidence for every finding, a target Zero Trust design and a prioritised roadmap.

When you need it

Your cloud network grew one peering, one public IP and one firewall rule at a time. Nobody can draw how traffic leaves the estate, which services answer from the internet or how far an attacker could get from one compromised workload.

What sets the quote

  • One cloud per review: AWS, Microsoft Azure or Google Cloud.
  • Sized from a free read-only inventory query you run (AWS Resource Explorer, Azure Resource Graph or Google Cloud Asset Inventory); you send us only the counts.
  • One week covers up to 25 networks (VPCs, VNets or VPC networks) in up to 2 regions, with up to 2 hybrid links (site-to-site VPN, Direct Connect, ExpressRoute or Cloud Interconnect).
  • Two clouds, or a larger estate, take two weeks and are quoted after the sizing query.

What changes

  • You know every path into, out of and between your networks, and which ones nobody meant to allow.
  • Every finding comes with evidence, so your team can fix it without investigating again.
  • You have a target design and a roadmap ordered by risk and effort, ready for your backlog.

What you get

  • Map of today's traffic paths (in from the internet, out to the internet, between networks and to on-premises), built from routes, rules and flow logs
  • Findings report mapped to NIST SP 800-207 principles, with severity, affected networks, evidence and the fix for each finding
  • Target Zero Trust network design with a diagram of the hub, spokes, private endpoints, DNS, egress inspection and segmentation
  • Prioritised roadmap, ordered by risk and effort and sequenced so running workloads stay up
  • All findings as a CSV file for your ticket system
  • A 90-minute readout with your network and security owners

What we cover on each cloud

AreaAWSAzureGoogle Cloud
Hub and transitTransit GatewayVirtual WAN or hub VNetNetwork Connectivity Center or Shared VPC
Private endpointsInterface VPC endpointsPrivate EndpointsPrivate Service Connect
Private DNSRoute 53 Resolver and private hosted zonesAzure Private DNS and DNS Private ResolverCloud DNS private zones
Egress and inspectionNAT gateway and AWS Network FirewallAzure FirewallCloud NAT, Cloud NGFW and Secure Web Proxy
SegmentationSecurity groups and network ACLsNetwork security groups and application security groupsFirewall policies
Hybrid linksSite-to-Site VPN and Direct ConnectVPN Gateway and ExpressRouteCloud VPN and Cloud Interconnect
Flow logsVPC Flow LogsVNet flow logsVPC Flow Logs

Not included

  • Building the target design (quoted separately as a Zero Trust network build)
  • On-premises networks and devices; we review the cloud side of each hybrid link
  • Identity, device and application security reviews
  • Penetration testing (we can refer you to a certified partner)

What we need from you

  • AWS: read-only access with the SecurityAudit and ViewOnlyAccess policies across the organisation, plus read access to wherever VPC Flow Logs are stored.
  • Azure: Reader and Security Reader at the root management group, plus Storage Blob Data Reader on the storage accounts that hold VNet flow logs.
  • Google Cloud: Viewer and Compute Network Viewer at organisation level, plus Logs Viewer where VPC Flow Logs are stored.
  • Flow logs switched on at least a week before we start, and any network diagrams and IP address plan you already have.
  • Two 60-minute interviews: your network owner and your security owner.

How it works

  1. Free 30-minute call, then the sizing query and a written fixed quote.

  2. Collect routes, rules, endpoints, DNS settings and flow logs, then trace every path in and out.

  3. Interviews to confirm which paths are intended.

  4. Findings, target design and roadmap, then a 90-minute readout.

At a glance

Duration
1–2 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Assess Popular

Cloud foundation check

In 1–2 weeks, we review your AWS, Azure or Google Cloud foundation against the CIS benchmark and tie every finding to evidence, the affected resources and a fix.

Duration:1–2 weeks
Assess

Migration check

In 1–2 weeks, we assess what you run on-premises or in another cloud, with a migration approach per application, a wave plan and a cost estimate for AWS, Azure or Google Cloud.

Duration:1–2 weeks
Assess

Cloud cost quick wins

Lower your AWS, Azure or Google Cloud bill in one to two weeks by changing how the platform is built, from NAT and data transfer paths to commitments, with the quick wins delivered as code.

Duration:1–2 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.