Cloud security review
A review of your cloud accounts against how they are actually attacked: identity, exposure, secrets, and logging.
What the engagement covers.
Identity and access
Privilege escalation paths through roles, policies, and trust relationships, plus unused credentials and missing MFA.
Network exposure
Security groups, public IPs, load balancers, and peering that expose more than intended.
Data services
Object storage, databases, snapshots, and backups checked for public access, weak encryption, and cross-account sharing.
Secrets and pipelines
Credentials in code, CI variables, and container images, and what a compromised pipeline could deploy.
Logging and detection
Whether audit logs are on, retained, protected from tampering, and actually watched.
Kubernetes
Cluster RBAC, network policies, workload identity, and admission controls for teams running containers at scale.
How it runs.
Access
Read-only credentials provisioned to a dedicated review account. We never need write access.
Review
Automated inventory of every account and region, then manual analysis of privilege paths, exposure, and architecture.
Validate
Where authorized, we prove the impact of key findings, such as reaching a database from a low-privilege role.
Remediate
A working session with your platform team to fix the highest-impact issues and agree on guardrails.
What you receive.
- Findings report with impact and infrastructure-as-code fixes
- Privilege path diagrams for your most sensitive resources
- Guardrail recommendations: policies, SCPs, and detection rules
- Remediation working session with your platform team
Who it is for.
- Companies that moved to the cloud quickly and never looked back
- Platform teams ahead of a compliance audit or major customer review
- Organizations running production Kubernetes
Questions about cloud security.
Which cloud providers do you cover?
AWS, Microsoft Azure, and Google Cloud, plus Kubernetes on any of them. Multi-cloud estates are reviewed as one system, because attackers treat them that way.
Do you need write access to our accounts?
No. A read-only role is enough for the review. Where we validate impact, we agree the exact actions in advance.
How long does a review take?
One to two weeks for a single-cloud estate of moderate size, longer for large multi-account organizations. Scoping fixes the estimate.
Scope a cloud security engagement.
Tell us about the system and the deadline. You will get a fixed-price proposal after one scoping call.