Services / Cloud security assessment

Cloud security assessment

We review your AWS, Azure, Google Cloud or Microsoft 365 environment for misconfigurations, excessive permissions and attack paths.

Most cloud incidents aren’t caused by a flaw at the cloud provider, but by a wrong setting on the customer’s side: a public storage account, an admin without MFA, a key that never expires. With read access to your environment, we review the configuration and look at how an attacker could get from a small foothold to full control.

What we look at

Identity & access

Entra ID / IAM: admin roles, MFA, conditional access, service accounts and keys.

Exposure

Publicly reachable storage, databases, management interfaces and network rules.

Logging & detection

Are you logging what you need to investigate an incident? And is anyone watching?

Attack paths

How could an attacker move on from one compromised account or server?

What you get

  • Findings measured against CIS Benchmarks and provider best practices
  • Visual overview of the key attack paths
  • Prioritised remediation plan with concrete settings
  • Optional: scripts or policies to monitor the configuration

A good fit for

  • Organisations that have (partly) moved to the cloud
  • Businesses running on Microsoft 365 and Entra ID
  • Teams building fast in AWS, Azure or GCP
  • After a migration or change of IT partner

Questions

Not sure this is the right service?

Start with the Security Posture Assessment, or book a call.

Where do I start? →
What access do you need?

Read-only (for example the Reader or SecurityAudit role). We don’t change anything in your environment.

Does this include Microsoft 365 and Entra ID?

Yes. For many mid-sized organisations, Microsoft 365 is the most important cloud environment and the most attacked target.

Curious how an attacker sees your organisation?

Book a no-obligation 30-minute call. We’ll discuss your situation and give honest advice on what makes sense — even if that isn’t work for us.