Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cloud security

Organizations running all or part of their information system on AWS, Azure, Google Cloud, or Microsoft 365, in pure cloud or hybrid environments.

Last updatedAugust 22, 2026

The problem this solves

Moving to the cloud shifts the security perimeter without always shifting the skills needed to oversee it. Misconfigurations, excessive permissions, and publicly exposed resources remain the leading cause of cloud incidents, often discovered only after the fact.

What's included

Configuration review against applicable CIS Benchmarks for the provider

Identity and permissions analysis (IAM, roles, privileged access)

Review of public exposure of resources and services

Assessment of cloud-native logging and detection capabilities

Data residency compliance check

Frameworks applied

CIS BenchmarksCSA Cloud Controls MatrixWell-Architected Framework (security pillar)

Deliverables

Configuration report with gaps against CIS Benchmarks

Map of at-risk identities and permissions

List of publicly exposed resources

Prioritized remediation plan

2 to 4 weeks depending on the number of accounts and services covered

Typical duration

Client prerequisites

  • Read access to the consoles and APIs of the relevant environments
  • List of accounts, subscriptions, or tenants in scope
  • A technical contact with cloud administration rights

Frequently asked questions

Can the audit cover several cloud providers at once?

Yes. Scope is defined at kickoff and can span one or more providers (AWS, Azure, Google Cloud) as well as Microsoft 365, within a single engagement.

Does the audit disrupt production services?

No. The analysis relies on read-only configuration and log review, with no action taken on production environments.

Get in touch