The challenge behind the engagement.
This review tells you how your cloud environment compares to the provider's published security benchmark and your own standard, setting by setting. It is not a dashboard score. From read-only access, we take an automated inventory pass, then review each area by hand: how administrative and everyday accounts are protected, how keys and secrets are handled, which trust and access policies are in place, and what is exposed to the internet. We then check public data exposure, encryption and key handling, whether logging is complete and tamper-evident, workload and container settings, and the guardrails set at the top of your environment. You receive a findings register mapped to the benchmark, a coverage matrix per account, and a retest after you fix. Nothing is changed and nothing is installed.
For platform and security leads running production in the cloud who need a benchmark-mapped answer before an audit or evidence window. Also for teams that inherited a cloud environment, or whose native posture dashboards disagree with each other and leave too much marked manual.
What we do.
What you can use.
Grant read-only access and set the baseline
You provide the account list, environment structure, diagrams, and any prior reports, and grant read-only access for the window. We agree which benchmark to measure against and whether to also map findings to a federal or industry control catalog you already report to.
Confirm every candidate finding by hand
An automated pass produces a candidate list. We then check each item directly in the environment: does the policy really grant that access, does the storage object really read anonymously, does the audit log really reach its archive? False positives are dropped, and everything the tooling leaves as a manual check is worked through one by one.
Return configuration findings and validation evidence
You receive a findings register with severity, the affected resource, timestamped evidence, and the exact fix. A pass, fail, not applicable, or manual matrix per account and an executive summary come with it. After you remediate, we re-run the affected checks and record the result.
Who it’s for.
When you need it.
- Teams running production across one or more clouds without a benchmark-mapped baseline of their current settings
- Organizations that inherited a cloud environment nobody deliberately designed or documented
- Security leads whose native posture dashboards disagree or leave many checks marked manual
- Companies preparing evidence of cloud configuration for an audit or customer due-diligence review
- An audit or customer questionnaire asks for proof of cloud configuration against a named benchmark
- A new account or environment was stood up outside the usual process
- A misconfiguration, exposed storage, or public admin port was recently discovered
- You turned on a native posture service and cannot tell which findings are real
What the scope can include.
- 01
Identity: protection of administrative and everyday accounts, multi-factor coverage, keys and secrets, trust policies, and unused access
- 02
Network exposure: services reachable from the internet, open administrative ports, public addresses, and use of private connectivity
- 03
Data protection: publicly readable storage, encryption at rest, customer-managed keys, and how data sharing is controlled
- 04
Logging: complete, tamper-evident audit and network logs delivered to a protected archive and kept long enough to matter
- 05
Workload and container configuration: instance metadata protection, cluster exposure, secrets handling, and workload isolation
- 06
Top-level guardrails as configured today: the organization-wide policies that constrain every account beneath them
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
One cloud account or subscription running a handful of workloads
About 32–48 hoursSeveral accounts with one provider, separate production and test environments
About 60–100 hoursDozens of accounts, or estates spread across two cloud providers
About 120–200 hours- Number of cloud accounts, subscriptions, or projects in scope
- How many different services and workloads are running
- Whether more than one cloud provider is involved
- Whether you need results mapped to a compliance framework and a retest
1–2 weeks for a single account; 3–6 weeks for a large multi-account or two-provider estate, plus a retest window after fixes
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Findings register with severity, the affected resource, timestamped evidence, and a fix written for the resource owner
- Benchmark coverage matrix per account or environment: pass, fail, not applicable, or manual
- Executive summary and a prioritized remediation plan sequenced by blast radius
- Configuration validation report showing corrected settings and dated exports for each remediated issue
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
How is this different from turning on the cloud provider's own posture dashboard?
Turn it on; it is useful input. But those dashboards often track an older benchmark version, leave many requirements as manual checks, and only see the accounts where they are switched on. They do not read your top-level guardrails, trust policies, or container clusters the way a reviewer does. We use their output as a starting list, confirm each item by hand, cover the manual checks and the current benchmark, and write the fix for the person who owns the resource.
Will you need write access, and can you review production safely?
No write access. Everything runs from read-only access you create for the engagement window and remove afterwards, and we install nothing in your environment. Read-only review does not change resources, so production carries on as normal. The main effort drivers are how many accounts and regions are in scope, whether central logging and a single posture view already exist, and how many container clusters are involved. A single-account review usually runs a few days; larger estates run one to several weeks.
- CIS Critical Security Controls Version 8.1
- CIS Amazon Web Services Benchmarks
- Security Pillar - AWS Well-Architected Framework
- The AWS Security Reference Architecture
- Overview of the Microsoft cloud security benchmark v2 (preview)
- What is an Azure landing zone? - Cloud Adoption Framework
- Enterprise foundations blueprint | Cloud Architecture Center
