Cloud Security / FOCUSED SERVICE

Cloud Security Assessment & Configuration Review

Cloud security assessments review identity, network exposure, data protection, logging, and workloads, with validated findings and prioritized fixes.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This review tells you how your cloud environment compares to the provider's published security benchmark and your own standard, setting by setting. It is not a dashboard score. From read-only access, we take an automated inventory pass, then review each area by hand: how administrative and everyday accounts are protected, how keys and secrets are handled, which trust and access policies are in place, and what is exposed to the internet. We then check public data exposure, encryption and key handling, whether logging is complete and tamper-evident, workload and container settings, and the guardrails set at the top of your environment. You receive a findings register mapped to the benchmark, a coverage matrix per account, and a retest after you fix. Nothing is changed and nothing is installed.

WHEN THIS IS THE RIGHT FIT

For platform and security leads running production in the cloud who need a benchmark-mapped answer before an audit or evidence window. Also for teams that inherited a cloud environment, or whose native posture dashboards disagree with each other and leave too much marked manual.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Grant read-only access and set the baseline

You provide the account list, environment structure, diagrams, and any prior reports, and grant read-only access for the window. We agree which benchmark to measure against and whether to also map findings to a federal or industry control catalog you already report to.

Confirm every candidate finding by hand

An automated pass produces a candidate list. We then check each item directly in the environment: does the policy really grant that access, does the storage object really read anonymously, does the audit log really reach its archive? False positives are dropped, and everything the tooling leaves as a manual check is worked through one by one.

Return configuration findings and validation evidence

You receive a findings register with severity, the affected resource, timestamped evidence, and the exact fix. A pass, fail, not applicable, or manual matrix per account and an executive summary come with it. After you remediate, we re-run the affected checks and record the result.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Teams running production across one or more clouds without a benchmark-mapped baseline of their current settings
  • Organizations that inherited a cloud environment nobody deliberately designed or documented
  • Security leads whose native posture dashboards disagree or leave many checks marked manual
  • Companies preparing evidence of cloud configuration for an audit or customer due-diligence review
WHEN IT’S TIME TO ENGAGE
  • An audit or customer questionnaire asks for proof of cloud configuration against a named benchmark
  • A new account or environment was stood up outside the usual process
  • A misconfiguration, exposed storage, or public admin port was recently discovered
  • You turned on a native posture service and cannot tell which findings are real
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Identity: protection of administrative and everyday accounts, multi-factor coverage, keys and secrets, trust policies, and unused access

  • Network exposure: services reachable from the internet, open administrative ports, public addresses, and use of private connectivity

  • Data protection: publicly readable storage, encryption at rest, customer-managed keys, and how data sharing is controlled

  • Logging: complete, tamper-evident audit and network logs delivered to a protected archive and kept long enough to matter

  • Workload and container configuration: instance metadata protection, cluster exposure, secrets handling, and workload isolation

  • Top-level guardrails as configured today: the organization-wide policies that constrain every account beneath them

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$4,800–$7,200

One cloud account or subscription running a handful of workloads

About 32–48 hours
Mid-size
$9,000–$15,000

Several accounts with one provider, separate production and test environments

About 60–100 hours
Large
$18,000–$30,000

Dozens of accounts, or estates spread across two cloud providers

About 120–200 hours
WHAT MOVES THE PRICE
  • Number of cloud accounts, subscriptions, or projects in scope
  • How many different services and workloads are running
  • Whether more than one cloud provider is involved
  • Whether you need results mapped to a compliance framework and a retest
TYPICAL TIMELINE

1–2 weeks for a single account; 3–6 weeks for a large multi-account or two-provider estate, plus a retest window after fixes

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Findings register with severity, the affected resource, timestamped evidence, and a fix written for the resource owner
  • Benchmark coverage matrix per account or environment: pass, fail, not applicable, or manual
  • Executive summary and a prioritized remediation plan sequenced by blast radius
  • Configuration validation report showing corrected settings and dated exports for each remediated issue

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

How is this different from turning on the cloud provider's own posture dashboard?

Turn it on; it is useful input. But those dashboards often track an older benchmark version, leave many requirements as manual checks, and only see the accounts where they are switched on. They do not read your top-level guardrails, trust policies, or container clusters the way a reviewer does. We use their output as a starting list, confirm each item by hand, cover the manual checks and the current benchmark, and write the fix for the person who owns the resource.

Will you need write access, and can you review production safely?

No write access. Everything runs from read-only access you create for the engagement window and remove afterwards, and we install nothing in your environment. Read-only review does not change resources, so production carries on as normal. The main effort drivers are how many accounts and regions are in scope, whether central logging and a single posture view already exist, and how many container clusters are involved. A single-account review usually runs a few days; larger estates run one to several weeks.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security