The challenge behind the engagement.
This review is for environments that span more than one provider, or cloud and on-premises, where the risk sits in the joins. We inventory every trust relationship between environments and check each one for access broader than the work requires: one environment federated into another, sign-in trusts extended to outside systems and pipelines, and an on-premises directory reaching into the cloud. We trace the connectivity between them: how traffic is routed, whether the links are encrypted, where it is inspected, and how names resolve across the boundary. Then we compare controls side by side in a neutral frame: guardrails, central logging, key management, break-glass, and multi-factor coverage on each side. You receive a trust map, a reachability matrix, a control-parity matrix, and a roadmap separating guardrail fixes from architectural change.
For CISOs and platform leads who acquired a company on another cloud, run one provider alongside another for a product, or depend on an on-premises directory for cloud administration. Typical trigger: a due-diligence question about how the two environments trust each other.
What we do.
What you can use.
Map trusts, circuits, and log paths
You provide read-only access to each environment, plus your directory and federation configuration, routing and link details, and per-environment diagrams. Add the list of federations and service identities and your central logging sources. We agree which boundaries matter most, usually the ones regulated data crosses.
Check each join for over-broad trust
Every trust is read for who it accepts, what it is scoped to, and what it can reach on the other side. Connections between environments are checked for link encryption, what is actually reachable, and where inspection sits. Controls are compared per environment: a guardrail present on one side with no equivalent on the other is recorded as a gap, not assumed covered.
Deliver the parity matrix and roadmap
You receive a cross-environment trust map, a connectivity diagram with a reachability matrix, and a control-parity matrix per provider and on-premises. Findings carry a neutral control reference and a fix specific to each environment. The roadmap separates quick guardrail fixes from changes that need architectural work. Anything you fix during the window is retested.
Who it’s for.
When you need it.
- Organizations running more than one cloud provider, or cloud alongside on-premises systems
- Teams whose cloud administration still depends on an on-premises directory as its root of trust
- Security leaders who cannot get one consistent posture view across their providers
- Companies that absorbed another environment through acquisition and now share trust between them
- Due diligence asks how two cloud environments trust and reach each other
- A workload now spans providers and no one owns the connective tissue
- A connection or federation was added quickly and never reviewed for over-broad trust
- A tool you relied on for cross-cloud posture coverage is being retired
What the scope can include.
- 01
Trust inventory: every federation and cross-environment sign-in, plus any on-premises directory reaching into the cloud
- 02
Federation conditions: who each trust accepts, what it is scoped to, and whether it is broader than the workload needs
- 03
Connectivity: routing and reachability between environments, link encryption, inspection points, and name resolution across the boundary
- 04
Control parity per environment: guardrails, central logging, key management, posture monitoring, break-glass, and multi-factor policy
- 05
Consolidated visibility: whether one posture view spans every provider and whether all logs reach a single place
- 06
Hybrid specifics: an on-premises directory as root of trust, management agents, and backup and key custody across sites
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
One cloud plus your on-premises network, a few connections between them
About 40–72 hoursTwo cloud providers plus on-premises, shared sign-in across them
About 80–140 hoursThree or more environments across business units, many trusts and links
About 160–260 hours- Number of environments and providers that connect to each other
- Number of trust relationships and network links to trace
- Whether on-premises directories reach into the cloud
- Depth of the control-by-control comparison you need
2–3 weeks for one cloud plus on-premises; 5–8 weeks for a large multi-provider estate
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Cross-environment trust map listing who each trust accepts, what it is scoped to, and the resources it can reach
- Connectivity diagram with a reachability matrix across providers and on-premises
- Control-parity matrix per environment with each finding under a neutral reference and a fix specific to that environment
- Roadmap separating quick guardrail fixes from architectural change, plus a risk register
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
We just acquired a company that runs on a different cloud. What should we look at first?
The trusts, before anything else. Acquisitions add federations in a hurry: their environment gets federated into yours, a shared pipeline gains sign-in trusts in both clouds, or their directory is joined to yours. Each one is a path from their weakest account into your strongest. We inventory those trusts, check who can reach what, then look at whether their logs reach your central logging and whether your guardrails have an equivalent on their side. Rebuilding their environment can wait; over-broad trust cannot.
Can we get one posture view across all our clouds?
Partly, and the options keep shifting. Some tools connect to more than one provider and can give you a single console across clouds; others report only on their own provider, and at least one cross-cloud tier is being retired, so do not build on it. Whichever you choose, each tool checks its own benchmark version, so the parity matrix we hand over is framework-neutral and does not depend on any one vendor. Reviews with several providers and on-premises in scope commonly run several weeks.
- CIS Critical Security Controls Version 8.1
- CIS Amazon Web Services Benchmarks
- Security Pillar - AWS Well-Architected Framework
- The AWS Security Reference Architecture
- Overview of the Microsoft cloud security benchmark v2 (preview)
- What is an Azure landing zone? - Cloud Adoption Framework
- Enterprise foundations blueprint | Cloud Architecture Center
