Technical Assurance & Offensive Security

Cloud Security Assessment & Hardening

Your cloud is misconfigured. We find out how badly, and set the baseline that keeps it fixed.

The situation

Almost every cloud breach traces to configuration and identity, not to a provider vulnerability.

We assess AWS, Azure and Google Cloud estates against CIS Benchmarks and provider security baselines, concentrate on the identity and privilege model where the real risk sits, and leave behind a hardening baseline and policy-as-code guardrails so the estate does not drift back within a quarter.

What the client receives

Schedule of deliverables

  1. 01Multi-cloud posture assessment against CIS Benchmarks
  2. 02IAM and privilege model review, including cross-account and workload identity
  3. 03Network, encryption and key management review
  4. 04Container and Kubernetes security assessment
  5. 05Landing zone and guardrail design (policy as code)
  6. 06Hardening baseline and drift detection recommendations

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • CIS Benchmarks
  • AWS / Azure / GCP well-architected security pillars
  • NIST SP 800-53
  • CSA CCM

Discuss this engagement

Tell us about the cloud estate, its accounts and the baseline you want held and we will set out the scope, the method and the reporting format.

Contact us