Configuration review
We analyse your cloud configuration and identity model without touching workloads.
- No production impact
- Fastest turnaround
- Great annual baseline
Most cloud breaches are not exotic exploits. They are a public bucket, an over-privileged role or a forgotten key. We audit AWS, Azure and GCP the way an attacker would, then help you close the gaps.
We review your cloud configuration and identity model against attacker behaviour and CIS benchmarks, looking for the paths that turn one leaked credential into full account access.
The review combines read-only configuration analysis with hands-on testing of the paths we find, so you get proof of what is actually reachable rather than a raw list of misconfigurations.
Pick the depth that matches where you are in your cloud journey.
We analyse your cloud configuration and identity model without touching workloads.
We attempt real exploitation of the paths we find, from a low-privilege starting point.
Recurring reviews as your environment changes, with tracked remediation.
You grant a read-only audit role. We inventory accounts, regions, services and owners.
We map every role, policy and trust relationship to find privilege escalation paths.
We look at what is reachable from the internet and what an insider could reach.
We safely confirm the paths that matter, so you know which findings are theoretical and which are real.
You get a prioritised plan with exact fixes, mapped to CIS and your compliance needs.
Reports your board and your engineers can both use. No 400-page scanner dump.
Tell us about your systems and we will recommend the right assessment, with a clear scope and a fixed price.
No. A read-only audit role is enough for the configuration review. Hands-on testing uses a low-privilege account you create for us, with scope agreed in writing first.
Yes. We regularly review AWS Organizations, Azure tenants with multiple subscriptions, and mixed environments. Scope and pricing scale with the number of accounts.
Yes. Findings are mapped to CIS benchmarks and the relevant controls, and the report is written so auditors accept it as evidence of testing.
Cloud changes faster than on-premise, so quarterly is ideal for active environments, and at minimum annually or after any major architectural change.
Tell us what you need tested. Our team will reply with a clear scope and quote.