The configuration review
Cloud Security Audit and Configuration Review
A cloud security audit is an independent, evidence-referenced review of how your AWS, Azure or GCP estate is configured: identity, networking, storage, encryption and logging, each measured against the CIS Benchmark and handed back as a prioritised, costed plan to fix what genuinely matters.
Why now
The audit someone has asked you for
Most cloud security audits are commissioned because someone outside the platform team asked a question nobody could evidence: an insurer wanting proof that storage is not public, an enterprise customer's supplier questionnaire, a board member reading about a cloud breach, or an auditor asking how long your logs are kept. The audit exists to answer those questions with evidence rather than assurances.
Because every finding is referenced to the CIS Foundations Benchmark for your cloud and to the provider's own security baseline, the answers carry weight: not "we think it is configured well" but "here is the control, the evidence and the score". This one page absorbs what others split across cloud security review, risk assessment, infrastructure assessment and configuration review; it is a single exercise.
You receive
- A scored, evidence-referenced finding for every reviewed control
- CIS Benchmark mapping for AWS, Azure or GCP against each item
- A prioritised, costed remediation plan your team can work through
- A board summary: risk position, what it means commercially, cost to close
- A debrief session where every finding can be challenged
Audit scope
What the cloud security audit examines
Six control areas across AWS, Azure and GCP, reviewed with evidence. The published prices apply by cloud estate size.
Identity and access
Every IAM role, service account and access key across your accounts and subscriptions: over-privileged principals, dormant credentials, root and break-glass usage, and whether multi-factor authentication is enforced where it matters.
Network exposure
Security groups, network security groups and firewall rules examined for anything reachable from the public internet that should not be: open management ports, permissive ingress and flat network paths between workloads.
Data storage
Object and blob storage, databases and volumes checked for public exposure, missing encryption at rest and over-broad access policies. Publicly readable storage is one of the most common findings across AWS, Azure and GCP estates.
Encryption and key management
Encryption in transit and at rest, key rotation and how your KMS, Key Vault or Cloud KMS keys are governed, so sensitive data is protected and the controls stand up to a due diligence question.
Logging and monitoring
Whether CloudTrail, Azure activity and diagnostic logs, or GCP audit logs are switched on, what they capture, how long retention actually runs and whether anyone would see an event that mattered. The setting most estates get wrong.
Configuration against benchmark
Every control mapped to the CIS Foundations Benchmark for your cloud and the provider's own security baseline, so each finding carries a recognised reference rather than an opinion.
Quick answers
Cloud security audit questions, answered
What is the difference between a cloud security audit and a cloud security assessment?
In practice the terms are used interchangeably. The meaningful difference is formality: we use audit for the point-in-time, evidence-referenced exercise that supports compliance, insurance and customer due diligence answers, and assessment for the same technical review positioned around improvement. Same method, same benchmark, same consultants, whether you call it an audit, a review, a risk assessment or a configuration review.
Which cloud platforms does the audit cover?
AWS, Azure and Google Cloud, single account or multi-cloud. We review the infrastructure layer of your estate: accounts and subscriptions, identity, networking, storage, encryption and logging, each measured against the CIS Foundations Benchmark for that platform.
Is a cloud security audit the same as a penetration test?
No. An audit reviews your configuration to find what would let an intruder in; a penetration test actively attacks systems to prove what one could do. Configuration review finds the large majority of real-world cloud weaknesses. If you need offensive testing of your cloud estate, our sister service covers that separately.
Does this cover Microsoft 365 and Entra ID?
This audit covers Azure infrastructure: virtual machines, storage, networking and subscription-level identity. Microsoft 365, Entra ID and the wider tenant configuration are a distinct exercise with its own benchmark, delivered by our tenant security service. If your question is about mailboxes, Conditional Access or SharePoint sharing, that is the page you want.
Will the audit disrupt our services or change anything?
No. The audit runs on read-only access to your cloud accounts. Nothing is modified, nothing is deployed into your environment, and the only people who know it is happening are the ones you tell.
Evidence beats assurances
Scope your cloud security audit
A free 45 minute call establishes which accounts and subscriptions need auditing, what it costs at the published rate and what the report will cover.