The configuration review

Cloud Security Audit and Configuration Review

A cloud security audit is an independent, evidence-referenced review of how your AWS, Azure or GCP estate is configured: identity, networking, storage, encryption and logging, each measured against the CIS Benchmark and handed back as a prioritised, costed plan to fix what genuinely matters.

Why now

The audit someone has asked you for

Most cloud security audits are commissioned because someone outside the platform team asked a question nobody could evidence: an insurer wanting proof that storage is not public, an enterprise customer's supplier questionnaire, a board member reading about a cloud breach, or an auditor asking how long your logs are kept. The audit exists to answer those questions with evidence rather than assurances.

Because every finding is referenced to the CIS Foundations Benchmark for your cloud and to the provider's own security baseline, the answers carry weight: not "we think it is configured well" but "here is the control, the evidence and the score". This one page absorbs what others split across cloud security review, risk assessment, infrastructure assessment and configuration review; it is a single exercise.

You receive

  • A scored, evidence-referenced finding for every reviewed control
  • CIS Benchmark mapping for AWS, Azure or GCP against each item
  • A prioritised, costed remediation plan your team can work through
  • A board summary: risk position, what it means commercially, cost to close
  • A debrief session where every finding can be challenged

Audit scope

What the cloud security audit examines

Six control areas across AWS, Azure and GCP, reviewed with evidence. The published prices apply by cloud estate size.

Identity and access

Every IAM role, service account and access key across your accounts and subscriptions: over-privileged principals, dormant credentials, root and break-glass usage, and whether multi-factor authentication is enforced where it matters.

Network exposure

Security groups, network security groups and firewall rules examined for anything reachable from the public internet that should not be: open management ports, permissive ingress and flat network paths between workloads.

Data storage

Object and blob storage, databases and volumes checked for public exposure, missing encryption at rest and over-broad access policies. Publicly readable storage is one of the most common findings across AWS, Azure and GCP estates.

Encryption and key management

Encryption in transit and at rest, key rotation and how your KMS, Key Vault or Cloud KMS keys are governed, so sensitive data is protected and the controls stand up to a due diligence question.

Logging and monitoring

Whether CloudTrail, Azure activity and diagnostic logs, or GCP audit logs are switched on, what they capture, how long retention actually runs and whether anyone would see an event that mattered. The setting most estates get wrong.

Configuration against benchmark

Every control mapped to the CIS Foundations Benchmark for your cloud and the provider's own security baseline, so each finding carries a recognised reference rather than an opinion.

Quick answers

Cloud security audit questions, answered

What is the difference between a cloud security audit and a cloud security assessment?

In practice the terms are used interchangeably. The meaningful difference is formality: we use audit for the point-in-time, evidence-referenced exercise that supports compliance, insurance and customer due diligence answers, and assessment for the same technical review positioned around improvement. Same method, same benchmark, same consultants, whether you call it an audit, a review, a risk assessment or a configuration review.

The cloud security assessment, in full

Which cloud platforms does the audit cover?

AWS, Azure and Google Cloud, single account or multi-cloud. We review the infrastructure layer of your estate: accounts and subscriptions, identity, networking, storage, encryption and logging, each measured against the CIS Foundations Benchmark for that platform.

See the published prices by estate size

Is a cloud security audit the same as a penetration test?

No. An audit reviews your configuration to find what would let an intruder in; a penetration test actively attacks systems to prove what one could do. Configuration review finds the large majority of real-world cloud weaknesses. If you need offensive testing of your cloud estate, our sister service covers that separately.

Cloud penetration testing

Does this cover Microsoft 365 and Entra ID?

This audit covers Azure infrastructure: virtual machines, storage, networking and subscription-level identity. Microsoft 365, Entra ID and the wider tenant configuration are a distinct exercise with its own benchmark, delivered by our tenant security service. If your question is about mailboxes, Conditional Access or SharePoint sharing, that is the page you want.

Microsoft 365 and tenant security

Will the audit disrupt our services or change anything?

No. The audit runs on read-only access to your cloud accounts. Nothing is modified, nothing is deployed into your environment, and the only people who know it is happening are the ones you tell.

Rocket above the cloud security Consultancy call to action

Evidence beats assurances

Scope your cloud security audit

A free 45 minute call establishes which accounts and subscriptions need auditing, what it costs at the published rate and what the report will cover.