Asked and answered
Frequently asked questions
The questions UK businesses bring to us before commissioning a cloud security assessment, answered plainly: what an assessment is, how it runs across AWS, Azure and GCP, what it costs, and where it differs from CSPM tooling and penetration testing. Anything these leave open, we work through directly with you on the scoping call.
What is a cloud security assessment?
A cloud security assessment is an independent review of how your cloud estate is configured and secured, tested against recognised good practice such as the CIS Benchmarks and the cloud provider's own security guidance. It looks across AWS, Azure and GCP at the things that most often go wrong: misconfigured services, over-permissive identity and access, publicly exposed storage and databases, weak network controls, gaps in logging and monitoring, and workloads running without the guardrails they should have.
The output is a findings report you can act on: each issue described plainly, rated by the risk it carries, and set against a prioritised, costed plan to close it. It is a point-in-time assessment of your configuration and posture, delivered as project work with a defined scope and a fixed fee, rather than an ongoing monitoring service.
How do you do a cloud security assessment?
It begins with a scoping call to agree which accounts, subscriptions and services are in scope and what good looks like for your business. From there a consultant reviews the estate with read-only access, examining identity and access management, resource configuration, network design, data storage, encryption, logging and monitoring against the provider's security guidance and the CIS Benchmarks.
Findings are gathered into a single list, ordered by the risk each one carries rather than the order they were found, and written up with the context an engineer needs to fix them. You are left with a clear picture of where the estate stands and a sequenced plan to put it right, starting with whatever exposes you most. The review is a read of your configuration and does not involve exploiting or attacking live systems, which is a separate exercise.
What is the cloud assessment process?
The process runs in four stages. First, scope: agreeing the accounts, subscriptions and services in scope and the standards to measure against. Second, review: a consultant examines the estate with read-only access, checking configuration, identity, network, data and monitoring against the CIS Benchmarks and the provider's guidance. Third, analysis: every finding is validated, rated by risk and set in the context of your environment rather than reported as a raw tool dump.
Fourth, report and plan: you receive a findings report with a clear rating against each area and a prioritised remediation plan that gives every item an order and an indication of the effort to close it. Where useful, a walkthrough call talks the delivery team through the findings so the plan can be actioned straight away.
What tools do you use for a cloud security assessment?
The assessment draws on the cloud provider's native security services and on recognised benchmarks rather than a single product. On the tooling question people usually mean the difference between a Cloud Security Posture Management (CSPM) tool and an assessment. A CSPM tool continuously scans your estate and flags configuration drift against a ruleset, which is genuinely useful for ongoing hygiene once it is tuned. What it does not do is interpret your findings, tell you which of hundreds of alerts actually matter for your business, or judge the ones that need context a rule cannot capture.
An assessment is the human read on top of that. A consultant validates what the tools surface, discards the noise, weighs each real issue against the risk it poses to your organisation, and hands you a short, prioritised plan rather than a raw feed of alerts. Many organisations benefit from both: a tool to watch the estate day to day, and a periodic assessment to make sense of it and set direction.
What are the 4 pillars of cloud security?
The four pillars people refer to are the core areas any sound cloud security programme has to cover. They are commonly framed as: identity and access management, keeping the right people and workloads on the right permissions and no more; data protection, meaning encryption, key management and control over where data lives and who can reach it; infrastructure and network security, covering secure configuration of compute, storage and networking; and visibility and governance, meaning logging, monitoring, threat detection and the policies that hold it all together.
A cloud security assessment works across all four, because weakness in one tends to undermine the others. Strong network controls count for little if an over-permissive identity can bypass them, and encryption matters less if logging would never show you the data had been reached. The value of an assessment is seeing the four together and prioritising across them, rather than hardening one in isolation.
What is CSPM, or cloud security posture management?
Cloud Security Posture Management (CSPM) is a category of tooling that continuously checks a cloud estate for misconfiguration and compliance drift. A CSPM tool holds a library of rules based on best practice and provider guidance, scans your AWS, Azure or GCP accounts against them, and raises alerts when something falls out of line, such as a storage bucket turned public or an identity granted more than it needs.
CSPM is worth having for continuous hygiene, but it is a tool, not an answer. It reports against its ruleset and cannot judge which of its alerts genuinely threaten your business, discard false positives with confidence, or weigh a finding that needs context a rule cannot hold. That interpretation is what a cloud security assessment adds: a consultant makes sense of the posture, sets priorities and gives you a plan. We do not resell CSPM products; we help you decide whether you need a tool, an assessment, or both.
How much does a cloud security assessment cost?
Indicative fixed-fee pricing is published on our pricing page, scaled by the size of your cloud estate rather than quoted only after a sales process. Assessments start from £4,500 for a single account or small estate, with higher figures for multi-account and larger or multi-cloud estates. The fee for your organisation depends on how many accounts or subscriptions are in scope and how many services need reviewing.
Most providers in this market are quote-only and vendor tools are priced by subscription, so we set out indicative 'from' prices here and put the fixed fee in writing once the scoping call has defined your estate. It means you can budget the assessment before you ever pick up the phone.
What is the difference between a cloud security assessment and penetration testing?
They answer different questions. A cloud security assessment is a configuration and posture review: a consultant examines how your AWS, Azure or GCP estate is set up against recognised benchmarks and tells you where it falls short, with a prioritised plan to fix it. It is a read of the estate, carried out with read-only access, and it is what this service delivers.
Penetration testing is a separate, active exercise. A tester attempts to exploit weaknesses to prove what an attacker could actually reach, which is a different scope, a different method and a different engagement. We do not deliver cloud penetration testing on this service. If that is what you need, it is offered by our sister service at managedvulnerabilityscanning.co.uk, and a scoping call will point you to the right one. Many organisations run an assessment first to fix the obvious exposure, then a penetration test to validate what remains.
A question we missed?
Bring it to the scoping call
That is what the scoping call is for: 45 minutes, free, on your AWS, Azure or GCP estate, the scope you need and the indicative fixed fee, whether or not you go on to commission the assessment. It is taken by a cloud security consultant, not a salesperson.