The process
How it works
A cloud security assessment runs as a clear sequence: a scoping call, read-only access to your AWS, Azure or GCP estate, the assessment across misconfiguration, identity, data exposure and posture, findings triaged and prioritised, a report with a prioritised fix plan, and a debrief. The same sequence runs whether you have a single account or a multi-cloud estate. It is delivered in-house by CyPro, one team from first call to debrief.
Six steps
From scoping call to a prioritised fix plan
Every assessment runs this sequence. What changes between a single account and a large multi-cloud estate is how much estate is in scope, not the shape of the process around it.
Step 1
The scoping call
Free, taken by a consultant rather than a salesperson. We establish which cloud you run, how many accounts or subscriptions are in scope, the services inside them, and the estate-size level you sit in. Before the call wraps up you will have the indicative fixed fee in hand, matching the figure published on our pricing page.
Step 2
Read-only access arranged
We confirm in writing the accounts, subscriptions or projects in scope, then arrange read-only access to your AWS, Azure or GCP estate. The access is authorised by you and read only: we look at how the estate is configured, we do not change it. Nothing is touched that has not been agreed, and a fixed-scope statement of work is settled before the assessment begins.
Step 3
The assessment
Our consultants review the estate across four areas: misconfiguration in the cloud services you run, identity and access management, where data is exposed or over-shared, and your overall posture against best practice and recognised benchmarks such as the CIS Benchmarks. On a multi-cloud estate the same review runs across each provider, with the differences between AWS, Azure and GCP accounted for.
Step 4
Findings triaged and prioritised
Every finding is weighed for the risk it carries and prioritised: a publicly exposed data store is separated from a housekeeping fix, and the things that matter from the noise. Nothing goes out until each finding has been verified for accuracy and relevance, so the report you receive has been vetted rather than passed on unfiltered.
Step 5
A prioritised fix plan
You receive a clear report: where your cloud estate stands against best practice, what is at risk, and a prioritised fix plan ordered for the people who will act on it, highest-risk items first. It is drafted to hand straight to a board, an auditor or a client, with no polishing needed first.
Step 6
The debrief
We talk the findings through with the people who will act on them: what the highest-risk items mean, why they matter, and how to close them. The fix plan is yours to act on with your own team, or you can bring us in to help. The same consultants who ran the assessment take the debrief, so nothing is lost in a handover.
What is in scope
One cloud, or a multi-cloud estate
The sequence above runs the same way whichever cloud you are on. What changes is how much estate is in scope, and it is always delivered as a fixed-scope assessment rather than an open-ended engagement.
A single cloud. Your AWS, Azure or GCP estate reviewed across misconfiguration, identity and access, data exposure and posture. For Azure that means your infrastructure: subscriptions, virtual machines, storage, networking and the access around them.
A multi-cloud estate. More than one provider reviewed together, with the differences between AWS, Azure and GCP accounted for, and a single fix plan across the whole footprint. See the prices on the pricing page.
The exchange
What the assessment needs from you, and what you get back
What it asks of you
- A named contact: someone who can authorise access and receives the findings.
- Your estate defined: which cloud accounts, subscriptions or projects are in scope, and the services running inside them.
- Read-only access to the AWS, Azure or GCP estate, arranged at scoping so we can review how it is configured.
- Written authorisation for that access, agreed at scoping; we only review systems we have been authorised on, and the access is read only.
What it hands back
- A clear view of where your cloud estate stands against best practice, and exactly where the risk sits.
- Findings ordered by the risk they carry, with a prioritised fix plan, not a raw list of alerts to decode.
- A report ready to share with a board, an auditor or a client as it stands.
- One team throughout, a debrief with the people who will act, and help with the fixes where you want it.
Common questions
What organisations ask before they commission
What does a cloud security assessment involve?
It runs as a clear sequence: a scoping call to fix what is in scope, read-only access to your AWS, Azure or GCP estate, the assessment itself across misconfiguration, identity and access, data exposure and posture against best practice, then every finding triaged and prioritised, a report with a prioritised fix plan, and a debrief. The same shape runs whether you have one account or a multi-cloud estate. What changes is how much estate is in scope, not the order of the work.
What access do you need to our cloud?
Read-only access to the accounts, subscriptions or projects in scope, authorised by you at scoping. Read only means we review how the estate is configured, its identity and access setup, its data exposure and its posture, without changing anything or interrupting what is running. We only ever review systems you have authorised us on, and the scope is agreed in writing before we begin.
Is this a penetration test?
No. A cloud security assessment is a read review of how your cloud is configured: misconfiguration, identity and access, data exposure and posture against best practice and the CIS Benchmarks. It does not attack or exploit your systems. Penetration testing, where a tester actively probes for a way in, is a separate service. The assessment tells you where your cloud estate is weak; it is the natural first step, and it will flag where deeper testing is worth commissioning.
What do we get at the end?
A report and a prioritised fix plan: where your cloud estate stands against best practice, what is at risk, and the fixes ordered so the highest-risk items come first. Then a debrief with the people who will act on it. The plan is yours to act on with your own team, or you can bring us in to help close the gaps. The indicative prices for the assessment are on the pricing page.
Step one costs nothing
Book the scoping call
Bring the cloud you run and a rough idea of what is in scope. We bring the sequence above, the indicative fixed fee, and a clear view of how large your AWS, Azure or GCP assessment would be.