Fix Cloud Drift Before Attackers Find It
Cloud Security Configuration Assessment
We assess your cloud accounts against the CIS Foundations Benchmarks and provider baselines. You learn exactly which settings are exposed, why they matter, and how to close them without breaking your workloads.
See the engagement path, 6 phasesSee the full Hardening and Configuration Review service index
Overview
Cloud estates drift. A quick fix from six months ago leaves a bucket public, a security group open, or logging switched off. This assessment reads your live configuration across identity, network, storage, logging and workload settings, then compares it to the CIS Foundations Benchmark for each provider. We separate real exposure from benchmark noise, so your team spends effort where it counts. You finish with a scorecard and a runbook, not a raw scanner dump.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Cloud Security Configuration Assessment engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Baseline Selection. We agree which accounts, subscriptions and projects are in scope, and pick the right CIS Foundations Benchmark version for each provider. We confirm read-only access and any regions or services to exclude. Activities: Inventory in-scope AWS accounts, Azure subscriptions and GCP projects; Select the matching CIS Foundations Benchmark version per provider; Provision read-only assessor roles and confirm access; Agree excluded regions, services and maintenance windows. Hands over Scope and Baseline Agreement with Read-Only Access Confirmed. Phase 2, Evidence and Config Collection. Using read-only roles we pull configuration across IAM, networking, storage, logging and compute. We snapshot the state so findings are reproducible and tied to evidence. Activities: Export IAM users, roles, policies and key age data; Capture security group, NACL and VPC peering configuration; Record storage bucket ACLs, encryption and public access settings; Snapshot CloudTrail, Azure Monitor and GCP audit log settings. Hands over Timestamped Configuration Evidence Set. Phase 3, Benchmark Comparison. We run automated checks with ScoutSuite, Prowler and provider-native tooling, then map results to CIS controls and your own policy where you have one. Activities: Run Prowler and ScoutSuite across every in-scope account; Pull findings from Security Hub and Defender for Cloud; Map each result to its CIS Foundations control number; Flag deviations from your own internal cloud policy. Hands over Draft CIS Benchmark Scorecard. Phase 4, Manual Review of Risky Settings. We manually verify the high-impact items: public exposure, over-broad IAM, missing encryption, and gaps in logging. This filters false positives and catches issues benchmarks miss. Activities: Confirm which buckets and endpoints are reachable from the internet; Trace wildcard IAM permissions and privilege escalation paths; Check encryption at rest and key rotation on data stores; Verify MFA and conditional access on privileged identities; Discard false positives with a documented reason. Hands over Validated Exposure List. Phase 5, Prioritised Findings. Each finding is rated by real exposure and blast radius, with the affected resources listed so your team can act without hunting. Activities: Rate each finding by exposure and blast radius; List affected resource ARNs and IDs per finding; Group findings by owning team and account; Walk the engineering team through the top items. Hands over Cloud Configuration Findings Report. Phase 6, Remediation and Re-Check. We hand over fix guidance mapped to each control, then re-run the checks after your changes to confirm the scorecard has moved. Activities: Write fix steps and Terraform snippets per control; Support your team through the change windows; Re-run Prowler and ScoutSuite after the fixes land; Reissue the scorecard showing the movement. Hands over Re-Check Report and Updated Scorecard. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Baseline Selection
We agree which accounts, subscriptions and projects are in scope, and pick the right CIS Foundations Benchmark version for each provider. We confirm read-only access and any regions or services to exclude.
What Happens In This Phase
- Inventory in-scope AWS accounts, Azure subscriptions and GCP projects
- Select the matching CIS Foundations Benchmark version per provider
- Provision read-only assessor roles and confirm access
- Agree excluded regions, services and maintenance windows
The Handover
Scope and Baseline Agreement with Read-Only Access Confirmed
The next phase starts from this.
Phase 01 Scoping and Baseline Selection
We agree which accounts, subscriptions and projects are in scope, and pick the right CIS Foundations Benchmark version for each provider. We confirm read-only access and any regions or services to exclude.
What Happens In This Phase
- Inventory in-scope AWS accounts, Azure subscriptions and GCP projects
- Select the matching CIS Foundations Benchmark version per provider
- Provision read-only assessor roles and confirm access
- Agree excluded regions, services and maintenance windows
The Handover
Scope and Baseline Agreement with Read-Only Access Confirmed
The next phase starts from this.
- 01
Scoping and Baseline Selection
We agree which accounts, subscriptions and projects are in scope, and pick the right CIS Foundations Benchmark version for each provider. We confirm read-only access and any regions or services to exclude.
OutputScope and Baseline Agreement with Read-Only Access ConfirmedActivities
- Inventory in-scope AWS accounts, Azure subscriptions and GCP projects
- Select the matching CIS Foundations Benchmark version per provider
- Provision read-only assessor roles and confirm access
- Agree excluded regions, services and maintenance windows
- 02
Evidence and Config Collection
Using read-only roles we pull configuration across IAM, networking, storage, logging and compute. We snapshot the state so findings are reproducible and tied to evidence.
OutputTimestamped Configuration Evidence SetActivities
- Export IAM users, roles, policies and key age data
- Capture security group, NACL and VPC peering configuration
- Record storage bucket ACLs, encryption and public access settings
- Snapshot CloudTrail, Azure Monitor and GCP audit log settings
- 03
Benchmark Comparison
We run automated checks with ScoutSuite, Prowler and provider-native tooling, then map results to CIS controls and your own policy where you have one.
OutputDraft CIS Benchmark ScorecardActivities
- Run Prowler and ScoutSuite across every in-scope account
- Pull findings from Security Hub and Defender for Cloud
- Map each result to its CIS Foundations control number
- Flag deviations from your own internal cloud policy
- 04
Manual Review of Risky Settings
We manually verify the high-impact items: public exposure, over-broad IAM, missing encryption, and gaps in logging. This filters false positives and catches issues benchmarks miss.
OutputValidated Exposure ListActivities
- Confirm which buckets and endpoints are reachable from the internet
- Trace wildcard IAM permissions and privilege escalation paths
- Check encryption at rest and key rotation on data stores
- Verify MFA and conditional access on privileged identities
- Discard false positives with a documented reason
- 05
Prioritised Findings
Each finding is rated by real exposure and blast radius, with the affected resources listed so your team can act without hunting.
OutputCloud Configuration Findings ReportActivities
- Rate each finding by exposure and blast radius
- List affected resource ARNs and IDs per finding
- Group findings by owning team and account
- Walk the engineering team through the top items
- 06
Remediation and Re-Check
We hand over fix guidance mapped to each control, then re-run the checks after your changes to confirm the scorecard has moved.
OutputRe-Check Report and Updated ScorecardActivities
- Write fix steps and Terraform snippets per control
- Support your team through the change windows
- Re-run Prowler and ScoutSuite after the fixes land
- Reissue the scorecard showing the movement
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Cloud Security Configuration Assessment scope, running left to right in three stages. Stage one, what we run, 9 tools and techniques: ScoutSuite, Prowler, CIS-CAT Pro, AWS Config, AWS Security Hub, Microsoft Defender for Cloud, Azure Security Center, Trivy, gcloud and Cloud Asset Inventory. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 7 published standards: CIS AWS Foundations Benchmark, CIS Microsoft Azure Foundations Benchmark, CIS Google Cloud Platform Foundations Benchmark, CIS Kubernetes Benchmark, NIST SP 800-53, AWS, Azure and GCP Well-Architected security baselines, MITRE ATT&CK for Cloud.
What We Run
9 tools
- ScoutSuite
- AWS Config
- AWS Security Hub
- Microsoft Defender for Cloud
- Azure Security Center
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
7 standards
- CIS
- CIS
- CIS
- CIS
- CSPAWS, Azure, GCP
Deliverables
What You Receive
- Cloud configuration findings report
- CIS benchmark scorecard by account
- Cloud hardening runbook
- Re-check report after remediation
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Do you need write access to our cloud accounts?
No. We work from read-only roles. You keep control of every change, and we give you the exact steps to apply.
Which providers do you cover?
AWS, Azure and GCP, using the matching CIS Foundations Benchmark for each. We can also review Kubernetes clusters against the CIS Kubernetes Benchmark.
How is this different from our cloud provider's security dashboard?
Native dashboards flag issues but rarely rank them by real exposure or explain the fix. We validate findings by hand, cut the noise, and give you a runbook your team can follow.
Keep Moving Through Hardening and Configuration Review
Service 1 of 5 in this practice area
Practice Area
More in Hardening and Configuration Review
- Operating System Hardening ReviewBenchmark comparison of your Windows and Linux builds against CIS and STIG baselines
- Firewall and Perimeter ReviewRule-base and configuration review of your firewalls, VPNs and edge devices
- Active Directory and Domain Controller AuditSecurity review of your AD forest, domain controllers and privilege paths
- Database and Web Server ConfigurationHardening review of your databases and web servers against CIS Benchmarks