Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Hardening and Configuration Review5 services in this practice area

Fix Cloud Drift Before Attackers Find It

Cloud Security Configuration Assessment

We assess your cloud accounts against the CIS Foundations Benchmarks and provider baselines. You learn exactly which settings are exposed, why they matter, and how to close them without breaking your workloads.

See the engagement path, 6 phasesSee the full Hardening and Configuration Review service index

Overview

Cloud estates drift. A quick fix from six months ago leaves a bucket public, a security group open, or logging switched off. This assessment reads your live configuration across identity, network, storage, logging and workload settings, then compares it to the CIS Foundations Benchmark for each provider. We separate real exposure from benchmark noise, so your team spends effort where it counts. You finish with a scorecard and a runbook, not a raw scanner dump.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Cloud Security Configuration Assessment engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Baseline Selection. We agree which accounts, subscriptions and projects are in scope, and pick the right CIS Foundations Benchmark version for each provider. We confirm read-only access and any regions or services to exclude. Activities: Inventory in-scope AWS accounts, Azure subscriptions and GCP projects; Select the matching CIS Foundations Benchmark version per provider; Provision read-only assessor roles and confirm access; Agree excluded regions, services and maintenance windows. Hands over Scope and Baseline Agreement with Read-Only Access Confirmed. Phase 2, Evidence and Config Collection. Using read-only roles we pull configuration across IAM, networking, storage, logging and compute. We snapshot the state so findings are reproducible and tied to evidence. Activities: Export IAM users, roles, policies and key age data; Capture security group, NACL and VPC peering configuration; Record storage bucket ACLs, encryption and public access settings; Snapshot CloudTrail, Azure Monitor and GCP audit log settings. Hands over Timestamped Configuration Evidence Set. Phase 3, Benchmark Comparison. We run automated checks with ScoutSuite, Prowler and provider-native tooling, then map results to CIS controls and your own policy where you have one. Activities: Run Prowler and ScoutSuite across every in-scope account; Pull findings from Security Hub and Defender for Cloud; Map each result to its CIS Foundations control number; Flag deviations from your own internal cloud policy. Hands over Draft CIS Benchmark Scorecard. Phase 4, Manual Review of Risky Settings. We manually verify the high-impact items: public exposure, over-broad IAM, missing encryption, and gaps in logging. This filters false positives and catches issues benchmarks miss. Activities: Confirm which buckets and endpoints are reachable from the internet; Trace wildcard IAM permissions and privilege escalation paths; Check encryption at rest and key rotation on data stores; Verify MFA and conditional access on privileged identities; Discard false positives with a documented reason. Hands over Validated Exposure List. Phase 5, Prioritised Findings. Each finding is rated by real exposure and blast radius, with the affected resources listed so your team can act without hunting. Activities: Rate each finding by exposure and blast radius; List affected resource ARNs and IDs per finding; Group findings by owning team and account; Walk the engineering team through the top items. Hands over Cloud Configuration Findings Report. Phase 6, Remediation and Re-Check. We hand over fix guidance mapped to each control, then re-run the checks after your changes to confirm the scorecard has moved. Activities: Write fix steps and Terraform snippets per control; Support your team through the change windows; Re-run Prowler and ScoutSuite after the fixes land; Reissue the scorecard showing the movement. Hands over Re-Check Report and Updated Scorecard. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Baseline Selection

We agree which accounts, subscriptions and projects are in scope, and pick the right CIS Foundations Benchmark version for each provider. We confirm read-only access and any regions or services to exclude.

What Happens In This Phase

  • Inventory in-scope AWS accounts, Azure subscriptions and GCP projects
  • Select the matching CIS Foundations Benchmark version per provider
  • Provision read-only assessor roles and confirm access
  • Agree excluded regions, services and maintenance windows

The Handover

Scope and Baseline Agreement with Read-Only Access Confirmed

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Baseline Selection

    We agree which accounts, subscriptions and projects are in scope, and pick the right CIS Foundations Benchmark version for each provider. We confirm read-only access and any regions or services to exclude.

    OutputScope and Baseline Agreement with Read-Only Access Confirmed

    Activities

    • Inventory in-scope AWS accounts, Azure subscriptions and GCP projects
    • Select the matching CIS Foundations Benchmark version per provider
    • Provision read-only assessor roles and confirm access
    • Agree excluded regions, services and maintenance windows
  2. 02

    Evidence and Config Collection

    Using read-only roles we pull configuration across IAM, networking, storage, logging and compute. We snapshot the state so findings are reproducible and tied to evidence.

    OutputTimestamped Configuration Evidence Set

    Activities

    • Export IAM users, roles, policies and key age data
    • Capture security group, NACL and VPC peering configuration
    • Record storage bucket ACLs, encryption and public access settings
    • Snapshot CloudTrail, Azure Monitor and GCP audit log settings
  3. 03

    Benchmark Comparison

    We run automated checks with ScoutSuite, Prowler and provider-native tooling, then map results to CIS controls and your own policy where you have one.

    OutputDraft CIS Benchmark Scorecard

    Activities

    • Run Prowler and ScoutSuite across every in-scope account
    • Pull findings from Security Hub and Defender for Cloud
    • Map each result to its CIS Foundations control number
    • Flag deviations from your own internal cloud policy
  4. 04

    Manual Review of Risky Settings

    We manually verify the high-impact items: public exposure, over-broad IAM, missing encryption, and gaps in logging. This filters false positives and catches issues benchmarks miss.

    OutputValidated Exposure List

    Activities

    • Confirm which buckets and endpoints are reachable from the internet
    • Trace wildcard IAM permissions and privilege escalation paths
    • Check encryption at rest and key rotation on data stores
    • Verify MFA and conditional access on privileged identities
    • Discard false positives with a documented reason
  5. 05

    Prioritised Findings

    Each finding is rated by real exposure and blast radius, with the affected resources listed so your team can act without hunting.

    OutputCloud Configuration Findings Report

    Activities

    • Rate each finding by exposure and blast radius
    • List affected resource ARNs and IDs per finding
    • Group findings by owning team and account
    • Walk the engineering team through the top items
  6. 06

    Remediation and Re-Check

    We hand over fix guidance mapped to each control, then re-run the checks after your changes to confirm the scorecard has moved.

    OutputRe-Check Report and Updated Scorecard

    Activities

    • Write fix steps and Terraform snippets per control
    • Support your team through the change windows
    • Re-run Prowler and ScoutSuite after the fixes land
    • Reissue the scorecard showing the movement

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Cloud Security Configuration Assessment scope, running left to right in three stages. Stage one, what we run, 9 tools and techniques: ScoutSuite, Prowler, CIS-CAT Pro, AWS Config, AWS Security Hub, Microsoft Defender for Cloud, Azure Security Center, Trivy, gcloud and Cloud Asset Inventory. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 7 published standards: CIS AWS Foundations Benchmark, CIS Microsoft Azure Foundations Benchmark, CIS Google Cloud Platform Foundations Benchmark, CIS Kubernetes Benchmark, NIST SP 800-53, AWS, Azure and GCP Well-Architected security baselines, MITRE ATT&CK for Cloud.

What We Run

9 tools

  • ScoutSuite
  • Prowler
  • CIS-CAT Pro
  • AWS Config
  • AWS Security Hub
  • Microsoft Defender for Cloud
  • Azure Security Center
  • Trivy
  • gcloud and Cloud Asset Inventory

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

7 standards

  • CISAWS Foundations
  • CISMicrosoft Azure Foundations
  • CISGoogle Cloud Platform Foundations
  • CISKubernetes
  • NIST SP 800-53
  • CSPAWS, Azure, GCPWell-Architected
  • MITRE ATT&CK for Cloud
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Cloud configuration findings report
  • CIS benchmark scorecard by account
  • Cloud hardening runbook
  • Re-check report after remediation

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Do you need write access to our cloud accounts?

No. We work from read-only roles. You keep control of every change, and we give you the exact steps to apply.

Which providers do you cover?

AWS, Azure and GCP, using the matching CIS Foundations Benchmark for each. We can also review Kubernetes clusters against the CIS Kubernetes Benchmark.

How is this different from our cloud provider's security dashboard?

Native dashboards flag issues but rarely rank them by real exposure or explain the fix. We validate findings by hand, cut the noise, and give you a runbook your team can follow.

Keep Moving Through Hardening and Configuration Review

Service 1 of 5 in this practice area