Services / Cloud review

Cloud configuration review

Most cloud incidents start with configuration and identity, not exotic exploits. This review looks at how your environment is actually set up, and what to fix first.

What's included

  • Identity and access review: privileged roles, conditional access, service principals and key rotation
  • Network exposure: what is reachable from the internet and why
  • Data protection: storage, encryption and secret handling
  • Logging and detection coverage, so an incident would actually be visible
  • Findings measured against recognised cloud security baselines, risk-rated and prioritised

Scope

  • One Azure subscription or a defined set of workloads
  • Identity and access, network exposure, secrets, logging and monitoring
  • Read-only access; no changes are made to your environment

Who it's for

  • Teams running production workloads in Azure without a dedicated security engineer
  • Companies preparing for ISO 27001 or a customer security assessment
  • Anyone who has grown quickly and never had the environment reviewed

What you get

  • Findings report with prioritised remediation
  • Quick wins list your team can action in the first week
  • Debrief call

Report delivered within 5 working days of testing ending. One retest of fixed findings included, within 60 days.

deliverables/ What lands in your inbox
report/
  technical-report.pdf      findings, evidence, fixes
  management-summary.pdf    for the board or a customer
  findings.csv              straight into your tracker
retest/
  retest-letter.pdf         after you've fixed things

How the engagement runs

01

Scope

A short call about the application, its roles and what would hurt most if it broke. You get a fixed-price proposal and dates.

02

Authorise

Rules of engagement, authorisation and an NDA if you want one. Testing starts only once these are signed.

03

Map

Reconnaissance and mapping: every route, role, parameter and API call that makes up the attack surface.

04

Test

Manual testing against the OWASP guides, supported by tooling. Critical findings are reported the moment they are confirmed, not held for the report.

05

Report

Findings with evidence, reproduction steps, CVSS ratings and fix guidance written for developers, plus a summary for everyone else.

06

Retest

Once you have fixed things, a retest confirms it, and you get a letter you can show customers or auditors.

Questions

Do you need write access?

No. A read-only role over the subscriptions in scope is enough, and we will tell you exactly what permissions are needed before you grant anything.

Is this a penetration test?

No. It is a configuration and identity review. It pairs well with an application test, and the two together cover both the application and the platform it runs on.

request a scope

Get a fixed price for your environment

A 20-minute scoping call, then a fixed-price proposal. No obligation, and no pressure to buy a bigger scope than you need.

Fixed-price quote within 2 working days of the scoping call · Report delivered within 5 working days of testing ending · One retest of fixed findings included, within 60 days