Services / Cloud review
Cloud configuration review
Most cloud incidents start with configuration and identity, not exotic exploits. This review looks at how your environment is actually set up, and what to fix first.
What's included
- Identity and access review: privileged roles, conditional access, service principals and key rotation
- Network exposure: what is reachable from the internet and why
- Data protection: storage, encryption and secret handling
- Logging and detection coverage, so an incident would actually be visible
- Findings measured against recognised cloud security baselines, risk-rated and prioritised
Scope
- One Azure subscription or a defined set of workloads
- Identity and access, network exposure, secrets, logging and monitoring
- Read-only access; no changes are made to your environment
Who it's for
- Teams running production workloads in Azure without a dedicated security engineer
- Companies preparing for ISO 27001 or a customer security assessment
- Anyone who has grown quickly and never had the environment reviewed
What you get
- Findings report with prioritised remediation
- Quick wins list your team can action in the first week
- Debrief call
Report delivered within 5 working days of testing ending. One retest of fixed findings included, within 60 days.
report/ technical-report.pdf findings, evidence, fixes management-summary.pdf for the board or a customer findings.csv straight into your tracker retest/ retest-letter.pdf after you've fixed things
How the engagement runs
Scope
A short call about the application, its roles and what would hurt most if it broke. You get a fixed-price proposal and dates.
Authorise
Rules of engagement, authorisation and an NDA if you want one. Testing starts only once these are signed.
Map
Reconnaissance and mapping: every route, role, parameter and API call that makes up the attack surface.
Test
Manual testing against the OWASP guides, supported by tooling. Critical findings are reported the moment they are confirmed, not held for the report.
Report
Findings with evidence, reproduction steps, CVSS ratings and fix guidance written for developers, plus a summary for everyone else.
Retest
Once you have fixed things, a retest confirms it, and you get a letter you can show customers or auditors.
Questions
Do you need write access?
No. A read-only role over the subscriptions in scope is enough, and we will tell you exactly what permissions are needed before you grant anything.
Is this a penetration test?
No. It is a configuration and identity review. It pairs well with an application test, and the two together cover both the application and the platform it runs on.
Other services
Web application & API test
Manual testing of your web application and the APIs behind it, authenticated as every user role, against the OWASP testing guides.
From £2,950
Details →Medical-device & SaMD web application test
The same testing, plus the evidence structure that regulatory submissions and notified-body reviews ask for.
From £5,950
Details →request a scope
Get a fixed price for your environment
A 20-minute scoping call, then a fixed-price proposal. No obligation, and no pressure to buy a bigger scope than you need.
Fixed-price quote within 2 working days of the scoping call · Report delivered within 5 working days of testing ending · One retest of fixed findings included, within 60 days