Security & Compliance

Cloud Security

Posture review and hardening across AWS, Azure and GCP, ending in a prioritised remediation plan.

Overview

Cloud breaches are rarely exotic. They are overly permissive identity, a storage bucket exposed during a hurried deployment, a management port open to the internet, and logging that was never enabled. The controls that prevent them are well understood and unglamorous.

We review your environment against CIS benchmarks, the provider’s own security baselines and the expectations of NZISM and the Essential Eight where they apply, then rank every finding by exploitability and business impact so the work can be sequenced sensibly.

What you get

Findings you can action

Every item carries a severity, an effort estimate and a named owner, not just a control reference.

Identity examined first

Over-privileged roles and long-lived keys are the most common real-world entry point, so they lead the review.

Logging that would help

Verification that you would actually be able to investigate an incident with the telemetry you currently retain.

Remediation available

We can implement the fixes as well as identify them, which is usually the faster path.

How we work

  1. 01

    Scope

    Accounts, subscriptions and workloads in scope agreed in writing, along with the standards being measured against.

  2. 02

    Review

    Automated posture tooling combined with manual review of identity, networking, data handling and logging.

  3. 03

    Prioritise

    Findings ranked by exploitability and business impact, with quick wins separated from structural work.

  4. 04

    Remediate

    Fixes delivered by us or by your team with our support, then re-tested to confirm closure.

Common questions

How is this different from a penetration test?

A posture review examines configuration and design from the inside. A penetration test attempts to exploit from the outside. They answer different questions and complement each other.

Which standard should we align to?

It depends on your customers. NZISM and the Essential Eight for government-adjacent work, CIS benchmarks as a solid technical baseline, ISO 27001 or SOC 2 when enterprise customers ask.

Will the review disrupt production?

No. It is read-only. Any change to the environment is agreed separately as remediation work.

Often paired with

Security & Compliance

Vulnerability Assessment

Continuous scanning across infrastructure, containers and dependencies — with triage so the list stays actionable.

Read more

Ready to talk about cloud security?

We will tell you what we would do, roughly what it costs, and whether it is worth doing yet.

Book a meeting