Cloud Security Configuration Review
Cloud configuration review across Europe: CIS-benchmark audit of IAM, storage, logging, encryption on AWS, Azure, GCP. Fixed price. Get a fixed quote.
A cloud configuration review checks every meaningful setting in your AWS, Azure or GCP environment against a hardened baseline and tells you, in order of risk, exactly what to change. Where a pentest proves what an attacker could do, this is the exhaustive audit that makes sure nothing was left open in the first place.
What a cloud configuration review actually covers
Cloud environments drift. A setting that was safe at launch loosens over time as teams ship features, grant access “just for now”, and stand up new services faster than anyone documents them. A configuration review is the systematic sweep that catches that drift: not a hunt for one clever attack path, but a complete pass over identity, storage, networking, logging, encryption and the guardrails that are supposed to hold the whole thing together. The point is coverage. We check the settings you know about and the ones you forgot you had.
A full review typically spans:
How we run a cloud configuration review
The review is read-only and evidence-based. We work from audit or security-reader access to your environment and pull the configuration directly, so every finding is grounded in your real settings rather than an interview or a diagram. Automated collection gives us breadth quickly; a human then reviews the results, discards the noise, and works out which findings actually carry risk in your context. That second step is what separates a useful review from a raw benchmark dump.
Access and scoping
We agree which accounts, subscriptions and projects are in scope and take read-only access. There is nothing intrusive here, so a review runs comfortably against production without any risk to availability, which is one reason many teams start with a configuration review before booking a full penetration test.
Automated collection and benchmarking
We gather configuration across the whole estate and measure it against the CIS Benchmark for your provider and each provider’s own security guidance. This produces the raw picture: every control, its current state, and where it deviates from the hardened baseline.
Manual review and prioritisation
Then the real work. A benchmark will happily flag a hundred deviations, many of which do not matter for how you actually operate. We read each one in context, confirm the ones that represent genuine exposure, weed out the false positives, and rank what is left by real business risk. You get a short list of things that matter, not a spreadsheet nobody will read.
Reporting and re-review
The output is an executive summary and a technical report where every finding has its risk, the affected resources, and a precise remediation step. After you make the changes, we re-review the affected controls for free to confirm the environment now meets the baseline and has not drifted elsewhere in the process.
The gaps we find most often
Across AWS, Azure and GCP the same handful of configuration gaps turn up again and again, usually because they are easy to create and invisible until someone looks.
Excess and stale permissions
Identities accumulate rights and rarely give them back. We consistently find users and roles with far more access than their job needs, service credentials that have not been rotated in years, and accounts belonging to people who left. Tightening this is the single highest-value outcome of most reviews.
Logging that would not help after a breach
Audit logging switched off in some accounts, logs with a retention period too short to investigate an incident, and no alerting on the events that actually signal compromise. Plenty of environments would not be able to reconstruct what happened after an attack. We check that the record you would need actually exists.
Storage and encryption gaps
Buckets and volumes without encryption at rest, backups that are unencrypted or missing entirely, and storage quietly reachable from the public internet. We check exposure and encryption together, because one without the other still leaves data at risk.
Missing account guardrails
Without organisation-level controls such as service control policies or Azure Policy, nothing stops a team from reintroducing yesterday’s misconfiguration tomorrow. We assess whether preventative guardrails exist, so the fixes from this review actually stay fixed.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you get
The report is written for the people who own the environment. Leadership sees where the estate stands against a recognised baseline and which gaps carry the most risk, and engineers get the exact resource, the current value, the target value and the step to get there for every finding. It reads as a work list, ordered by priority, not as an undifferentiated audit dump.
We also flag the systemic patterns behind individual findings, such as an account with no guardrails or a permission model that keeps growing, because fixing those stops the same gaps reappearing after the next sprint. The free re-review then confirms the changes landed and the baseline holds.
Standards and compliance
The review is built to line up with the frameworks your auditors expect and to produce evidence you can hand over.
CIS Benchmarks
The CIS Benchmarks for AWS, Azure and GCP are our primary yardstick. They give a widely recognised definition of a hardened configuration and a clear pass or fail for each control, which makes remediation and future measurement straightforward.
ISO 27001, SOC 2 and PCI DSS
A configuration review produces strong evidence for the technical controls these frameworks require, and the report and attestation letter are structured to slot into your audit. Tell us which framework you answer to and we map the findings to it.
Cross-reference: penetration testing
A configuration review tells you what is misconfigured; a penetration test proves what an attacker would actually do with it. The two are complementary, and where you need the adversarial view rather than the exhaustive audit, our cloud penetration testing service covers that ground.
Review, remediate, and keep the drift out
A one-off review that finds two hundred issues and leaves you to fix them is only half the job. The value comes from closing the gaps and then stopping them from reopening, so we structure the engagement around all three stages.
Review
The first pass establishes the baseline: where the estate stands today against the CIS Benchmark and provider guidance, and which deviations matter. This is the snapshot everything else is measured against, and for many teams it is the first time anyone has looked at the whole environment at once rather than one account at a time.
Remediate
Findings come as a prioritised work list with the exact change for each one, so your team can start at the top and work down. Where a fix is unfamiliar or touches something fragile, we walk your engineers through it and explain the reasoning, so the remediation lands cleanly and nobody breaks a working service in the name of a benchmark control.
Prevent drift
The hardest part is staying secure after the review. We recommend the preventative guardrails, such as service control policies, Azure Policy or organisation policies, and the automated configuration checks that catch a bad setting the moment it is created rather than at the next audit. A review that also leaves you with the means to hold the line is worth far more than a snapshot that goes stale in a month.
Why a manual review beats a raw benchmark score
You can run an open-source benchmark tool yourself in an afternoon and get a long list of failed controls. The problem is that the list treats a public production bucket and a missing tag with almost equal weight, and it has no idea which findings matter for your business. Turning that raw output into a ranked, de-duplicated, context-aware plan is the work, and it is why an aws cloud configuration review or an azure cloud configuration review from an engineer is worth more than the tool that produced the first draft. A number on a dashboard does not fix anything; a prioritised plan does. The tool tells you a control failed; the engineer tells you whether that failure is a five-minute change or the tip of a design problem, and which one to spend your team’s limited time on first.
Pricing
Pricing depends on scope: the number of accounts, subscriptions or projects, how many cloud providers are involved, and the size and complexity of the estate. A review is lighter than a full penetration test, and priced accordingly. Here is the shape of a typical European engagement.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Essential | Single account or subscription, CIS-benchmark review across IAM, storage, network and logging, prioritized report, free re-review | 3–5 working days | from €1,800 |
| Standard | Multi-account environment, full config review plus encryption, guardrails and monitoring coverage, exec + technical report | 5–8 working days | €3,000–€7,000 |
| Advanced | Large or multi-cloud estate, landing-zone and organisation-policy review, drift analysis and remediation workshop | 8–14 working days | €7,000–€18,000 |
| Compliance add-on | Mapping and attestation letter for ISO 27001, SOC 2, PCI DSS or DORA | with any tier | from €800 |
| Custom / multi-cloud | Full estate across AWS, Azure and GCP, scoped after a call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a re-review included. Get a fixed quote
FAQ
How much does a cloud configuration review cost?
How is this different from cloud penetration testing?
Will the review affect our live environment?
What access do you need?
What do you actually deliver?
Does this help with ISO 27001 or SOC 2?
Do you cover AWS, Azure and GCP?
Do you work with clients across Europe?
Related services
Teams that have grown fast in the cloud and are unsure what has drifted; companies preparing for an ISO 27001 or SOC 2 audit who need their configuration cleaned up first; and platform owners who want a prioritised, baseline-driven work list rather than a raw benchmark score. It also suits organisations that inherited a cloud estate through an acquisition or a departing engineer and simply need to know what they now own and how exposed it is.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.