Home/Services/Cloud Security Configuration Review
security service

Cloud Security Configuration Review

Cloud configuration review across Europe: CIS-benchmark audit of IAM, storage, logging, encryption on AWS, Azure, GCP. Fixed price. Get a fixed quote.

Manual, expert-ledEvidence-based findingsFree remediation retest

A cloud configuration review checks every meaningful setting in your AWS, Azure or GCP environment against a hardened baseline and tells you, in order of risk, exactly what to change. Where a pentest proves what an attacker could do, this is the exhaustive audit that makes sure nothing was left open in the first place.

What a cloud configuration review actually covers

Cloud environments drift. A setting that was safe at launch loosens over time as teams ship features, grant access “just for now”, and stand up new services faster than anyone documents them. A configuration review is the systematic sweep that catches that drift: not a hunt for one clever attack path, but a complete pass over identity, storage, networking, logging, encryption and the guardrails that are supposed to hold the whole thing together. The point is coverage. We check the settings you know about and the ones you forgot you had.

A full review typically spans:

Identity and access: users, roles, policies, MFA enforcement and dormant or over-privileged accounts
Storage and databases: public exposure, encryption at rest, backup and retention settings
Network configuration: security groups, NSGs, firewall rules, public endpoints and peering
Logging and monitoring: CloudTrail, Azure Monitor, audit logs, retention and alerting coverage
Encryption and key management: KMS, Key Vault, key rotation and who can use each key
Account-level guardrails: SCPs, Azure Policy, organisation policies and landing-zone hygiene

How we run a cloud configuration review

The review is read-only and evidence-based. We work from audit or security-reader access to your environment and pull the configuration directly, so every finding is grounded in your real settings rather than an interview or a diagram. Automated collection gives us breadth quickly; a human then reviews the results, discards the noise, and works out which findings actually carry risk in your context. That second step is what separates a useful review from a raw benchmark dump.

Access and scoping

We agree which accounts, subscriptions and projects are in scope and take read-only access. There is nothing intrusive here, so a review runs comfortably against production without any risk to availability, which is one reason many teams start with a configuration review before booking a full penetration test.

Automated collection and benchmarking

We gather configuration across the whole estate and measure it against the CIS Benchmark for your provider and each provider’s own security guidance. This produces the raw picture: every control, its current state, and where it deviates from the hardened baseline.

Manual review and prioritisation

Then the real work. A benchmark will happily flag a hundred deviations, many of which do not matter for how you actually operate. We read each one in context, confirm the ones that represent genuine exposure, weed out the false positives, and rank what is left by real business risk. You get a short list of things that matter, not a spreadsheet nobody will read.

Reporting and re-review

The output is an executive summary and a technical report where every finding has its risk, the affected resources, and a precise remediation step. After you make the changes, we re-review the affected controls for free to confirm the environment now meets the baseline and has not drifted elsewhere in the process.

Read-only
safe to run against production
100%
findings reviewed by hand, not raw benchmark output
Free
re-review after you fix

The gaps we find most often

Across AWS, Azure and GCP the same handful of configuration gaps turn up again and again, usually because they are easy to create and invisible until someone looks.

Excess and stale permissions

Identities accumulate rights and rarely give them back. We consistently find users and roles with far more access than their job needs, service credentials that have not been rotated in years, and accounts belonging to people who left. Tightening this is the single highest-value outcome of most reviews.

Logging that would not help after a breach

Audit logging switched off in some accounts, logs with a retention period too short to investigate an incident, and no alerting on the events that actually signal compromise. Plenty of environments would not be able to reconstruct what happened after an attack. We check that the record you would need actually exists.

Storage and encryption gaps

Buckets and volumes without encryption at rest, backups that are unencrypted or missing entirely, and storage quietly reachable from the public internet. We check exposure and encryption together, because one without the other still leaves data at risk.

Missing account guardrails

Without organisation-level controls such as service control policies or Azure Policy, nothing stops a team from reintroducing yesterday’s misconfiguration tomorrow. We assess whether preventative guardrails exist, so the fixes from this review actually stay fixed.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

What you get

The report is written for the people who own the environment. Leadership sees where the estate stands against a recognised baseline and which gaps carry the most risk, and engineers get the exact resource, the current value, the target value and the step to get there for every finding. It reads as a work list, ordered by priority, not as an undifferentiated audit dump.

We also flag the systemic patterns behind individual findings, such as an account with no guardrails or a permission model that keeps growing, because fixing those stops the same gaps reappearing after the next sprint. The free re-review then confirms the changes landed and the baseline holds.

Standards and compliance

The review is built to line up with the frameworks your auditors expect and to produce evidence you can hand over.

CIS Benchmarks

The CIS Benchmarks for AWS, Azure and GCP are our primary yardstick. They give a widely recognised definition of a hardened configuration and a clear pass or fail for each control, which makes remediation and future measurement straightforward.

ISO 27001, SOC 2 and PCI DSS

A configuration review produces strong evidence for the technical controls these frameworks require, and the report and attestation letter are structured to slot into your audit. Tell us which framework you answer to and we map the findings to it.

Cross-reference: penetration testing

A configuration review tells you what is misconfigured; a penetration test proves what an attacker would actually do with it. The two are complementary, and where you need the adversarial view rather than the exhaustive audit, our cloud penetration testing service covers that ground.

Review, remediate, and keep the drift out

A one-off review that finds two hundred issues and leaves you to fix them is only half the job. The value comes from closing the gaps and then stopping them from reopening, so we structure the engagement around all three stages.

Review

The first pass establishes the baseline: where the estate stands today against the CIS Benchmark and provider guidance, and which deviations matter. This is the snapshot everything else is measured against, and for many teams it is the first time anyone has looked at the whole environment at once rather than one account at a time.

Remediate

Findings come as a prioritised work list with the exact change for each one, so your team can start at the top and work down. Where a fix is unfamiliar or touches something fragile, we walk your engineers through it and explain the reasoning, so the remediation lands cleanly and nobody breaks a working service in the name of a benchmark control.

Prevent drift

The hardest part is staying secure after the review. We recommend the preventative guardrails, such as service control policies, Azure Policy or organisation policies, and the automated configuration checks that catch a bad setting the moment it is created rather than at the next audit. A review that also leaves you with the means to hold the line is worth far more than a snapshot that goes stale in a month.

Why a manual review beats a raw benchmark score

You can run an open-source benchmark tool yourself in an afternoon and get a long list of failed controls. The problem is that the list treats a public production bucket and a missing tag with almost equal weight, and it has no idea which findings matter for your business. Turning that raw output into a ranked, de-duplicated, context-aware plan is the work, and it is why an aws cloud configuration review or an azure cloud configuration review from an engineer is worth more than the tool that produced the first draft. A number on a dashboard does not fix anything; a prioritised plan does. The tool tells you a control failed; the engineer tells you whether that failure is a five-minute change or the tip of a design problem, and which one to spend your team’s limited time on first.

Pricing

Pricing depends on scope: the number of accounts, subscriptions or projects, how many cloud providers are involved, and the size and complexity of the estate. A review is lighter than a full penetration test, and priced accordingly. Here is the shape of a typical European engagement.

Engagement What’s included Timeline Price
Essential Single account or subscription, CIS-benchmark review across IAM, storage, network and logging, prioritized report, free re-review 3–5 working days from €1,800
Standard Multi-account environment, full config review plus encryption, guardrails and monitoring coverage, exec + technical report 5–8 working days €3,000–€7,000
Advanced Large or multi-cloud estate, landing-zone and organisation-policy review, drift analysis and remediation workshop 8–14 working days €7,000–€18,000
Compliance add-on Mapping and attestation letter for ISO 27001, SOC 2, PCI DSS or DORA with any tier from €800
Custom / multi-cloud Full estate across AWS, Azure and GCP, scoped after a call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a re-review included. Get a fixed quote

FAQ

How much does a cloud configuration review cost?
Cloud configuration review cost starts from €1,800 for a single account and scales with the number of accounts and cloud providers. It is lighter than a full pentest, and you get a fixed price after a free scoping call.
How is this different from cloud penetration testing?
A configuration review is an exhaustive read-only audit of your settings against a hardened baseline, while a penetration test actively exploits weaknesses to prove impact. Many teams start with a review to clean up the obvious gaps, then book a pentest for the adversarial view.
Will the review affect our live environment?
No. It is entirely read-only. We work from audit or security-reader access and never change or disrupt anything, which is why a review is safe to run directly against production.
What access do you need?
Read-only audit or security-reader access to the accounts, subscriptions or projects in scope. We help you set up a scoped role with least privilege, and it can be revoked the moment the review is done.
What do you actually deliver?
An executive summary and a technical report where every finding has the affected resource, its current and target state, and a precise fix, ranked by risk. A free re-review after you remediate confirms the baseline holds.
Does this help with ISO 27001 or SOC 2?
Yes. A cloud security configuration review produces strong evidence for the technical controls ISO 27001, SOC 2 and PCI DSS require, and the report and attestation letter are built to slot into your audit.
Do you cover AWS, Azure and GCP?
Yes. We run an aws cloud configuration review, an azure cloud configuration review or a GCP review against the relevant CIS Benchmark and provider guidance, and we handle mixed multi-cloud estates as one engagement.
Do you work with clients across Europe?
We are a European cloud configuration review company and provider working with clients across Europe and remotely worldwide, so your environment’s region is not a constraint.

Related services

Who needs this

Teams that have grown fast in the cloud and are unsure what has drifted; companies preparing for an ISO 27001 or SOC 2 audit who need their configuration cleaned up first; and platform owners who want a prioritised, baseline-driven work list rather than a raw benchmark score. It also suits organisations that inherited a cloud estate through an acquisition or a departing engineer and simply need to know what they now own and how exposed it is.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Cloud Security Configuration Review"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.