04Practice
Cloud security assessment, architecture and defense for AWS, Azure and Google Cloud
Assessment, architecture and ongoing defense for AWS, Azure, Google Cloud and Microsoft 365: identity-first security, posture management, workload protection and cloud-native detection engineering.
- Name
- Cloud Security
- Line
- 04 · Cloud
- Type
- Practice, engaged on its own or within a program
01The problem
Cloud breaches are configuration breaches.
Many major cloud incidents trace back to the same causes: over-privileged identities, public storage, exposed keys, unmonitored control planes. Traditional network security instincts do not transfer. In the cloud, identity is the perimeter and the control plane is the crown jewel.
Securing cloud environments means engaging with how they actually work: IAM graphs, service configurations, ephemeral workloads and audit telemetry, continuously, not as an annual review.
- Identity is the perimeter
- Privilege-escalation paths through IAM are the cloud equivalent of network lateral movement. We map and cut them.
- Misconfiguration is continuous
- Environments change daily. Point-in-time audits age in weeks. Posture needs guardrails and monitoring, not annual snapshots.
- The control plane must be watched
- Attacker activity in the cloud shows up in audit logs. Cloud-native detection for control-plane abuse catches what endpoint tools cannot see.
02Scope
What cloud security covers.
Cloud Security Assessment
Full-environment review of AWS, Azure or GCP against CIS benchmarks and provider security frameworks, prioritized by exploitability.
Microsoft 365 Security
Hardening of Exchange Online, identity, mail-flow, sharing and audit configuration for a heavily attacked SaaS estate.
Azure & Entra ID Security
Assessment and hardening of Azure workloads and Entra ID: conditional access, privileged roles, app registrations.
AWS Security
IAM analysis, organization structure, GuardDuty/Security Hub operationalization and workload hardening.
Google Cloud Security
GCP organization policy, IAM, workload and logging configuration review and remediation.
Cloud IAM & Entitlements (CIEM)
Mapping of effective permissions and privilege-escalation paths, with least-privilege remediation that sticks.
Cloud Configuration Review
Deep review of specific services (storage, serverless, databases, networking) against hardening baselines.
Cloud Workload Security
Protection for VMs, containers and serverless: runtime controls, image hygiene and vulnerability management.
Container & Kubernetes Security
Cluster hardening, RBAC, admission control, network policy and supply-chain controls for containerized platforms.
Cloud Network Security
Segmentation, private connectivity, egress control and exposure reduction across VPCs and VNets.
CSPM / CNAPP Enablement
Selection and operationalization of posture and workload-protection platforms, tuned so findings get fixed, not ignored.
Cloud Logging & Monitoring
Audit and telemetry architecture: what to log, where to send it and how long to keep it, balanced against cost.
Cloud Detection Engineering
Detection content for control-plane abuse, identity attacks and data exfiltration in cloud-native telemetry.
Cloud Incident Response
Investigation and containment of cloud intrusions: key compromise, token abuse, crypto-mining, data exposure.
Cloud Security Architecture
Landing zones, account structure, guardrails and reference architectures for teams building in the cloud.
03Approach
How a cloud security engagement runs.
Discover
Inventory accounts, subscriptions, identities and data stores, including the shadow ones.
Assess
Configuration, IAM and exposure analysis prioritized by attack-path relevance rather than raw finding count.
Remediate
Hands-on remediation with your platform teams. Our cloud engineering team can make the infrastructure-as-code and platform changes, so findings get fixed as well as reported.
Guard
Preventive guardrails: policies, landing-zone patterns and IaC checks that stop misconfiguration recurring.
Monitor
Cloud-native detection and response wired into your security operations, ours or yours.
04Deliverables
Cloud security deliverables.
- Cloud posture assessment with attack-path prioritization
- IAM and entitlement analysis with least-privilege plan
- Hardening baselines and guardrail policies as code
- Logging and detection architecture for the control plane
- Remediation validation and posture re-measurement
When this work fits
- Teams migrating workloads or born in the cloud
- Organizations running Microsoft 365 at any scale
- Platform teams who inherited sprawling cloud accounts
- Companies whose auditors or customers ask hard cloud questions
05Questions
Cloud security: questions we are asked
AWS, Azure, Google Cloud and Microsoft 365. Each is assessed against its own provider guidance and CIS benchmarks, using the platform’s native security services where they fit.
Yes, as a starting point. That is why engagements end with guardrails and monitoring as well as a report: policy-as-code, IaC checks and detections that keep posture from drifting back.
Yes. Reviewing Terraform, Bicep or CloudFormation catches misconfigurations before deployment and is often the fastest way to fix a class of issues permanently.
Yes. Running AWS alongside Azure or Microsoft 365 is common. We assess each platform on its own terms and give you one coherent risk picture across them.
Identity and access first, because most cloud compromise runs through over-privileged identities. Then network exposure, storage and data protection, logging and detection coverage, workload and container configuration, and the pipeline that deploys infrastructure. Findings are rated by exploitability in your environment and checked against the CIS Benchmarks and the provider's own security guidance.
A posture tool reports individual misconfigurations against a rule set. It does not show how findings combine. A manual assessment traces attack paths: a role that can assume another role, which can read a secret, which opens a production database. It also reviews design decisions no rule covers, and removes findings that are unreachable in practice.
The provider secures the infrastructure it runs: data centers, hardware and the virtualization layer. You secure what you configure: identities, network rules, data, encryption settings, workloads and logging. With managed services the line moves, but identity and data always stay with you. Most cloud incidents arise on the customer side of that line.
Yes. Cluster reviews cover RBAC, network policy, pod security settings, secrets handling, admission control, image provenance and the security of the control plane, measured against the CIS Kubernetes Benchmark and the NSA and CISA Kubernetes hardening guidance. Where deeper assurance is needed, penetration testing can include container escape and cluster takeover paths.
Often alongside
