forumNew topic

We moved the company entirely to the cloud, but where do we start with a cloud security assessment?

LLale A***Member
Job title
Site Manager
Sector
IT services
Organization type
cooperative
Joined
Jul 2023
Message
86
#1

We are a 14-person logistics consultancy based in London. Four months ago, we migrated our file storage, accounting records, and CRM entirely to cloud infrastructure. We paid an external freelance specialist around 6,500 GBP for the migration. Everything is working fine right now, but once the specialist finished and left, we realized that no retrospective security audit or testing was ever carried out.

Last week, an enterprise client sent over a vendor audit questionnaire requesting the results of our cloud security assessment. I don't have a report, nor do I even know what we're supposed to check. What are the concrete steps we can review internally? Which stages can our in-house IT person handle, and at what point does bringing in an external cybersecurity firm become unavoidable?

ÖÖzge U***Member
Job title
Marketing manager
Sector
Real estate
Organization type
120-person company
Joined
Apr 2023
Message
18
Most Helpful#2

Short answer: When conducting a cloud security assessment, your first priorities are enforcing multi-factor authentication across all user accounts, locking down publicly exposed storage buckets, and documenting who has access to which data. An in-house technical staffer can complete these foundational checks within a few days; an external audit only becomes necessary when regulatory compliance or enterprise client contracts explicitly mandate it.

The assessment process you can run internally breaks down into four main pillars. Step one is identity and access management: revoke access for former employees, separate admin accounts from daily tasks, and enforce the principle of least privilege. Step two is data security: segregate sensitive data like client contracts and financial records, and ensure cloud storage buckets are never exposed to the public internet, even with read-only permissions.

Step three is your backup and disaster recovery policy. You must verify that data backups run automatically and that these backups are actually tested and restored at least once every quarter. Step four is logging and monitoring, ensuring that access logs are retained and alerts are triggered for anomalous login attempts.

If your enterprise client is demanding an independent auditor's report (such as third-party certified compliance attestation) or if you store customer credit card data, an internal review alone will not suffice. At that stage, you will need to budget for an external security assessment.

YYiğit A***VeteranCommunity member
Joined
Jan 2025
Message
2
#3

The very first thing you should do is check your storage permissions. While cloud providers usually keep buckets private by default, people often set them to public read access during migrations just to make things easier. Also, check whether management ports on your virtual servers (especially SSH or RDP) are open to the entire internet. Restrict them strictly to your office's static IP address.

LLeylaMember
Job title
Purchasing
Joined
Apr 2024
Message
86
#4

We run a financial brokerage office of similar size. When we received a similar vendor questionnaire last year, we hired an independent security consultant. They billed us 2,200 GBP for a four-day configuration review. The resulting report flagged eight critical vulnerabilities, six of which were just misconfigured user permissions. If you do the basic cleanup yourselves before an external audit, costs drop significantly.

VVahide U***MemberCommunity member
Joined
Jan 2024
Message
139
#5

tell your it guy right away to enforce u2f security keys or an authenticator app on all admin accounts... sms verification isn't considered secure anymore. anyway the first thing they look at on client audit forms is usually your mfa policy anyway.

AAhmet E***Member
Job title
System support specialist
Sector
Electrical-electronics
Organization type
chain store
Joined
Mar 2023
Message
197
#6

Internal reports based on canned checklists downloaded off the internet won't satisfy most enterprise clients. Many checklists just ask about policies that exist on paper without showing actual vulnerabilities in the system. If your client has to run the audit form by their risk department, it'll be very tough to sign that contract without a signed external assessment report.

GGökhan C***Member
Job title
Studio Founder
Sector
Education
Organization type
chain store
Joined
Jan 2023
Message
64
#7

Here's what you need to knock out on day one of your internal audit: 1) Enforce two-factor authentication on all employee logins. 2) Revoke old, unused API keys and service accounts created during the migration. 3) Open up your cloud provider's built-in security alert dashboard and resolve the high-priority risks one by one. 4) Verify that your data backups are kept isolated in a different region.

İİlker A***MemberCommunity member
Joined
Feb 2023
Message
292
#8

Didn't the contractor who handled the migration leave you handover documentation? That document should state which virtual resources were set up, where encryption keys are stored, and how the database is protected. If you don't have something like that, shouldn't your first step be going back to the contractor and demanding a system inventory?

MMert Ö***Expert
Job title
Courier coordinator
Sector
Energy
Organization type
early-stage startup
Joined
Jan 2023
Message
157
#9

The security questionnaires sent by enterprise clients are usually based on international information security standards. These forms will ask whether your system has undergone penetration testing and what your incident response plan is. Your in-house tech person can patch basic misconfigurations, but obtaining an independent report for legal commitments given to the client will protect you from future liability.

GGürkan A***Member
Job title
Studio Founder
Sector
Software
Organization type
chain store
Joined
Jul 2024
Message
139
#10

The quickest thing you can do tomorrow morning is open the built-in security and compliance center in your cloud dashboard. Providers usually offer a free security score alongside a list of deficiencies. Even just fixing the critical red alerts and grabbing a screenshot is a good first step to show the client that the process is underway.

FFiliz Ç***Member
Job title
General coordinator
Sector
Leather
Organization type
medium-sized business
Joined
Jul 2025
Message
13
#11

I'd appreciate it if you shared the outcome. When making decisions, write down the worst-case scenario too, not just the best.

That's all, sorry if I went on too long.

AAhmet A***MemberCommunity member
Joined
Oct 2023
Message
63
#12

Let me summarize what's been said so far. The harder it is to reverse a decision, the slower you should make it.

Forgotten test environments are more often the entry point than live systems. If you have questions, write them; I'll answer as best I can.

BBarış V***Member
Job title
Front office accounting
Sector
Food wholesale
Organization type
a company within a holding
Joined
Jan 2023
Message
2
#13

We've heard this a lot but it never happened like that for us. Just because everyone does it doesn't mean it's right.

If you dont write this down from the start it leads to arguments later. Of course it varies if your situation is different.

VVildan Ş***Expert
Job title
Agency Founder
Sector
Freight
Organization type
cooperative
Joined
Sep 2023
Message
113

Doki · Server maintenance contract · 2026

#14

I felt relieved reading this answer, so it's not just me. When making a decision, first look at what data you have on hand.

FFeyza K***Member
Job title
Intern
Sector
Catering
Organization type
workshop
Joined
Nov 2024
Message
2
#15

I'm curious too. Everything goes well for the first three months; problems arise in the fourth.

This is my opinion, I'm not claiming it's absolute truth.

ÖÖzgür G***Member
Job title
Software developer
Sector
Cosmetics
Organization type
8-person team
Joined
Jun 2023
Message
16
#16

I have a question, don't want to go off-topic though. Most incidents start with a leaked password, not a vulnerability.

Proven by experience.

FFerhat E***MemberCommunity member
Joined
Nov 2025
Message
134
#17

There is something to watch out for. If it's your first time, start small; scaling comes later.

If you have questions, write them; I'll answer as best I can.

YYavuz G***Member
Job title
Courier coordinator
Sector
Packaging
Organization type
family business
Joined
Jun 2025
Message
45

Doki · Log management setup · 2023

#18

There's a trap here, let me mention it. The real issue isn't the number, but what it's based on.

Good luck with that.

OOrhan T***MemberCommunity member
Joined
Mar 2024
Message
242
#19

To get into the details: The biggest time-waster for us was not knowing who had the final say.

Processes without records never improve, because you don't know what to fix.

CCansu C***MemberCommunity member
Joined
Mar 2022
Message
66
#20

How did you solve this? I mean when making a decision first look at what data you have on hand.

If I were you I'd go this route.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic