Identity and permissions
We review users, roles and service accounts against the principle of least privilege. Wildcard permissions, unused keys and accounts without multi-factor authentication are listed.
We review the identity, network and storage settings of your cloud accounts with authorised, read-only access. Publicly exposed resources, over-broad permissions and missing logs are reported in order of importance.
We review users, roles and service accounts against the principle of least privilege. Wildcard permissions, unused keys and accounts without multi-factor authentication are listed.
Internet-facing ports, security groups and subnet separation are examined. A single map shows which resource can be reached from where.
Public storage buckets, unencrypted disks and disabled logging are identified, and a remediation step is written for each item.
The review addresses the four layers of your account separately; findings are grouped and prioritised by layer.
We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.
Each step ends with something concrete in your hands; we move on with your approval.
Together we put the goal, the boundaries and the acceptance criteria in writing.
We assess the current state against agreed criteria and note gaps with evidence.
We share what was done, the result and the next step in a plain report.
We retest fixed findings and confirm with evidence that they are closed.
Which categories are applied is agreed together, based on your target and scope.
We audit your AWS, Azure and Google Cloud accounts with more than 600 checks covering permissions, logging, encryption and network settings.
We check whether file storage in the cloud (buckets) has been left open to everyone on the internet by mistake.
We review the access, permission and network settings of your container platform against secure configuration guidelines.
We scan the container images your applications are packaged in for outdated components with known vulnerabilities.
The figures are the number of checks in our automated security engines. Not every category runs in every test; the ones that fit your target and scope are selected.
Every test runs with your written permission and within the scope we agree together. Tests that could disrupt a service, and social engineering, are planned only with separate written approval. No test proves that a system is completely secure; we report clearly what was and was not found.
What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.
Tell us what you need; we will define the scope together.
Tell us about your projectWe can work on the common public cloud providers and on virtualisation environments you host yourself. Scope, number of accounts and access method are agreed in the first meeting; the review uses read-only permissions.
Yes. Only systems you are authorised for and have approved in writing are assessed.
Scope, time window and methods are agreed in advance; risky steps require your separate approval.
Tell us what you need; we will define the scope together.