← Consultancy
Cloud security

Secure the cloud you already run

An expert review of your AWS, Azure or Google Cloud environment, with prioritised fixes your team can apply or our engineers can implement, a retest to confirm fixes, and a logging and monitoring plan so it stays secure after we leave.

Read-only accessCIS benchmark mappedGuidance or hands-on fixesRetest included
Cloud posture · Azure + AWSCIS benchmark
Identity
62
Network
71
Data
80
Logging
48
Compute
66
HIGH · Storage account allows public blob access Recommendation: disable public blob access at the storage-account level and review existing public containers. Remediation guidance included with every finding
Why it's different

A cloud review should leave your cloud safer, not just documented

The usual way With Touchpoint
Automated tool output with hundreds of low-value alerts Expert review that separates the ten issues that matter from the noise
Findings say what’s wrong, not how to fix it Every finding comes with step-by-step fixes, applied by your team or ours
A snapshot that drifts out of date within weeks Drift checks and a re-review schedule agreed at the end
Logging gaps noted in the report Logging switched on and sent to your SIEM or SOC provider
Retest is extra Retest within the engagement window included
What we review

Six areas where cloud breaches start

Identity & access Over-privileged roles, stale accounts, service principals, conditional access and MFA coverage.
Network exposure Public endpoints, security groups, firewall rules and paths from the internet to your workloads.
Data protection Public storage, encryption at rest and in transit, key management and backup protection.
Logging & detection Audit logs, activity logs and threat detection services: switched on, retained and monitored.
Compute & containers VM hardening, container images, Kubernetes configuration and serverless permissions.
Governance Account and subscription structure, guardrails, tagging and policy enforcement.
How it works

Two weeks from access to a safer cloud

  1. 01 Connect You grant read-only access. No agents, and no changes without your written approval.
  2. 02 Assess Automated checks against CIS benchmarks, then expert review of identity, exposure and data paths.
  3. 03 Prioritise Findings ranked by how exploitable they are, not how many there are.
  4. 04 Advise We walk your team through each finding and the recommended fix. Your team makes the changes, or our engineers do under a separate scope.
  5. 05 Retest & watch We confirm the fixes and check your logging is in place.
What you get

A clear plan your team can act on

Written for both the engineers who fix the issues and the leaders who need to know the risk is gone.

✓ Executive summaryYour cloud risk in plain language, with the top priorities.
✓ Prioritised findingsRated Critical to Low, with affected resources and evidence.
✓ Remediation guidanceStep-by-step recommendations for each finding, written for your engineers.
✓ Benchmark mappingEach finding mapped to CIS, NIST and ISO 27001 controls.
✓ Retest confirmationEvidence that fixed findings are closed.
✓ Logging planWhich cloud logs to enable and where to send them.
Engagement options

From a quick check to ongoing assurance

Fast start Posture review For a clear picture of cloud risk before an audit, funding round or migration.
  • ✓One cloud platform
  • ✓CIS benchmark assessment
  • ✓Prioritised findings with remediation guidance
  • ✓Executive summary
Get a fixed quote →
Most chosen Review & advise For teams that want expert guidance while they fix the priority issues.
  • ✓Everything in Posture review
  • ✓Remediation workshop with your team
  • ✓Retest of fixed findings
  • ✓Logging and monitoring review
Get a fixed quote →
Ongoing Continuous cloud assurance For growing estates that change every week.
  • ✓Quarterly expert reviews
  • ✓Drift checks between reviews
  • ✓Priority support for new services
  • ✓Board-ready cloud risk summary
Get a fixed quote →
Questions

Before you ask

What access do you need?+

Read-only roles for the review. Your team applies fixes, or our engineers can under a separate, written change scope.

Which platforms do you cover?+

AWS, Microsoft Azure and Google Cloud, including hybrid and multi-cloud estates.

Is this a penetration test?+

No. A review finds misconfigurations; a cloud pentest actively exploits them. Many teams do the review first, then a pentest.

How long does it take?+

A posture review for one platform typically takes around two weeks from access to report.

See your cloud the way an attacker would

Tell us which platforms you run. We’ll come back with a fixed-price scope and a start date.

Book a cloud review
Other consultancy services Penetration testing→ Tabletop exercises→ vCISO→ Engineering & implementation→