Cloud security

Your cloud secured. By default. Not as an option.

IAM audit, network hardening, secrets management, data encryption, suspicious event monitoring. AWS, GCP, Azure, Kubernetes — following CIS Benchmarks and AWS Well-Architected Framework.

  • AWS · GCP · Azure · Kubernetes
  • Least-privilege IAM · secrets · KMS
  • VPC · Security Groups · WAF
  • CIS Benchmarks · SOC 2 ready

The context

82% of cloud breaches come from misconfiguration.

In 2026, cloud attacks are almost never « sophisticated hacks ». 82% come from configuration errors: an accidentally public S3 bucket, an IAM role with `*:*`, an access key committed to a public repo, a Security Group open on 0.0.0.0/0. The cloud exposes so much surface that a single flaw opens the house.

Yet the fundamentals are known: least-privilege IAM, managed secrets (never in clear), private network by default, audit logs enabled, encryption at-rest and in-transit. But between « knowing » and « having actually checked screen by screen on 300 resources », there's a world. Teams ship product, not hardening.

We do the audit for you. CIS Benchmarks, AWS Security Hub, ScoutSuite, Prowler, kube-bench if Kubernetes. Actionable report sorted by criticality with patches ready to apply (Terraform, IaC). We can also implement the hardening if you want.

150+

Controls audited

CIS Benchmarks AWS Foundations (1.5), GCP, Azure covered

< 5d

Audit timeline

Medium-size AWS/GCP account audited in 5 business days

100%

Actionable report

Every finding with proof, severity, Terraform patch

0

Silent false positive

We verify every alert before including it in the report

What we audit

Six cloud hardening axes.

The audit covers the full surface: identities, network, data, app layer, observability, governance.

Identities

IAM & access

Achilles heel #1.

Audit of roles, policies, MFA, key rotation. Detection of excessive privileges (`*:*`, AdministratorAccess on non-admin roles). Least-privilege recommendations with generated policies. SSO, SCP, AWS OUs, Boundary Permissions.

Network

Network & isolation

VPC, Security Groups, WAF.

Audit VPC, Subnets, Routing Tables, Security Groups, NACLs, VPC Endpoints. Detection of SGs open on Internet, overly broad peering, routes to external accounts. WAF rules review, DDoS Shield, Network Firewall.

Secrets

Secrets & KMS

No clear-text keys.

Audit Secrets Manager, Parameter Store, KMS keys. Detection of hardcoded secrets (git history scan, Lambda env vars). Automatic rotation, key policies, envelope encryption for sensitive data.

Data

Data & encryption

Encrypted at-rest and in-transit.

Audit S3 buckets (public access, encryption), RDS (encryption, snapshots), EBS, DynamoDB. Detection of public buckets, unencrypted data, unencrypted backups. TLS 1.2+ in transit mandatory.

Observability

Logs & monitoring

See before it breaks.

Audit CloudTrail, GuardDuty, Security Hub, Config, Inspector. Detective Controls setup (IAM anomalies, root access, critical changes). Slack/PagerDuty alerting on security events. Multi-account log centralisation.

Compliance

Compliance & governance

SOC 2, ISO 27001 ready.

Mapping to SOC 2, ISO 27001, HIPAA controls as needed. Custom AWS Config rules, Service Control Policies, Organizations strategy. Immutable audit log. Automatic compliance reporting.

Our approach

Four steps, from scan to hardening.

We start by mapping your infra, identifying findings, prioritising, fixing them.

01

Discovery (1 wk)

Complete inventory of AWS/GCP/Azure accounts, resources, human and machine access. Blast radius identification per environment (prod, staging, dev). No aggressive scan — read-only API via dedicated audit role.

Complete mapping + account & role inventory
02

Automated scan (2-3 d)

Run ScoutSuite, Prowler, kube-bench (if K8s), aws-iam-actions-lookup. Cross-reference with CIS Benchmarks. Filter false positives. Classify by criticality (CVSS-like + business context).

Raw findings + scoring + filtered false positives
03

Manual analysis (3-5 d)

For critical and high findings: manual analysis of policy, SG, bucket. Real exposure validation. Exploitation PoC if relevant (no impact). Quantified recommendations.

Complete report: findings + proofs + criticality + impact
04

Patching & hardening (1-2 wks)

Implementation of fixes (if you choose): Terraform/CloudFormation for persistence, refactored IAM policies, tightened SGs, enabled encryption. Re-scan after patching to validate. Operational docs delivered.

Hardened infra + IaC delivered + validation re-scan

Tools used

The tools we actually use.

Mix of mature open-source tools and cloud-native tooling.

Cloud scanners

ScoutSuite · Prowler · CloudSploit · Steampipe

ScoutSuite multi-cloud (AWS/GCP/Azure), Prowler very complete on AWS (200+ checks). Steampipe to query cloud like a SQL DB.

AWS-native

Security Hub · GuardDuty · Inspector · Macie · Config

Security Hub aggregates all findings (CIS, PCI). GuardDuty for anomalies. Inspector for CVEs. Macie for sensitive data in S3.

Kubernetes

kube-bench · kube-hunter · Falco · Trivy · OPA Gatekeeper

kube-bench applies CIS Kubernetes. Falco for runtime anomalies. Trivy scans images. OPA Gatekeeper enforces admission policies.

IaC scanning

Checkov · tfsec · Terrascan · Cloudsploit

Checkov for Terraform, CloudFormation, K8s manifests, Helm. tfsec fast integrated in CI. Terrascan for compliance benchmarks.

Secrets scanning

gitleaks · TruffleHog · detect-secrets

gitleaks scans git history. TruffleHog same + entropy detection. detect-secrets for CI/CD with baseline.

IAM analysis

iam-floyd · Cloudsplaining · pmapper · aws-iam-actions-lookup

Cloudsplaining identifies excessive policies. pmapper models privilege escalation paths. iam-floyd generates clean policies.

Measurable guarantees

Four contractual commitments.

150+

Controls

CIS Benchmarks AWS, GCP, Azure covered on 100% of the audit. No control skipped.

100%

IaC delivered

Every fix delivered in Terraform or CloudFormation, ready to apply. No throwaway shell scripts.

0

Data stored

No client data extracted nor stored on our side. Read-only audit via dedicated role, deleted after mission.

30 d

Re-scan included

30 days after patching delivery, free re-scan to validate that fixes hold under real conditions.

가격

모든 프로젝트는 고유합니다. 견적도 마찬가지입니다.

추상적인 패키지 대신 귀하의 상황에 맞춰 범위, 복잡성, 마감일, 제약 조건을 고려합니다. 하고 싶은 일을 3문장으로 작성해 주시면 — 영업시간 기준 48시간 이내에 확정 견적으로 회신해 드립니다.

영업시간 기준 48시간 이내 답변 견적 요청