Cloud Configuration Review

Custom assessments to protect your cloud environments from cyber threats

If your business utilises cloud services and applications to support day-to-day operations, security is of paramount importance and should include a robust security assessment program.

What is cloud penetration testing?

Cloud penetration testing is a form of security assessment conducted on an environment hosted by a cloud service provider such as Amazon’s AWS or Microsoft Azure. Cloud pen testing is designed to gauge the effectiveness of security controls and identify, safely exploit and help to remediate vulnerabilities before they are compromised by malicious adversaries.

Configuration review or penetration test — which do you need?

These are different exercises, and buying the wrong one is a common and expensive mistake.

A configuration review compares your environment against a known-good baseline — CIS benchmarks and the provider’s own guidance — and reports where it diverges. It is thorough, it is systematic, and it finds the issues that cause the overwhelming majority of real cloud breaches. It does not involve exploitation.

A cloud penetration test actively attempts to exploit what it finds and chain issues together to demonstrate impact — proving that an over-permissive role can actually be used to reach production data rather than simply noting that it exists.

For most organisations, the configuration review is the right first purchase. Cloud environments rarely fail because someone defeated a security control. They fail because a control was never configured in the first place.

What a cloud configuration review checks

We assess your environment against CIS benchmarks and provider hardening guidance across five areas.

Identity and access

The most common source of serious findings. We review privileged role assignment, whether multi-factor authentication is genuinely enforced rather than merely available, conditional access policy coverage and its gaps, dormant accounts that retain access, service principals and their permission scope, guest and external user access, and whether the principle of least privilege survives contact with how people actually work.

Data exposure

Publicly accessible storage buckets and containers, sharing links that have outlived their purpose, anonymous access settings, encryption at rest and in transit, retention and deletion policy, and whether sensitive data is sitting somewhere it was never meant to reach.

Network and perimeter

Security group and firewall rules, management ports exposed to the internet, network segmentation between environments, private endpoint usage, and the gap between what your network diagram says and what your environment actually permits.

Logging, monitoring and detection

Whether audit logging is enabled across all subscriptions and regions, log retention against your own incident response requirements, alerting on privileged actions, and — the question that matters most — whether anyone would actually notice a compromise. An environment with no logging cannot be investigated after an incident, which is usually discovered at the worst possible moment.

Workload and service configuration

Virtual machine and container hardening, managed database exposure, secrets handling, key rotation, backup configuration and whether backups have ever been tested, plus the default settings that quietly remain in place years after deployment.

How the assessment runs

We work through four stages, typically over several days depending on environment size.

  1. Scoping. We establish which tenants, subscriptions and accounts are in scope, roughly how many users, and which services carry your important data.
  2. Read-only access. You grant a reader-level role. We do not require write access to perform a configuration review, and we will not ask for it.
  3. Assessment. Automated benchmark comparison establishes the baseline, then manual review interprets it against how your business actually operates. This distinction matters: a tool reports that a storage account is public. A reviewer determines whether that is a genuine exposure or a deliberate choice for your public asset library.
  4. Reporting and remediation support. Findings are prioritised by real risk in your environment rather than by generic severity score, and our experts remain available while you fix them.

What a finding actually looks like

To make this concrete, here is the shape of a typical high-severity finding in a Microsoft 365 environment:

Conditional access requires multi-factor authentication for all users, but legacy authentication protocols remain enabled tenant-wide. Because legacy protocols do not support modern authentication, they bypass conditional access entirely. Any account whose password appears in breach data can therefore be accessed without MFA, regardless of the policy.

That is a configuration issue, not a vulnerability. No scanner flags it as a CVE. It is invisible on a network penetration test. And it renders your MFA rollout substantially less effective than the dashboard suggests.

These are the findings a configuration review exists to surface.

What you receive

  • An executive summary stating your overall posture and the decisions that need making, written for people who do not work in security
  • A technical summary covering the shape of the issues and how they relate to one another
  • Detailed findings with severity, affected resources, evidence, and specific remediation steps — the setting to change, not the principle to consider
  • Benchmark mapping so you can evidence your position against CIS controls
  • Remediation support from the people who performed the assessment

On our Managed Cloud Reviews tier you also receive regular sessions to work through findings, and a re-test with an updated report once fixes are in place — which is usually what a customer, auditor or insurer actually wants to see.

Which environments we cover

Microsoft 365, Microsoft Azure and Azure AD (Entra ID), Amazon Web Services, Google Cloud Platform and Oracle Cloud. Multi-cloud estates are assessed together, because the gaps between platforms are frequently where the interesting findings live.

Types of cloud penetration testing

Whether you’re looking for a cloud penetration test utilising traditional internal and external assessment techniques, or a cloud configuration review to compare configurations against best practice, our experts are well-placed to assist.

We follow tried and tested methodologies to rigorously assess your environments and measure them against CIS benchmarks. While cloud pen testing no longer requires prior authorisation, testers must follow the rules of engagement outlined by cloud providers.

Our cloud security testing experts are well-versed in navigating these rules and can perform testing on a range of environments, including Amazon Web Services (AWS), Microsoft Azure and Azure AD, and Microsoft 365.

Cloud configuration review pricing

One-Time Baseline

For organisations looking to understand their cloud security posture without high cost barriers


  • Security review against industry benchmarks (CIS, Microsoft, AWS)
  • Coverage 1 cloud environment (M365, Azure, AWS, GCP, Oracle)
  • Detailed Report
  • Executive Summary
  • Technical Summary
  • Detailed Findings
  • Actionable Remediation Advice
  • Support with advice from our experts during Remediation
  • Flexible Pricing

£1500

Managed Cloud Reviews

For organisations looking for ongoing support to understand, secure and remediate their cloud environment


  • Security review against industry benchmarks (CIS, Microsoft, AWS)
  • Coverage of cloud environments (M365, Azure, AWS, GCP, Oracle)
  • Detailed Reports with Executive and Technical Summary
  • Detailed Findings
  • Actionable Remediation Advice
  • Support with advice from our experts during Remediation
  • Regular sessions to assist managing findings and cloud security posture*
  • Re-test of findings and re-issue of report with updated status*
  • Flexible Pricing

From £2000

FAQs

Frequently asked questions about cloud configuration reviews

For a single environment, assessment typically runs over several days once read-only access is in place, with the report following shortly after. Larger multi-cloud estates take longer. The variable is the number of tenants, subscriptions and accounts in scope rather than your headcount — a 30-person company with four AWS accounts and a separate Microsoft 365 tenant is a bigger job than a 300-person company running one.

Read-only. We ask for a reader-level role scoped to the environments in scope — Global Reader in Microsoft 365, Reader in Azure, SecurityAudit or an equivalent read-only policy in AWS. We do not require write access to perform a configuration review and we will not ask for it. If a provider asks for administrative access to review your configuration, ask them why.

No. A configuration review reads settings; it does not change them, and it does not exploit what it finds. Your users will not notice it is happening and there is no risk of outage. This is one of the practical advantages of a configuration review over a penetration test — it can be run against production without the coordination a test requires.

Secure Score is a useful signal and a poor substitute. It scores your tenant against Microsoft’s generic recommendations, weights everything by its own formula, and has no knowledge of your business. It will tell you a setting is off. It will not tell you whether that matters given how your organisation actually operates, and it does not cover AWS, Google Cloud or Oracle at all. We assess against CIS benchmarks and provider hardening guidance, then interpret the results in your context and prioritise by real risk rather than by points available.

Yes, and often more so. Microsoft 365 is where most organisations hold their email, files and identity, and it is configured by default in a way that prioritises getting people working over locking things down. Legacy authentication left enabled, conditional access with gaps, over-privileged global administrators, external sharing that was never reviewed — these are extremely common and they are exactly what a review surfaces. A Microsoft 365 tenant is a full cloud environment, not a subset of one.

They cover different ground. A network or application penetration test assesses what an attacker can reach and exploit from outside or within your estate. It will not tell you that your storage account permits anonymous access, that audit logging is disabled in two of your five subscriptions, or that a service principal holds far more permission than it needs. If a meaningful share of what you run is in the cloud, the two are complementary rather than alternatives.

Have more questions about

Our Service

Challenge Your Defences, Fortify Your Business.

Contact Us

We are happy to discuss your challenges and our solutions.