
Evaluate
Cloud and technical configuration audit
A read-only technical audit of how your cloud and infrastructure are actually configured, against recognised baselines. Findings are ranked by what an attacker could realistically do with them, not by the scanner's own severity label.
Duration
2–3 weeks
Built on
CIS Benchmarks · ISO/IEC 27001 Annex A · cloud provider security baselines
Indicative price
€8,500–19,000 per engagement
Who this is for
CIO or IT director
Inherited an estate that has grown faster than anyone documented.
Cloud or platform engineer
Knows roughly where the problems are and needs them evidenced to get them funded.
CISO
Needs assurance that is technical rather than declarative.
Auditor or risk function
Wants the configuration position tested, not described.
Almost nothing is breached through a novel vulnerability
The overwhelming majority of cloud incidents come down to configuration: a storage bucket readable by anyone, an identity with far more privilege than its job requires, a management interface exposed to the internet because it was quicker, a subscription somebody created for a proof of concept three years ago and nobody has looked at since.
None of this appears in an architecture diagram, because the diagram shows what was designed. Estates drift. Every urgent change, every temporary exception, every engineer who has since left contributes a little, and the gap between the designed state and the running state widens quietly until something finds it.
Automated scanners find most of it, and this is the trap. A raw scanner report runs to thousands of findings, ranked by a severity score that knows nothing about your business, and the effect on a team is paralysis. The valuable work is not the scan; it is the triage — which of these can actually be chained into something, and which are noise in your context.
So we rank by exploitability. A medium-severity misconfiguration on an internet-facing host holding client data outranks a high-severity finding on an isolated internal system, every time, and a report that cannot make that distinction has simply moved the problem.
The audit is read-only. We do not change your configuration and we do not test by exploitation — this is an audit, not a penetration test, and the two answer different questions.
How we do it
- 01
Scoping and read-only access
2–3 days
Which subscriptions, tenants, accounts and on-premises estate are in scope. Read-only credentials provisioned by you, with the permissions documented so you can revoke them cleanly afterwards.
- 02
Automated baseline assessment
2–3 days
Configuration measured against CIS benchmarks and the provider's own security baselines, across compute, storage, network, identity and logging.
- 03
Identity and privilege review
3–4 days
Who and what can do what. Standing privilege, service principals and machine identities, dormant accounts, privilege escalation paths, and whether multi-factor authentication is genuinely enforced rather than merely enabled.
- 04
Exposure review
2–3 days
What is reachable from the internet, intentionally or otherwise: management planes, storage, databases, forgotten test environments, expired or misissued certificates.
- 05
Data protection and recovery review
2–3 days
Encryption at rest and in transit, key management, backup coverage, and — the part most often untested — whether a restore has ever actually been performed.
- 06
Triage and reporting
3–4 days
Findings ranked by realistic exploitability in your context, with remediation steps, effort estimates and a fix sequence. Presented to your engineers, not only to management.
Named artefacts
What you receive
- Configuration findings register, ranked by exploitability rather than by scanner severity
- Identity and privilege map, including machine identities and escalation paths
- Internet exposure inventory
- Encryption and key management assessment
- Backup coverage and recovery assessment, including whether restores have been tested
- Remediation plan, sequenced, with effort per item
- Technical walkthrough for your engineering team
- Executive summary that does not require a cloud background to read
What we need from you
- Read-only credentials across the estate in scope, and an inventory of subscriptions or accounts — including the ones nobody is sure are still used.
- A few hours from whoever runs the platform, to explain intent. Some of what looks wrong is deliberate, and we would rather ask than guess.
- Your architecture documentation, however out of date. The gap between it and reality is itself a finding.
- An owner for the remediation plan before we deliver it, so the report lands somewhere rather than circulating.
What changes
- 01You know what is actually exposed, as opposed to what the diagram shows.
- 02Findings are ranked so your team can start at the top rather than freeze.
- 03Privilege is mapped, including the machine identities that rarely get reviewed.
- 04You know whether your backups would restore, because someone checked.
- 05The remediation plan is costed and sequenced, so it can be funded.
What it costs
€8,500–19,000 per engagement
All prices exclude VAT.
Questions
Is this a penetration test?
No. A penetration test attempts exploitation to prove impact. This is a configuration audit — read-only, broad rather than deep, and better value as a first engagement because it finds the systemic issues rather than one route through. The two are complementary, and doing the audit first makes the pen test cheaper.
Will it disrupt anything?
No. Everything is read-only. We change nothing, and we agree the access scope with you in writing before we start.
Which platforms do you cover?
Microsoft Azure and Microsoft 365 primarily, alongside on-premises infrastructure and network. Tell us what else is in the estate and we will say plainly whether we cover it — we would rather scope it out than assess it badly.
We already have a scanning tool. Why would we need this?
Because the scanner is not the hard part. If your tool produces three thousand findings and your team has fixed forty of them, the problem is triage rather than detection, and that is what this delivers.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.