Advisory & Strategy

Cloud Security Assessment

Comprehensive security configuration review for AWS, Azure, and GCP cloud environments to ensure your data protection

We comprehensively review your cloud environment security configurations to discover misconfigurations, access control vulnerabilities, and compliance issues — with a clear remediation roadmap.

What's included

  • Cloud posture and configuration review (CSPM) against the CIS Benchmarks for AWS, Azure, and GCP, surfacing misconfigurations across compute, storage, databases, and logging.
  • Identity and access management review: roles and policies, least privilege, privilege-escalation paths, MFA, and root and break-glass accounts.
  • Network security and segmentation: virtual network design, security groups and NSGs, public exposure, private endpoints, and ingress/egress paths.
  • Data protection: encryption at rest and in transit, key management, exposed storage buckets, in-Kingdom data residency, and backup.
  • Logging, monitoring, and detection: activity trails, cloud-native threat detection, and preventive guardrails.
  • Workload and container security where present: managed Kubernetes, serverless functions, and secrets management.

Methodology & standards

01

Scoping and read-only access: define the accounts, subscriptions, and projects in scope, and provision a read-only auditor role that makes no changes.

02

Automated posture scanning (CSPM) against the CIS Benchmarks and cloud Well-Architected security guidance.

03

Manual deep-dive and validation: IAM analysis, network exposure, data protection, elimination of false positives, and identification of attack paths.

04

Risk rating and mapping to NCA CCC and the cloud provisions of SAMA CSF.

05

A remediation roadmap with prioritized, provider-specific fixes.

Deliverables

  • Cloud posture assessment report with findings rated by severity.
  • CIS Benchmark conformance scorecard per provider.
  • IAM and privilege-path analysis.
  • Prioritized remediation plan with actionable, provider-specific steps.
  • Compliance mapping to NCA CCC and SAMA CSF.
  • Executive summary and a detailed technical appendix.

Regulatory controls it satisfies

NCA CCC — Cloud Cybersecurity Controls
The reference framework for cloud tenants and providers in the Kingdom, covering governance, IAM, data protection, and isolation.
CIS Benchmarks
Configuration-hardening baselines for AWS, Azure, and GCP.
SAMA CSF — Cloud & Third-Party
Cloud, outsourcing, and data-residency provisions for financial institutions, with retained control over third-party risk.
PDPL
Data residency, cross-border transfer, and protection of personal data hosted in the cloud.
ISO/IEC 27017
Cloud-specific security controls extending ISO/IEC 27001.

Typical timeline

Typically two to three weeks depending on the number of accounts, subscriptions, or projects in scope and the range of services deployed.

Common questions

Do you need production access?

We work through a read-only audit role (such as SecurityAudit on AWS, Reader on Azure, or Viewer on GCP), making no changes to your environment and causing no disruption to workloads.

Do you cover multi-cloud and hybrid environments?

Yes. We assess AWS, Azure, and GCP against the relevant CIS Benchmarks, and can extend to hybrid connectivity and on-premises integration points.