We comprehensively review your cloud environment security configurations to discover misconfigurations, access control vulnerabilities, and compliance issues — with a clear remediation roadmap.
What's included
- Cloud posture and configuration review (CSPM) against the CIS Benchmarks for AWS, Azure, and GCP, surfacing misconfigurations across compute, storage, databases, and logging.
- Identity and access management review: roles and policies, least privilege, privilege-escalation paths, MFA, and root and break-glass accounts.
- Network security and segmentation: virtual network design, security groups and NSGs, public exposure, private endpoints, and ingress/egress paths.
- Data protection: encryption at rest and in transit, key management, exposed storage buckets, in-Kingdom data residency, and backup.
- Logging, monitoring, and detection: activity trails, cloud-native threat detection, and preventive guardrails.
- Workload and container security where present: managed Kubernetes, serverless functions, and secrets management.
Methodology & standards
Scoping and read-only access: define the accounts, subscriptions, and projects in scope, and provision a read-only auditor role that makes no changes.
Automated posture scanning (CSPM) against the CIS Benchmarks and cloud Well-Architected security guidance.
Manual deep-dive and validation: IAM analysis, network exposure, data protection, elimination of false positives, and identification of attack paths.
Risk rating and mapping to NCA CCC and the cloud provisions of SAMA CSF.
A remediation roadmap with prioritized, provider-specific fixes.
Deliverables
- Cloud posture assessment report with findings rated by severity.
- CIS Benchmark conformance scorecard per provider.
- IAM and privilege-path analysis.
- Prioritized remediation plan with actionable, provider-specific steps.
- Compliance mapping to NCA CCC and SAMA CSF.
- Executive summary and a detailed technical appendix.
Regulatory controls it satisfies
Typical timeline
Typically two to three weeks depending on the number of accounts, subscriptions, or projects in scope and the range of services deployed.
Common questions
Do you need production access?
We work through a read-only audit role (such as SecurityAudit on AWS, Reader on Azure, or Viewer on GCP), making no changes to your environment and causing no disruption to workloads.
Do you cover multi-cloud and hybrid environments?
Yes. We assess AWS, Azure, and GCP against the relevant CIS Benchmarks, and can extend to hybrid connectivity and on-premises integration points.
From the same practice