Before you call
Questions clients ask us before the first meeting
These are the points that come up most often when a security or platform team first gets in touch.
What does a cloud infrastructure security review actually include?
We look at identity and access, network exposure, encryption, logging and configuration across your cloud accounts. You receive written findings, a severity rating and a prioritised list of fixes with the reasoning behind each one.
Which cloud platforms do you work with?
The bulk of our work sits on Amazon Web Services, Microsoft Azure and Google Cloud, including Kubernetes clusters running on them. We also review hybrid setups where part of the estate remains in a data centre.
How long does a typical engagement take?
A focused review of a single platform usually runs two to three weeks. Broader work covering several accounts, compliance obligations and remediation support tends to run six to twelve weeks, depending on how quickly your team can act on findings.
Do we need to give you production credentials?
No. We work from read-only roles scoped to the resources in question, and we prefer to run from your own environment under your change process. Where access is sensitive, your team supervises the session.
How do you price the work?
Most engagements are quoted as a fixed fee once we have seen the scope and the size of the estate. Ongoing advisory is priced monthly. We set the fee before work begins, so there are no surprise invoices partway through.
Will you tell us which findings matter most?
Yes. Every finding carries a severity and a short note on the practical risk it creates. If something is low priority for your business, we say so plainly rather than inflating the list.