Past engagements
Reviewed account structure and guardrails for a financial services firm.
Ran tabletop exercises with the engineering team of a media company.
Redrew segment boundaries and testing routes for a healthcare provider.
Assessed encryption key storage and rotation for a legal practice.
Introduced reusable compliance policies for a logistics operator.
Tightened federation and privilege settings for a large housing association.
How we engage
You send a short description of your cloud estate, the concern that prompted you to seek help, and any deadline you are working towards. We reply within two working days to arrange a conversation.
A call of about an hour establishes the accounts, regions and services in scope, the standards you must meet, and who on your side will be available. You receive a written scope note afterwards.
We examine configuration, identity, network boundaries and logging against the agreed scope, speaking to your engineers where needed. Findings are recorded as we go so nothing is left to memory.
We deliver a written report separating urgent exposures from longer-term improvements, and we walk your team through it. You may then implement the changes yourselves or ask us to help.
What we offer
We inspect your cloud accounts against recognised baselines and set out every gap we find, ranked by the risk it carries. The review covers identity, storage, network and logging settings across your main providers.
We map how users, services and machines obtain access to your systems, then propose a structure built on least privilege. Roles, federation and break-glass accounts are all considered together.
We examine how your cloud networks are separated and how traffic moves between them. From that we advise on segmentation that limits how far a single compromised component can reach.
Your templates and deployment pipelines are read line by line for insecure defaults and drift from policy. We recommend changes that keep future deployments compliant by default.
We review where data is encrypted at rest and in transit, and how keys are stored, rotated and separated from the data they protect. Weak key custody is one of the most common findings we report.
We help you prepare for the day a cloud credential is lost or abused, covering detection, escalation and containment steps. Tabletop exercises with your team test whether the plan holds when it is needed.