Services Who We Are Resources Success Stories Contact Speak to a consultant
Cloud Configuration Reviews

Most cloud breaches start with a setting, not an exploit.

An over-permissive IAM role, a storage bucket left public, audit logging never switched on, multi-factor authentication enforced for some users but not all. Individually each looks minor. Together they form the paths attackers actually use. We assess your AWS, Azure, Microsoft 365 and Google Workspace environments against the CIS Benchmarks, the globally recognised consensus standard, and take you through to a CIS Compliance Certificate.

AWS
Foundations Benchmark
AZURE
Foundations Benchmark
MICROSOFT 365
M365 Benchmark
GOOGLE WORKSPACE
Workspace Benchmark
What we review

Every control, across the platforms you actually run

Each environment is assessed against its own published CIS Benchmark. The control domains below are where failures cluster in practice, and where they do the most damage when missed.

Identity and access

Privileged roles, MFA coverage, conditional access, service accounts and joiners-movers-leavers hygiene.

Logging and monitoring

Audit logging enabled and retained, alerting configured, and the visibility you would need during an incident.

Networking

Segmentation, exposed ports and endpoints, firewall rules, and anything reachable that should not be.

Data protection

Encryption at rest and in transit, key management, storage exposure and retention settings.

Security services

Native platform protections that exist but are frequently left switched off or only partially deployed.

LEVEL 1

The practical security baseline. Controls that materially reduce risk while keeping the platform usable day to day.

LEVEL 2

Defence in depth for higher-sensitivity environments. More restrictive, and scoped deliberately rather than applied blindly.

Applying Level 2 everywhere is not a security win if it breaks the business, and we will say so. Which level applies is agreed at scoping.

Engagement

A closed loop, from first review to clean report

We do not hand over a list and leave. The engagement runs until your environment is measurably compliant, then we say so, on the record.

01

Scope and baseline

Confirm the accounts, tenants and subscriptions in scope, the applicable benchmark and profile level, and establish read-only access.

02

Automated and manual verification

Every control assessed automatically, then verified by an analyst who removes false positives and applies real-world context.

03

Findings report

A control-by-control view, each marked pass, warning or fail, with evidence and remediation guidance for every failure.

04

Remediation

Your team works through failed controls starting with those that expose the most, with us available to advise.

05

Retest and attestation

Every affected control is re-verified. When fully compliant, we issue a CIS Compliance Certificate.

PASSED

The control is correctly configured and verified as such by an analyst.

WARNING

Partially met, or context-dependent. Flagged with an explanation rather than a bare score.

FAILED

The control is not met, reported with evidence and specific remediation guidance.

Common questions

What people ask before a cloud review

What are the CIS Benchmarks?

The CIS Benchmarks, published by the Center for Internet Security, are the globally recognised consensus standard for securely configuring cloud platforms and operating systems. They translate security best practice into hundreds of specific, testable controls per platform.

What is the difference between Level 1 and Level 2 benchmark profiles?

Level 1 is the practical security baseline that materially reduces risk while keeping a platform usable day to day. Level 2 is defence in depth for higher-sensitivity environments, more restrictive, and should be scoped deliberately rather than applied everywhere by default.

Do you have access to change our environment during the review?

No. Evidence is gathered using read-only access throughout. Nothing is modified in your environment at any stage of the review.

What do we get at the end of the review?

A detailed report showing every benchmark control marked as a clear pass, warning or fail, with evidence and specific remediation guidance for every failure, plus an overall risk rating.

What is the CIS Compliance Certificate?

Once you have remediated the failed controls, we re-verify every affected control. When the environment is fully compliant, we issue a CIS Compliance Certificate as independent proof for boards, customers and auditors.

Get started

Find out where your cloud actually stands

A configuration review needs read-only access and changes nothing in your environment. We stay with you through remediation and retest, and issue the certificate only once it genuinely passes.

Book a scoping call with our team

Tell us which platforms you run, and we'll scope the benchmark review around them.

+44 20 7862 3837 [email protected] cyberarmedsecurity.com