An over-permissive IAM role, a storage bucket left public, audit logging never switched on, multi-factor authentication enforced for some users but not all. Individually each looks minor. Together they form the paths attackers actually use. We assess your AWS, Azure, Microsoft 365 and Google Workspace environments against the CIS Benchmarks, the globally recognised consensus standard, and take you through to a CIS Compliance Certificate.
Each environment is assessed against its own published CIS Benchmark. The control domains below are where failures cluster in practice, and where they do the most damage when missed.
Privileged roles, MFA coverage, conditional access, service accounts and joiners-movers-leavers hygiene.
Audit logging enabled and retained, alerting configured, and the visibility you would need during an incident.
Segmentation, exposed ports and endpoints, firewall rules, and anything reachable that should not be.
Encryption at rest and in transit, key management, storage exposure and retention settings.
Native platform protections that exist but are frequently left switched off or only partially deployed.
The practical security baseline. Controls that materially reduce risk while keeping the platform usable day to day.
Defence in depth for higher-sensitivity environments. More restrictive, and scoped deliberately rather than applied blindly.
Applying Level 2 everywhere is not a security win if it breaks the business, and we will say so. Which level applies is agreed at scoping.
We do not hand over a list and leave. The engagement runs until your environment is measurably compliant, then we say so, on the record.
Confirm the accounts, tenants and subscriptions in scope, the applicable benchmark and profile level, and establish read-only access.
Every control assessed automatically, then verified by an analyst who removes false positives and applies real-world context.
A control-by-control view, each marked pass, warning or fail, with evidence and remediation guidance for every failure.
Your team works through failed controls starting with those that expose the most, with us available to advise.
Every affected control is re-verified. When fully compliant, we issue a CIS Compliance Certificate.
The control is correctly configured and verified as such by an analyst.
Partially met, or context-dependent. Flagged with an explanation rather than a bare score.
The control is not met, reported with evidence and specific remediation guidance.
The CIS Benchmarks, published by the Center for Internet Security, are the globally recognised consensus standard for securely configuring cloud platforms and operating systems. They translate security best practice into hundreds of specific, testable controls per platform.
Level 1 is the practical security baseline that materially reduces risk while keeping a platform usable day to day. Level 2 is defence in depth for higher-sensitivity environments, more restrictive, and should be scoped deliberately rather than applied everywhere by default.
No. Evidence is gathered using read-only access throughout. Nothing is modified in your environment at any stage of the review.
A detailed report showing every benchmark control marked as a clear pass, warning or fail, with evidence and specific remediation guidance for every failure, plus an overall risk rating.
Once you have remediated the failed controls, we re-verify every affected control. When the environment is fully compliant, we issue a CIS Compliance Certificate as independent proof for boards, customers and auditors.
A configuration review needs read-only access and changes nothing in your environment. We stay with you through remediation and retest, and issue the certificate only once it genuinely passes.
Tell us which platforms you run, and we'll scope the benchmark review around them.