Cloud / Google Cloud

Google Cloud architecture, IAM and cost review.

A Google Cloud organisation where projects outgrew the policy. We review it and write the fixes down.

Google Cloud services

What we examine on Google Cloud.

Organisation policy

Constraints on public access, key management and external identities, and where they are overridden.

IAM

Basic roles still in use, service account impersonation chains and IAM conditions that narrow access.

VPC Service Controls

Perimeter design, access levels, and the ingress rules that quietly defeat the perimeter.

Detection

Cloud Audit Logs coverage, log sinks and whether Security Command Centre findings reach an owner.

Cost

Committed use discount coverage, idle persistent disks and BigQuery slot versus on-demand choice.

Failure modes

What we find on Google Cloud estates.

  • Basic Editor granted at project level because a predefined role took longer to find.
  • A VPC Service Controls perimeter in dry-run mode that was never enforced.
  • Service account keys downloaded to a laptop instead of workload identity federation.
  • Organisation policy constraints overridden at the folder for one project, then forgotten.
  • BigQuery on-demand billing for a workload that runs continuously.
How to start

Three reviews, one platform.

Questions before you book

Practical answers.

Are you a Google Cloud partner?

No. We hold no Google Cloud partner status. The review carries no vendor incentive.

Do you cover data residency?

Yes. Region and multi-region placement for Australian data is part of the review.

Is BigQuery in scope?

Its access model and cost model are. A full data platform build is a separate scope.

Let’s scope it

Scope a Google Cloud review.

Send the accounts in scope and what prompted the question. We confirm scope and fee before any access.

Request a quote

Last reviewed: