Cloud / Cloud security review

Cloud security review for AWS, Azure and Google Cloud.

A customer questionnaire, an auditor, or something you saw in the console. This is the review to do first.

A Sorami cloud security review examines four areas: identity and access, network exposure, logging and recovery. It covers AWS, Azure or Google Cloud on read-only access to your control plane. You receive a findings register where every line carries a severity, an effort estimate and a named owner. It is not a penetration test and attempts no exploitation.

The trigger

When teams ask for this review.

A customer security questionnaire, an auditor, or a finding in the console that nobody can size.

Included

What the review covers

  • Identity and access: roles, keys and privilege paths.
  • Network exposure and workload isolation.
  • Logging, alerting and whether anyone reads it.
  • Encryption at rest and in transit. Secrets handling.
  • Backup, recovery and infrastructure-as-code drift.
Excluded

What it does not cover

  • Exploitation. See penetration testing.
  • Application code review unless scoped.
  • Ongoing monitoring.
The deliverable

What you get

A findings register. Every line carries a severity, an effort estimate and a named owner. Each one is marked fix now, fix at next change, or accept.

Failure modes

What usually goes wrong.

  • Review scoped to one account while the exposed workload sits in another.
  • Findings delivered with no effort estimate, so nothing gets scheduled.
  • A read-only role granted far broader than the review needs.
  • Alerts configured to a mailbox nobody owns.
Instant quote

Get an instant quote in 2 minutes

Answer four questions. The indicative price updates as you go. Prices are ex GST.

Indicative until we confirm scope in writing, within one business day. We use your details only to reply. See our Privacy notice.

Questions before you book

Practical answers.

Is this a penetration test?

No. A review examines how the estate is configured. A penetration test validates what an attacker can reach. The review is usually first.

How is our access handled?

Read-only and scoped to the accounts in the review. Access is logged and revoked at handover. Findings stay in your systems.

How long does it take?

One to three weeks depending on the number of accounts and how much is defined in code.

Will it satisfy our auditor?

It produces evidence an auditor can read. Acceptance depends on their requirements, so send us their wording first.

A review reads the configuration. It does not attack anything, so if you need somebody to try, that is cloud penetration testing. We compare the trade-offs in cloud security review vs penetration test. Where a maturity level was named rather than a test, start with the Essential Eight assessment and the Essential Eight ML2 guide for AWS and Azure. If a customer asked for a report, SOC 2 readiness is the closer fit.

Let’s scope it

Ready to scope this review?

Send the accounts in scope and what prompted the question. We will confirm scope and fee first.

Request a quote

Last reviewed: