Cloud security you can prove
We review your cloud security controls, run risk assessments, and build best-practice target-state controls that meet your compliance requirements and hold up under scrutiny.
Cloud security reviews, risk assessments and compliance controls
Cloud security problems rarely come from exotic attacks. They come from an over-permissive role created in a hurry, a storage bucket that was public for a week, a database that was never patched, or credentials in a repository. The platforms give you excellent tools to prevent all of that, and most environments have half of them switched off.
Orbit3's cloud security service starts from what is actually configured today. We assess the environment against the platform's own best-practice frameworks and the standards you need to meet, prioritise the findings by real risk, then design and implement the target-state controls. If we also run your environment through managed services, those controls are maintained and evidenced every month afterwards.
- Configuration and posture reviewEvery account, role, network path and storage location, against a recognised benchmark.
- Risk assessmentFindings ranked by what an attacker could actually do with them, not by tool severity.
- Target-state controlsIdentity, network, data protection, logging and detection designed and implemented.
- Compliance mappingControls mapped to ISO 27001, SOC 2, Cyber Essentials or the framework your customers ask about.
For businesses that have to answer a security questionnaire, or should
The trigger is usually external: a customer's due diligence, an insurer's questions, an audit date, or an incident somewhere similar.
Vendors selling to larger customers
Enterprise procurement wants evidence of your controls. You need to be able to show them, not describe them.
Regulated or certifying organisations
You are working towards ISO 27001, SOC 2 or Cyber Essentials and the cloud environment is the part nobody is sure about.
Teams that grew faster than their controls
Access was granted as needed and never reviewed. You would like to know what is actually exposed before someone else finds out.
Controls you can show an auditor
Security work is only useful if it leaves you with controls that hold, evidence you can produce, and a team that knows what changed. This is what each engagement covers.
- Identity and access reviewUsers, roles, service accounts and keys, with least-privilege recommendations and a clean-up plan.
- Network and perimeter reviewExposed services, security group and firewall rules, private connectivity and segmentation.
- Data protection reviewEncryption at rest and in transit, key management, storage exposure and backup protection.
- Logging, monitoring and detectionAudit logs enabled and retained, threat detection services configured, alerts routed to someone who will act.
- Benchmark assessmentConfiguration measured against CIS Benchmarks and the platform's own security best-practice framework.
- Prioritised findings reportEach finding with its real-world risk, the evidence behind it and the specific fix, ranked so you know what to do first.
- RemediationWe implement the fixes, or work alongside your team, with changes made through infrastructure as code where possible.
- Compliance control mappingFindings and controls mapped to the framework you are working towards, with the evidence an auditor will ask for.
- Re-assessmentA follow-up review to confirm the fixes hold and to produce a clean baseline report.
Assess, harden, comply
We work from evidence, not assumptions: what is actually configured today, what the risk is, and what good looks like for your size and sector.
Assess
We review controls across identity, network, data, logging and detection, using both automated benchmark tooling and manual inspection, and produce a risk-ranked findings report.
Harden
We design the target-state controls and implement them, prioritising the fixes that remove the most risk for the least disruption.
Comply
We map the controls to the standard your business must meet and package the evidence, then re-assess to confirm the environment holds.
AWS, Azure and Google Cloud
Each platform has its own native security services and its own sharp edges. We work with the native tooling first and add third-party controls only where they earn their place.
Amazon Web Services
IAM Access Analyzer, Security Hub, GuardDuty, Config rules, CloudTrail and KMS, aligned to the AWS Foundational Security Best Practices and CIS Benchmarks.
Microsoft Azure
Entra ID Conditional Access and Privileged Identity Management, Defender for Cloud, Azure Policy, Sentinel and Key Vault, aligned to the Microsoft cloud security benchmark.
Google Cloud
Organisation policies, IAM Recommender, Security Command Center, VPC Service Controls, Cloud Audit Logs and Cloud KMS, aligned to the CIS Google Cloud Benchmark.
Frequently asked questions
Is this a penetration test?
No. A penetration test tries to break in from the outside. A cloud security assessment reviews how the environment is configured from the inside, which is where most cloud breaches actually start. The two complement each other, and we can coordinate with a testing provider if you need both.
Will the assessment disrupt our environment?
The review is read-only. Remediation involves changes, which we plan with you, make through version-controlled infrastructure code where possible, and schedule around your business.
Which compliance frameworks do you work with?
Most commonly ISO 27001, SOC 2 and Cyber Essentials, plus the platform benchmarks from CIS and the cloud providers themselves. If your customers ask about a specific framework, we map to that.
How long does an assessment take?
A single-account environment can be assessed in days; a multi-account estate takes a few weeks. Remediation time depends on what we find and how much of it you want us to fix versus your own team.
Do you fix the problems or just report them?
Both. The report is written so your team could act on it alone, and we are equally happy to implement the fixes ourselves. Most clients ask us to handle the high-risk items immediately and work through the rest together.
What keeps the environment secure afterwards?
Controls drift as people and systems change. Our managed service maintains and evidences them every month; otherwise we recommend a re-assessment at least annually or after any major change.
Often combined with this
Security is easier to maintain when someone is watching the environment every day. These services keep the posture from drifting.
CloudOps Managed Services
24/7 monitoring, patching, security and cost control for your AWS, Azure or Google Cloud environment, run by us.
Learn moreCloud Backup
Backup and disaster recovery designed around your recovery objectives, and tested so restores are routine.
Learn moreCloud DevOps
CI/CD pipelines, infrastructure as code and observability so your team ships daily with confidence.
Learn moreWorried about your security posture?
Book a free 30-minute call and we'll help you find the gaps that matter most, and how to close them.