Skip to content

Cloud Security Audit

Security review of your cloud environment


The cloud offers enormous flexibility – but also new attack surfaces. Misconfigurations, excessive permissions, and lack of visibility are among the most common causes of security incidents in cloud environments. Our Cloud Security Audit identifies weaknesses in your configuration before attackers exploit them.

Why Cloud Security Matters


With migration to the cloud, security responsibility shifts – but it doesn't disappear. The Shared Responsibility Model means: the cloud provider secures the infrastructure, but you are responsible for correct configuration and protecting your data. In practice, we consistently see the same issues: publicly accessible storage buckets, over-privileged service accounts, missing multi-factor authentication, and insufficient logging.

On top of that, there are regulatory requirements: whether DSG, GDPR, FINMA, or industry-specific standards – compliance requirements for cloud environments are constantly growing. A Cloud Security Audit helps you systematically identify and close both technical risks and compliance gaps.

What We Review


Identity & Access Management

Review of user roles, permissions, MFA configuration, service accounts, and conditional access policies. We identify over-privileged accounts and insecure authentication mechanisms.

Network Configuration

Analysis of virtual networks, security groups, firewalls, VPN configurations, and network segmentation. We verify whether your cloud networks are configured according to the least-privilege principle.

Storage & Encryption

Review of storage permissions, encryption at rest and in transit, key management, and backup configurations. We ensure your data is not exposed without protection.

Logging & Monitoring

Assessment of audit logs, alerting rules, SIEM integration, and incident response capabilities. We verify whether security-relevant events are detected and logged.

Supported Platforms


Our Cloud Security Audit covers the most common cloud platforms. We tailor our review to the specific security features and best practices of each platform:

Microsoft Azure

Entra ID, Azure AD, network security, storage accounts, Azure Policy, Defender for Cloud

Amazon Web Services

IAM, VPC, S3, CloudTrail, GuardDuty, Security Hub, KMS

Microsoft 365

Exchange Online, SharePoint, Teams, DLP policies, conditional access, audit logging

Google Cloud

IAM, VPC, Cloud Storage, Cloud Audit Logs, Security Command Center, KMS

Who Is This For?


Our Methodology


01
Cloud Environment Assessment

Inventory of your cloud environment: which services, resources, and configurations are in use?

02
Configuration Review

Systematic review of all configurations against CIS Benchmarks and platform-specific best practices.

03
Identity & Access Analysis

In-depth analysis of identities, roles, permissions, and authentication mechanisms.

04
Reporting & Remediation

Detailed report with prioritized findings, compliance mapping, and concrete remediation plan.

From Our Engagements


Anonymized engagement example

A Swiss technology company. AWS. 3 S3 buckets with customer data publicly readable.

S3 buckets locked down within 24 hours. IAM overhaul and logging setup implemented in a four-week roadmap. Result: no publicly exposed resources remaining.

3 public S3 buckets 14 instances with admin access First fixes in 24h
Industry: Technology company
Environment: AWS
Duration: 5 days

A Swiss technology company wants its AWS environment reviewed after a security incident at a competitor put cloud security on the management agenda. The infrastructure has grown organically over two years.

Key Findings
  • Critical 3 S3 buckets containing customer data are publicly readable — including order history and addresses
  • High IAM role with AdministratorAccess is usable from 14 EC2 instances — one of which was publicly accessible
  • Medium CloudTrail logging is disabled in 2 of 4 active regions — attacks go undetected

Your Deliverables


Upon completion of the Cloud Security Audit, you will receive:

Cloud Security Posture Report

Comprehensive assessment of your current cloud security posture, including risk score and executive summary.

Misconfiguration Findings

Detailed listing of all identified misconfigurations with severity, description, and reproduction steps.

Compliance Mapping

Mapping of findings to relevant standards and regulations (CIS Benchmarks, DSG, GDPR, FINMA, ISO 27001).

Remediation Roadmap

Prioritized action plan with concrete recommendations and quick wins for immediate implementation.

from CHF 4,500

Typical duration: 3–7 days

Inquire Now

Why Manual Review?


Frequently Asked Questions


We audit all major cloud platforms: Microsoft Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), as well as Microsoft 365 and Entra ID (formerly Azure AD). The audit covers configuration, identity and access management, network security, data encryption, and compliance settings.

For a comprehensive audit, we need read-only access to the cloud configuration. We work with minimal permissions and provide you with a list of required roles in advance. Alternatively, we can work with exported configuration data or guide you through the audit.

Yes, we also evaluate your cloud configuration with regard to regulatory requirements such as the revDSG, GDPR, ISO 27001, and industry-specific standards (e.g., FINMA for the financial sector). The report includes concrete recommendations for closing compliance gaps.

A cloud security audit systematically analyzes the configuration and architecture of your cloud environment for vulnerabilities and best-practice deviations. A penetration test, on the other hand, simulates active attacks. Both approaches complement each other ideally: the audit finds misconfigurations, while the pentest shows how they can be exploited.
Request a Quote