Skip to main content
Home/Services/Cloud Configuration Review
CIS Benchmarks & Architecture Audit

Cloud Configuration Review

A systematic CIS benchmark audit of your AWS, Azure, or GCP environment - delivered as an audit-ready baseline and engineering remediation plan.

CIS Benchmarks SOC 2 Type II ISO 27001 CSA CCM OSFI B-13 PIPEDA
engagement log Cloud Configuration Review testing
day 01 access read-only audit role provisioned and validated ready
day 01 audit CIS Benchmark automated baseline scan executed complete
day 02 finding root/global admin account lacking hardware MFA token critical
day 02 finding CloudTrail log validation disabled in 3 regions high
day 03 review manual analysis of complex IAM policies completed verified
day 04 report control-by-control gap assessment published delivered
after retest re-audit of updated cloud configurations verified retested
retest included human countersigned report your auditor accepts
1 weektypical duration $4,500fixed scope, from 8deliverables 8methodology stages
Scope

What This Engagement Covers

The Service

The majority of cloud data breaches are caused by misconfigurations rather than zero-day exploits: unencrypted data at rest, excessive IAM privileges, disabled audit logs, and open network security groups. Our cloud configuration review performs a deep, systematic assessment of your cloud accounts against industry benchmarks (CIS Cloud Foundations, CSA Cloud Controls Matrix) and best practices, providing your engineering team with prioritized, actionable guidance.

What We Test

We review all core architectural components in AWS, Azure, or GCP: IAM users, groups, roles, and password policies; multi-factor authentication enforcement; storage access controls; encryption at rest and in transit; network security groups, firewalls, and routing tables; logging and monitoring (CloudTrail, CloudWatch, GuardDuty, Azure Monitor); and backup and disaster recovery configurations.

Targets

Components Evaluated in Scope

Our testers systematically inspect the following architectural layers and attack vectors during the assessment.

CIS AWS, Azure, and GCP Foundations Benchmarks
IAM least-privilege audit and unused credential analysis
Object storage permissions and public exposure settings
Logging, monitoring, and intrusion detection coverage
Network security groups, NACLs, and peering connections
Encryption key management and rotation (KMS, Key Vault)
Container registry and serverless execution settings
Database access controls, snapshots, and encryption
Third-party application integrations and service principal rights
Compliance control mapping for Canadian and international standards
Method

How We Run It

Using read-only API access, our assessors perform both automated collection and detailed manual analysis of your cloud control plane. We evaluate configurations against the CIS Benchmarks and cross-reference your specific regulatory obligations, eliminating false positives and delivering concrete Terraform, CloudFormation, or CLI remediation commands.

01

Scope Definition & Baseline Selection

Confirming in-scope accounts, benchmark version (CIS Level 1 or Level 2), and specific compliance frameworks.

02

Automated Data & Configuration Harvest

Executing read-only audit scripts to capture resource states across IAM, networking, compute, and storage.

03

Manual IAM & Policy Evaluation

Deep manual inspection of IAM trust relationships, cross-account permissions, and conditional access policies.

04

Network & Perimeter Security Review

Analyzing security groups, routing tables, and public IP allocations for unintended internet exposure.

05

Logging, Alerting & Forensic Readiness

Verifying audit trail immutability, centralized log forwarding, and real-time security alerting configurations.

06

Data Protection & Encryption Audit

Reviewing KMS key configurations, customer-managed key usage, and volume/bucket encryption standards.

07

Gap Analysis & Risk Prioritisation

Categorizing gaps by severity, effort to remediate, and compliance audit impact.

08

Reporting & Remediation Workshop

Delivering the benchmark scorecard and hosting a technical walkthrough with your engineering leads.

Deliverables

What You Receive

Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.

  • CIS Foundations Benchmark Scorecard and Gap Analysis
  • Control-by-Control Findings Spreadsheet with Status Ratings
  • IAM Least-Privilege Remediation Plan with Code Examples
  • Logging, Monitoring, and Forensic Readiness Summary
  • Prioritised Action Plan Organized by Engineering Effort vs Risk
  • Executive Summary for Leadership and Audit Committees
  • Free Retest Verification of Remediated Controls within 48 hours
  • Formal Letter of Attestation Documenting Configuration Baseline
Typical Results

What We Usually Find

The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.

Root Account Used for Daily Tasks Without Hardware MFA Over-Permissioned IAM Service Roles with AdministratorAccess CloudTrail or Activity Logs Not Sent to Centralized Bucket Security Groups Allowing Inbound 0.0.0.0/0 to SSH / RDP Object Storage Buckets Missing Default Encryption Unrotated Long-Lived Access Keys for Service Accounts Unattached and Unencrypted EBS Volumes or Managed Disks Missing Automated Backup and Cross-Region Replication Policies
Fit

Who This Is For

Companies Preparing for SOC 2 Type I / Type II or ISO 27001 Audits
Organizations Seeking a Non-Disruptive Assessment of Cloud Posture
Engineering Teams Needing an Independent Cloud Baseline Review
Canadian Businesses Undergoing Annual Cyber Risk Due Diligence
Firms with Rapid Cloud Deployments Needing Configuration Guardrails
Organizations Migrating Sensitive Data to Cloud Infrastructure
Standards this assessment supports

Findings are mapped directly to CIS Benchmarks, SOC 2 Type II, ISO 27001, CSA CCM, OSFI B-13, PIPEDA, allowing your team to drop the report into an audit package without manual translation.

Canadian Operations

Calgary & Toronto Security Specialists

For Canadian organizations that do not require active adversarial exploitation, a cloud configuration review provides an audit-defensible baseline against CIS benchmarks. This satisfies SOC 2 CC6.1, ISO 27001 A.8.8, and Canadian provincial privacy safeguards efficiently.

Calgary OfficeAlberta Operations
Toronto OfficeOntario Operations
FAQ

Common Questions

What access is required to perform a cloud configuration review? +

Only read-only API access (e.g. AWS SecurityAudit policy or Azure Security Reader role). We do not require write or administrative access, and our tools make zero modifications to your environment.

How is this different from running an automated CSPM tool? +

Automated tools produce endless notifications without architectural context. Our senior assessors review the output manually, eliminate false positives, evaluate real risk in your specific business context, and provide human-written remediation guidance.

Can we use this report for our SOC 2 or ISO 27001 audit? +

Yes. Our reports are designed specifically to serve as auditor-accepted evidence for SOC 2, ISO 27001, and regulatory reviews, complete with control mappings and remediation timelines.

Do you provide remediation scripts or Terraform code? +

Yes. Whenever applicable, our findings include specific Infrastructure-as-Code snippets (Terraform, CloudFormation, or AWS CLI commands) to streamline your engineering team's fix implementation.

Client Stories

Trusted by Fast-Growing Companies

JBWeb

Digital Agency

“From Pentest to malware analysis these guys know what they're doing.”

We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.

SOCaaS Incident Response
Flowtriq

SaaS Platform

“Streamlined Security Testing with White Glove Service”

We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.

Penetration Testing Continuous Assessments
Next

Scope It in One Call

Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.