Cloud Configuration Review
A systematic CIS benchmark audit of your AWS, Azure, or GCP environment - delivered as an audit-ready baseline and engineering remediation plan.
What This Engagement Covers
The Service
The majority of cloud data breaches are caused by misconfigurations rather than zero-day exploits: unencrypted data at rest, excessive IAM privileges, disabled audit logs, and open network security groups. Our cloud configuration review performs a deep, systematic assessment of your cloud accounts against industry benchmarks (CIS Cloud Foundations, CSA Cloud Controls Matrix) and best practices, providing your engineering team with prioritized, actionable guidance.
What We Test
We review all core architectural components in AWS, Azure, or GCP: IAM users, groups, roles, and password policies; multi-factor authentication enforcement; storage access controls; encryption at rest and in transit; network security groups, firewalls, and routing tables; logging and monitoring (CloudTrail, CloudWatch, GuardDuty, Azure Monitor); and backup and disaster recovery configurations.
Components Evaluated in Scope
Our testers systematically inspect the following architectural layers and attack vectors during the assessment.
How We Run It
Using read-only API access, our assessors perform both automated collection and detailed manual analysis of your cloud control plane. We evaluate configurations against the CIS Benchmarks and cross-reference your specific regulatory obligations, eliminating false positives and delivering concrete Terraform, CloudFormation, or CLI remediation commands.
Scope Definition & Baseline Selection
Confirming in-scope accounts, benchmark version (CIS Level 1 or Level 2), and specific compliance frameworks.
Automated Data & Configuration Harvest
Executing read-only audit scripts to capture resource states across IAM, networking, compute, and storage.
Manual IAM & Policy Evaluation
Deep manual inspection of IAM trust relationships, cross-account permissions, and conditional access policies.
Network & Perimeter Security Review
Analyzing security groups, routing tables, and public IP allocations for unintended internet exposure.
Logging, Alerting & Forensic Readiness
Verifying audit trail immutability, centralized log forwarding, and real-time security alerting configurations.
Data Protection & Encryption Audit
Reviewing KMS key configurations, customer-managed key usage, and volume/bucket encryption standards.
Gap Analysis & Risk Prioritisation
Categorizing gaps by severity, effort to remediate, and compliance audit impact.
Reporting & Remediation Workshop
Delivering the benchmark scorecard and hosting a technical walkthrough with your engineering leads.
What You Receive
Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.
- CIS Foundations Benchmark Scorecard and Gap Analysis
- Control-by-Control Findings Spreadsheet with Status Ratings
- IAM Least-Privilege Remediation Plan with Code Examples
- Logging, Monitoring, and Forensic Readiness Summary
- Prioritised Action Plan Organized by Engineering Effort vs Risk
- Executive Summary for Leadership and Audit Committees
- Free Retest Verification of Remediated Controls within 48 hours
- Formal Letter of Attestation Documenting Configuration Baseline
What We Usually Find
The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.
Who This Is For
Findings are mapped directly to CIS Benchmarks, SOC 2 Type II, ISO 27001, CSA CCM, OSFI B-13, PIPEDA, allowing your team to drop the report into an audit package without manual translation.
Calgary & Toronto Security Specialists
For Canadian organizations that do not require active adversarial exploitation, a cloud configuration review provides an audit-defensible baseline against CIS benchmarks. This satisfies SOC 2 CC6.1, ISO 27001 A.8.8, and Canadian provincial privacy safeguards efficiently.
Common Questions
Only read-only API access (e.g. AWS SecurityAudit policy or Azure Security Reader role). We do not require write or administrative access, and our tools make zero modifications to your environment.
Automated tools produce endless notifications without architectural context. Our senior assessors review the output manually, eliminate false positives, evaluate real risk in your specific business context, and provide human-written remediation guidance.
Yes. Our reports are designed specifically to serve as auditor-accepted evidence for SOC 2, ISO 27001, and regulatory reviews, complete with control mappings and remediation timelines.
Yes. Whenever applicable, our findings include specific Infrastructure-as-Code snippets (Terraform, CloudFormation, or AWS CLI commands) to streamline your engineering team's fix implementation.
Trusted by Fast-Growing Companies
We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.
We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.
Scope It in One Call
Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.