Cloud Security
Secure your digital backbone.
In the cloud, the question that matters is rarely whether there is an exploit. It is what one identity can reach. We find the permissions nobody needed, the storage nobody meant to share and the changes nobody reviewed, across AWS, Azure and GCP, and deliver the fixes as code.
AWS, Azure and GCP
Each assessed against its own CIS Foundations benchmark.
Read-only access
Configuration review runs through a read-only role, not admin keys.
Fixes as code
Findings come with Terraform and CloudFormation snippets.
Tools, then people
Scanners for breadth, manual review for the identity paths they miss.
Shared responsibility
Your provider secures the cloud. You secure what you put in it.
Every cloud provider draws a line. Below it, the infrastructure is theirs to protect. Above it, your data, your identities and your configuration are yours, whichever service you use.
Most cloud incidents happen on your side of that line, which is exactly where our work sits.
| Layer | IaaS | PaaS | SaaS |
|---|---|---|---|
| Data and content | You | You | You |
| Accounts and identities | You | You | You |
| Identity and directory | You | Shared | Shared |
| Applications | You | Shared | Provider |
| Network controls | You | Shared | Provider |
| Operating system | You | Provider | Provider |
| Physical hosts and datacentre | Provider | Provider | Provider |
The common shape of the model. Exact boundaries vary by provider and by service.
What we look at
Six domains, and the question behind each
The same six domains the App Defense Alliance Cloud profile groups its checks into. A benchmark tells you whether a setting is right; these are the questions that tell you whether you are safe.
Identity and access
“Which identities can reach what, and which of those permissions are ever used?”
Storage
“Is anything readable without authentication, including snapshots and backups?”
Networking
“Which management ports and services can the internet reach?”
Logging and monitoring
“If someone got in, would you be able to tell afterwards what they did?”
Compute
“Are instances and containers hardened, patched and running with minimal roles?”
Database services
“Are databases private and encrypted, and backed up where you think they are?”
Mapped to the benchmark for each provider
Amazon Web Services
CIS AWS Foundations Benchmark
Microsoft Azure
CIS Microsoft Azure Foundations Benchmark
Google Cloud
CIS Google Cloud Platform Foundation Benchmark
The domains are explained in full in our guide to the ADA Cloud App and Config profile.
Configuration drift
An assessment describes the day it was run
Cloud configuration changes every time someone deploys. An illustrative view of the same environment, watched two ways, after the same assessment.
Our approach
Assess, design, implement
We don't just secure infrastructure; we build resilience. Every service below belongs to one of three phases, so you can start wherever you are.
Phase 01
Assess
Deep-dive analysis of your current architecture and configuration against best practices.
Phase 02
Design
Architecting secure, scalable solutions based on Zero Trust principles.
Phase 03
Implement
Hands-on configuration, automation, and hardening of your environments.
Questions
Frequently asked questions
Do you need write access to our cloud accounts?
What is the difference between a cloud security assessment and cloud penetration testing?
Which clouds do you cover?
Isn’t the cloud provider responsible for security?
Do you just run a scanner against the CIS benchmark?
Can you fix what you find?
What is CSPM and do we need it?
How often should we have a cloud assessment?
Ready to secure your cloud?
Partner with Adayptus to build a secure, resilient, and compliant infrastructure. Tell us which providers and how many accounts, and we will come back with a scope.