Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Service

Cloud and application security reviews that catch risk early

A practitioner review of how your cloud environment and applications are designed and configured (identity, network exposure, data protection, logging, and secure design), with prioritized fixes your engineers can apply.

What we deliver

Cloud and application security reviews covering architecture, configuration, identity, logging, and secure design.

References
NIST CSF 2.0

Who it's for

A good fit for

  • SaaS teams running production workloads in one or more public clouds
  • Engineering leaders whose cloud environment grew quickly and who want an outside review of it
  • Teams planning a major architecture change, migration, or new product that want design input early
  • Organizations facing customer security reviews with detailed cloud and application questions

Not the right fit for

  • Organizations that want active exploitation of their systems, which is penetration testing
  • Teams looking for an ongoing managed cloud security or monitoring service
  • Organizations with no cloud footprint and no applications of their own

Problems it addresses

  • Access to cloud accounts has grown over time, and no one is sure who can do what.
  • Storage, databases, or services may be exposed to the internet by accident.
  • Logs exist, but they wouldn't answer basic questions after an incident.
  • Security gets reviewed at the end of development, when changes are expensive.
  • Secrets, keys, and credentials are scattered across code, pipelines, and configuration.

Scope

Included

  • Architecture review of how workloads, data stores, networks, and third-party services connect
  • Identity and access review: administrative access, roles, service accounts, federation, and multi-factor coverage
  • Configuration review against recognized baselines for the cloud services you use
  • Logging and monitoring coverage: what's collected, where it's kept, and whether it would support an investigation
  • Data protection: encryption, key management, backups, and exposure of storage and databases
  • Secure design review of selected applications, including authentication, authorization, secrets handling, and build and deployment pipelines

Not included

  • Active exploitation or penetration testing (scoped separately)
  • Making configuration changes in your environment
  • Line-by-line source code review of entire codebases
  • Ongoing monitoring or managed security services

Deliverables

  • Findings report prioritized by risk and effort, with specific remediation steps
  • Architecture notes and diagrams that highlight trust boundaries and key risks
  • Identity and access summary showing privileged access and recommended changes
  • Logging coverage summary with recommended additions
  • Walkthrough of findings and fixes with your engineers

How the engagement runs

Every engagement begins with a written scope and proposal.

  1. Scope

    We agree on the cloud accounts, applications, and depth of review, and document them in a written scope.

  2. Access and discovery

    You grant read-only access or provide exports, and we review architecture documents and talk with the engineers who run the environment.

  3. Review

    We examine identity, configuration, logging, data protection, and application design against the agreed baselines.

  4. Report and walk through

    We deliver prioritized findings and walk your engineers through them, including which fixes to tackle first.

Standards and methods

  • CIS Benchmarks for cloud-service and workload configuration baselines
  • OWASP Application Security Verification Standard (ASVS) 5.0.0 for application security requirements
  • NIST CSF 2.0 outcomes for identity and access, data security, and continuous monitoring

Configuration baselines and secure design

Two vendor-neutral references anchor a cloud and application review, so each finding points to a published expectation rather than a reviewer's preference.

CIS Benchmarks are prescriptive configuration recommendations for more than 25 vendor product families, including operating systems, cloud providers, network devices, and databases. They're the product of a consensus-based effort by cybersecurity experts, and they give configuration findings a specific, citable reference point.

The OWASP Application Security Verification Standard (ASVS), at version 5.0.0 when checked on 2026-09-27, provides a basis for testing web application technical security controls and gives developers a list of requirements for secure development.

The two complement each other: benchmarks describe how platforms should be configured, and the ASVS describes how the application itself should behave. A design-stage review can use the ASVS as a checklist of requirements before any code is written.

Sources: CIS Benchmarks; OWASP Application Security Verification Standard (ASVS)

Prerequisites and your responsibilities

  • Read-only access to the cloud accounts in scope, or configuration exports if outside access isn't allowed
  • Architecture diagrams, or a walkthrough from an engineer who knows the environment
  • Engineers who can answer questions about design decisions during the review
  • A list of the applications and environments in scope, with an owner for each

Pricing

  • Cloud Security Review

    From $7,500

    Typical scoped range: $7,500 to $18,000

    One-time project

Non-binding. Final pricing follows a written scope and proposal.

What affects the final price

Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

Compare published prices for every service

Guides

Frequently asked questions

What access do you need?

Read-only access is usually enough. During scoping we list the permissions we need, so your team can create a dedicated, time-limited role and remove it when the review ends. If your policies don't allow outside access, configuration exports and guided screen-sharing work too.

How is this different from a penetration test?

A cloud and application review looks at how things are built and configured, and often finds issues a tester wouldn't reach within a fixed testing window. A penetration test tries to exploit weaknesses from an attacker's point of view. The two complement each other, and a review is often a useful first step.

Do you review infrastructure as code?

Yes, when it's in scope. Reviewing templates and modules can catch problems before they're deployed, and it helps fixes last because changes go into the code rather than being made by hand.

Can you review an application that's still being designed?

Yes. Design-stage reviews often cost the least to act on, because changing a diagram is cheaper than changing production. We review the proposed architecture, data flows, and identity model, and recommend changes before build work starts.

Primary sources

Talk to a practitioner about a cloud or application review

Share what’s prompting the work and what you need to decide, and we’ll help you judge whether this service is the right fit.

What happens next

  1. Tell us about your environment and what's driving the request.
  2. Talk through goals, constraints, and options with a practitioner.
  3. Review the proposal and decide whether to go ahead.