Assessments & Audits

Cloud security assessment that finds what's exposed.

Misconfigured cloud is the fastest way in. SubRosa audits your AWS, Azure, and Google Cloud environments, identity, storage, network, and workloads, against real attack paths and best-practice benchmarks, then hands you a prioritized plan to close the gaps.

AWS · Azure · GCP · IAM · Storage · Workloads

Cloud security assessment, defined

What is a cloud security assessment?

A cloud security assessment, also called a cloud security audit, is a review of your cloud environment, its configuration, identity and access, network exposure, data storage, and workloads, against known attack techniques and provider best practices like the CIS Benchmarks and the AWS, Azure, and GCP Well-Architected frameworks. It finds the misconfigurations and over-permissive access an attacker would exploit, and prioritizes them by real-world risk so you fix what matters first.

What we assess

Every layer of your cloud estate.

We review every part of your cloud an attacker would target, from identity to workloads.

Identity & access (IAM)

Over-permissive roles, unused credentials, missing MFA, and privilege-escalation paths across your cloud IAM.

Storage & data exposure

Public buckets, exposed databases, unencrypted volumes, and secrets left where an attacker can reach them.

Network & perimeter

Security groups, exposed services, network segmentation, and the internet-facing surface of your cloud.

Configuration & benchmarks

Configuration reviewed against CIS Benchmarks and provider best practices, with every drift documented and prioritized.

How the engagement runs

Read-only review, real findings.

A cloud security assessment inspects how your environment is actually configured. It is not a penetration test, and the difference matters when you are deciding which one you need.

  1. 01

    Read-only access and scoping

    We agree the accounts, subscriptions or projects in scope and take read-only access. Nothing is changed and nothing is exploited, which is what makes an assessment straightforward to authorise compared with a test against production.

  2. 02

    Identity and permission analysis

    Who can do what, and who could grant themselves more. Over-permissive roles, unused credentials with standing access, missing MFA on privileged identities, and trust relationships between accounts. This is where most cloud incidents actually begin.

  3. 03

    Data exposure review

    Storage buckets, databases, snapshots and backups get checked for public exposure and for encryption at rest. We flag what is exposed and, crucially, what is in it — the severity of an open bucket is determined by its contents, not by the fact that it is open.

  4. 04

    Network and perimeter review

    Security groups, ingress rules, exposed management ports, VPC and subnet design, and whether logging and monitoring would actually capture an incident. An environment with no useful logs is a finding in itself.

  5. 05

    Benchmark comparison

    Your configuration is compared against the provider's own benchmarks and CIS guidance, so recommendations sit against a recognised standard rather than an opinion.

  6. 06

    Prioritised report and debrief

    Findings arrive ranked by real risk rather than by count, with remediation steps specific to your provider, plus a live debrief. Findings can land in Sable so remediation is tracked with owners and due dates.

Why SubRosa

An attacker's view, not just a scan.

Multi-cloud expertise

Deep, hands-on experience across AWS, Azure, and Google Cloud, so the assessment reflects how each provider actually fails.

Attack-path focus

We chain misconfigurations into real attack paths to prove exploitable impact, not just flag every setting a scanner dislikes.

Prioritized remediation

Every finding is ranked by the risk it carries, so your team closes the exposures that actually matter before the noise.

Every finding, tracked to closed.

From audit to remediation.

Your cloud assessment findings land in Sable, prioritized, assigned, and tracked from open to retested, so remediation becomes a managed workflow instead of a spreadsheet of settings that never gets fixed.

Cloud findings in Sable
Cloud findingsAWS · Azure · GCP
  • Critical
    Public bucket exposes customer data
    S3
    Open
  • High
    Role allows privilege escalation
    IAM
    In progress
  • High
    Security group open to 0.0.0.0/0
    Network
    Retested
  • Medium
    CIS drift: logging disabled
    Config
    Open
IAM · storage · network · configCIS Benchmarks mapped

Common questions

What is a cloud security assessment?
A cloud security assessment, also called a cloud security audit, is a review of your cloud environment, its configuration, identity and access, network exposure, data storage, and workloads, against known attack techniques and provider best practices like the CIS Benchmarks and the AWS, Azure, and GCP Well-Architected frameworks. It finds the misconfigurations and over-permissive access an attacker would exploit, prioritized by real-world risk.
Which cloud providers do you assess?
SubRosa assesses AWS, Microsoft Azure, and Google Cloud, including multi-cloud and hybrid environments. We review identity and access (IAM), storage and data exposure, network and perimeter, and configuration against CIS Benchmarks and each provider's best practices.
How is a cloud security assessment different from a vulnerability scan?
A vulnerability scan flags known issues automatically. A cloud security assessment is performed by security engineers who chain misconfigurations into real attack paths, such as an over-permissive IAM role plus a public bucket, to prove exploitable impact and prioritize what actually matters instead of returning a long list of settings.
Is a cloud security assessment the same as cloud penetration testing?
No, and picking the wrong one wastes money. An assessment is a read-only review of how your environment is configured — permissions, exposure, logging, benchmark compliance — and needs no exploitation. A penetration test establishes what is actually exploitable and how far a foothold reaches. If you have never had either, start with the assessment: it is faster, cheaper, easier to authorise, and it usually surfaces the issues that matter most.
Which cloud providers do you assess?
AWS, Azure and Google Cloud, including multi-cloud and hybrid estates. Findings are compared against each provider's own benchmarks and CIS guidance so recommendations sit against a recognised standard rather than an opinion.
Will the assessment affect our production environment?
No. It runs with read-only access — nothing is changed, nothing is exploited, no load is generated. That is precisely why it is straightforward to authorise against production where a penetration test may not be.
How long does it take?
Typically one to two weeks depending on the number of accounts and services in scope. You receive findings ranked by real risk, remediation steps specific to your provider, and a live debrief. Findings can land directly in Sable so remediation is tracked to closure.

See your cloud the way an attacker does.

Book a cloud security assessment and find the misconfigurations and exposed access across your cloud before someone else does.