By industry

Hardened infrastructure, assessed like an attacker

Hardened infrastructure and pipelines, assessed the way attackers would.

The estate changes faster than any annual assessment can describe it. What matters is whether the controls hold when infrastructure is created by code, by several teams, many times a day.


The regulatory picture

What this sector has to satisfy

Cloud-specific controls on top of the general ones, plus the independent testing that proves they hold.


Where you are

The constraints at this stage

What tends to be true when companies come to us at this size.

Accounts multiply faster than governance

New accounts, subscriptions and projects appear for good reasons and inherit none of the guardrails. The control set describes the estate as it was at the last audit.

The pipeline is the most privileged thing you own

CI holds credentials for everything and can deploy anywhere. It is rarely scoped, reviewed or monitored to the standard those privileges deserve.

Identity sprawl is mostly non-human

Service accounts, roles, tokens and workload identities vastly outnumber people, and almost none of them have an owner, an expiry or a review.


How the engagement works

What actually happens

The same four beats every time, scoped to what this stage needs.

Inventory the real estate

Every account, subscription and project, including the ones created outside the original scope. Discovery is where most of the findings are.

Set guardrails, not documents

Baseline configuration, identity boundaries and network design expressed so new accounts inherit them by default rather than by policy.

Secure the path to production

Pipeline permissions scoped, secrets handled properly, build inputs verified, and non-human identities given owners and lifecycles.

Test what is deployed

Testing against the live environment, retests after remediation, and continuous posture monitoring rather than an annual snapshot.


Proof

Track record

Across every engagement we have run, at every size.

0+

Companies Secured

Zero

Failed Audits

4-8

Weeks to Compliance

0+

Team Certifications


What you walk away with

The artefacts

Everything below is a thing you own at the end, not a promise about the process.

  • A complete inventory of cloud accounts, subscriptions and projects
  • Cloud posture assessment with prioritised, owned remediation
  • A baseline configuration new environments inherit by default
  • Pipeline and secrets review with scoped CI permissions
  • A non-human identity inventory with owners, rotation and expiry
  • Penetration test and retest reports against the live estate
  • ISO 27017 control implementation with a documented responsibility split

Related

Where to go next

The problems this stage usually arrives with, and the services behind them.


Questions

What people ask at this stage

It is a code of practice extending ISO 27001 with cloud-specific controls, assessed alongside it rather than certified independently. Its real value is forcing an explicit shared-responsibility split between you and your provider.
Yes. Scope, timing and rules of engagement are agreed up front, and destructive techniques are excluded unless you specifically want them in a non-production environment. The goal is finding what an attacker would, not causing an incident.
It is the preferred case — controls expressed in Terraform or equivalent apply to every environment created afterwards, rather than drifting. We review the modules and the pipeline that applies them, not just the running resources.
One control set, expressed per provider. The intent is identical across AWS, Azure and GCP; the implementation and the evidence differ, and those are handled per platform.

Make the guardrails the default.

Tell us how many accounts you have and who can deploy. That conversation usually finds the gap on its own.