What you receive
A summary of reviewed resources, configuration findings and prioritised recommendations.
A summary of reviewed resources, configuration findings and prioritised recommendations.
Your cloud team supplies access or evidence and validates changes before implementation.
Follow-up checks require their own arrangements; this review does not provide ongoing monitoring.
A clearly defined scope. A configuration review is not a penetration test or an assurance statement about every workload. Coverage and conclusions depend on the agreed scope and available access.
For examining access, storage and logging configuration. Review the devices used by administrators separately where their protection is also a concern. Explore device security reviews.
We’ll agree a written proposal and obtain authorisation before the assessment begins.
A cloud security review examines agreed configuration settings in AWS, Azure or Google Cloud. It focuses on how access, storage exposure and logging are configured within the environment in scope.
Review account protection and access permissions within the agreed accounts, subscriptions or projects.
Review relevant storage settings and public accessibility to identify potentially unintended exposure.
Examine the logging configuration in scope and highlight gaps that may limit your ability to investigate activity.
Identity and access management (IAM), storage exposure and logging are common concerns. Human identities represent people; workload identities, such as service accounts or roles used by applications, represent software. Both need appropriate permissions. The examples below help identify which parts of your environment belong in the review.
| Provider | Controls and evidence | Questions to investigate |
|---|---|---|
| AWS | IAM roles and permissions; Amazon S3 bucket permissions and S3 Block Public Access; CloudTrail event coverage. | Do people and workloads have appropriate permissions? Is storage access intentional, and are the needed activity events being recorded? |
| Azure | Azure role-based access control (RBAC) assignments; Blob Storage anonymous-access settings; Activity Log and relevant resource logging. | Are roles limited to the necessary resources? Can blobs be read anonymously? Distinguish subscription activity from logs of operations on data. |
| Google Cloud | IAM role bindings and service accounts; Cloud Storage public access prevention; Cloud Audit Logs configuration. | Which identities can use the resources? Is public access appropriate, and do the enabled audit log categories cover the events you need? |
Configuration evidence and activity evidence answer different questions. Access settings show what is permitted; the available logs may help investigate what happened. Public-access controls are only part of storage security: other permissions and authorised sharing paths still matter. The review scope identifies resources, identities, logging coverage and the baseline used. Your cloud owner should identify any required benchmark and version, confirm reviewer access or evidence exports, and remove temporary permissions afterwards.
Review configuration decisions after moving workloads or adding accounts and projects. Document which environments have been assessed and what remains outside the review.
Examine permissions and storage exposure relevant to the workloads in scope. Use findings to investigate access that may be broader than intended.
Translate configuration findings into prioritised work with owners. An agreed report can support internal assurance without implying that every cloud service has been assessed.
Review the permissions in scope against the work people and services need to perform. Broad privileges can increase the effect of a stolen or misused identity. Changes need to account for application dependencies and emergency access arrangements.
Understand whether storage access matches its intended use. Some resources are deliberately public; others contain information that should be restricted. The useful outcome is an informed access decision supported by configuration evidence.
Review the logging settings agreed for your environment. Missing or incomplete records can make later investigation harder. Configuration evidence helps identify improvements, but a review is not an ongoing service that monitors or responds to those logs.
Identify which team owns permissions, storage configuration and logging across the reviewed accounts. A cloud provider’s infrastructure protections do not remove your responsibility for the configuration and use of your own environment.
A prioritised report can group findings by account, subscription or project and responsible owner. This makes it easier to schedule changes and identify repeated configuration problems instead of treating every resource as an isolated task.
Use the reviewed account list, findings and remediation record to explain what has been examined to management or customers. Keep the scope attached to the evidence so a focused review is not mistaken for assurance over every cloud workload.
Identify providers, accounts, subscriptions or projects and the business services they support. Agree review depth and exclusions.
Agree permissions and evidence-sharing arrangements. Limit review access to what is needed and record how it will be removed afterwards.
Examine the agreed identity, storage and logging settings. Interpret findings in the context of intended use and the information available.
Give cloud owners a prioritised view of configuration gaps. Validate proposed changes against application dependencies before implementation.
Record changes and agree any follow-up checks. New services and configuration changes can introduce gaps after the review.

Work is authorised in writing before any assessment begins, and stays within the agreed scope.
Related services answer different questions. Confirm which scope you are buying before you compare quotes.
| Approach | What it tells you | Scope to confirm |
|---|---|---|
| Cloud security review | Examines agreed AWS, Azure or Google Cloud settings for configuration gaps. | Focuses on permissions, storage exposure and logging within the agreed scope. |
| Penetration testing | Investigates exploitable behaviour in agreed cloud-hosted applications or networks. | Requires a separate test scope and applicable hosting permissions. |
| Continuous cloud monitoring | Checks for changes or signals over time according to the monitoring service. | A configuration review is an assessment, not a promise of continuous detection or response. |
Illustrative example, not a client case study
This is a teaching example of a finding record, not an extract from a customer report or a promise of a particular report template.
The providers, account or project count, services in scope, review depth and access arrangements determine the quote. Multi-cloud coverage needs explicit boundaries for each environment. Confirm whether follow-up checks and additional SaaS applications are included.
List providers, accounts, subscriptions or projects, critical workloads and technical owners. Explain existing identity and logging arrangements and any restrictions on reviewer access. Agree the permission set, evidence-sharing method and removal of temporary access.
Allow for access preparation, the assessment, report delivery and your team’s remediation work. Confirm the delivery format, dates and any follow-up checks in your quote so each team knows when its input is needed.

Practical answers about scope, cost and what happens next.
Compare all six security servicesA cloud security review examines agreed configuration settings in AWS, Azure or Google Cloud. It focuses on how access, storage exposure and logging are configured within the environment in scope.
Link to this answerYes. Reviews can cover agreed AWS, Azure and Google Cloud environments. Each environment, the depth of review and required access are included in the scope and quote.
Link to this answerThis service is described around agreed AWS, Azure and Google Cloud configurations. Microsoft 365 or other SaaS applications should be raised separately during scoping, not assumed to be included in an Azure review.
Link to this answerNo. A configuration review and a penetration test are different services. If you need controlled attempts to exploit a cloud-hosted application or network, agree that scope and the required permissions separately.
Link to this answerThe access required depends on the agreed review. We confirm an appropriate permission set or evidence-based approach during scoping; unrestricted administrator access is not a default requirement.
Link to this answerNo. Responsibilities depend on the service model. The provider manages parts of the underlying service, while your organisation still makes decisions about its identities, data and configuration. A review should identify the customer-controlled settings that are in scope.
Link to this answerIt can if dependencies are not understood. A review identifies issues and recommended changes; your cloud team should validate and implement fixes through its change process. Do not assume that the review includes live configuration changes.
Link to this answerThe providers, account or project count, services in scope, review depth and access arrangements determine the quote. Multi-cloud coverage needs explicit boundaries for each environment. Confirm whether follow-up checks and additional SaaS applications are included.
Link to this answerNo. Security testing and reviews can help identify gaps, but certification requires a separate assessment under the relevant scheme. Buying this service does not guarantee certification.
Link to this answerExplore a different assessment, manage remediation or prepare for certification.
Related service
A qualified tester attempts to exploit weaknesses in agreed applications, APIs or networks, with written authorisation. Includes a report, fix guidance and a retest of the findings.
ExploreRelated service
Review laptop and mobile-device protection, including encryption, screen locks, updates and lost-device risks.
ExploreSoftware
Manage compliance gaps, remediation and supporting evidence.
ExploreCertification
Explore certification options for your organisation.
ExploreIndependent sources that explain the methods and controls behind the review.
Independent guidance
Guidance on cloud configuration, access boundaries, permissions and activity logging.
Work with Fig directly or through your MSP. Your proposal identifies the contracting entity, assessment scope and delivery responsibilities.
The companies
See the entities, licences and people behind the platform and our assessments.
ExploreMSP partners
Offer these services under your own brand and retain the client relationship.
ExplorePublished evidence
Verify our company details, licences and the claims we make in public.
ExploreContent updated .
Tell us what you need from cloud security reviews, the systems involved and any deadline. We’ll discuss the options and provide a quote.