Skip to content
For UK businesses and MSPs

Cloud security reviews
Configuration confidence across your cloud.

Fig reviews AWS, Azure and Google Cloud configurations for access, storage exposure and logging gaps. You receive a summary of the environment reviewed, findings explaining the security implications and prioritised recommendations for your cloud team.

At a glance

Your engagement at a glance

What you receive

A summary of reviewed resources, configuration findings and prioritised recommendations.

Your team’s part

Your cloud team supplies access or evidence and validates changes before implementation.

Follow-up arrangements

Follow-up checks require their own arrangements; this review does not provide ongoing monitoring.

A clearly defined scope. A configuration review is not a penetration test or an assurance statement about every workload. Coverage and conclusions depend on the agreed scope and available access.

For examining access, storage and logging configuration. Review the devices used by administrators separately where their protection is also a concern. Explore device security reviews.

Start with a scope discussion

We’ll agree a written proposal and obtain authorisation before the assessment begins.

Request a cloud review
The scope

What do Fig cloud security reviews cover?

A cloud security review examines agreed configuration settings in AWS, Azure or Google Cloud. It focuses on how access, storage exposure and logging are configured within the environment in scope.

Identity and permissions

Review account protection and access permissions within the agreed accounts, subscriptions or projects.

Storage and exposure

Review relevant storage settings and public accessibility to identify potentially unintended exposure.

Visibility and logging

Examine the logging configuration in scope and highlight gaps that may limit your ability to investigate activity.

Assessment detail

How does a review differ across AWS, Azure and Google Cloud?

Identity and access management (IAM), storage exposure and logging are common concerns. Human identities represent people; workload identities, such as service accounts or roles used by applications, represent software. Both need appropriate permissions. The examples below help identify which parts of your environment belong in the review.

Provider-specific examples of identity, storage and logging checks
ProviderControls and evidenceQuestions to investigate
AWSIAM roles and permissions; Amazon S3 bucket permissions and S3 Block Public Access; CloudTrail event coverage.Do people and workloads have appropriate permissions? Is storage access intentional, and are the needed activity events being recorded?
AzureAzure role-based access control (RBAC) assignments; Blob Storage anonymous-access settings; Activity Log and relevant resource logging.Are roles limited to the necessary resources? Can blobs be read anonymously? Distinguish subscription activity from logs of operations on data.
Google CloudIAM role bindings and service accounts; Cloud Storage public access prevention; Cloud Audit Logs configuration.Which identities can use the resources? Is public access appropriate, and do the enabled audit log categories cover the events you need?

Configuration evidence and activity evidence answer different questions. Access settings show what is permitted; the available logs may help investigate what happened. Public-access controls are only part of storage security: other permissions and authorised sharing paths still matter. The review scope identifies resources, identities, logging coverage and the baseline used. Your cloud owner should identify any required benchmark and version, confirm reviewer access or evidence exports, and remove temporary permissions afterwards.

When to book

When to book cloud security reviews

After migration or expansion

Review configuration decisions after moving workloads or adding accounts and projects. Document which environments have been assessed and what remains outside the review.

Before sharing sensitive information

Examine permissions and storage exposure relevant to the workloads in scope. Use findings to investigate access that may be broader than intended.

Give cloud teams a clear backlog

Translate configuration findings into prioritised work with owners. An agreed report can support internal assurance without implying that every cloud service has been assessed.

Security benefits

Security benefits of cloud security reviews

Identify excessive access

Review the permissions in scope against the work people and services need to perform. Broad privileges can increase the effect of a stolen or misused identity. Changes need to account for application dependencies and emergency access arrangements.

Investigate unintended public storage

Understand whether storage access matches its intended use. Some resources are deliberately public; others contain information that should be restricted. The useful outcome is an informed access decision supported by configuration evidence.

Expose gaps in activity records

Review the logging settings agreed for your environment. Missing or incomplete records can make later investigation harder. Configuration evidence helps identify improvements, but a review is not an ongoing service that monitors or responds to those logs.

Commercial value

The commercial value for your organisation

Clarify responsibilities after migration

Identify which team owns permissions, storage configuration and logging across the reviewed accounts. A cloud provider’s infrastructure protections do not remove your responsibility for the configuration and use of your own environment.

Plan changes across cloud teams

A prioritised report can group findings by account, subscription or project and responsible owner. This makes it easier to schedule changes and identify repeated configuration problems instead of treating every resource as an isolated task.

Support assurance with a defined scope

Use the reviewed account list, findings and remediation record to explain what has been examined to management or customers. Keep the scope attached to the evidence so a focused review is not mistaken for assurance over every cloud workload.

How it works

Your cloud security reviews engagement

  1. Map the environment

    Identify providers, accounts, subscriptions or projects and the business services they support. Agree review depth and exclusions.

  2. Arrange suitable access

    Agree permissions and evidence-sharing arrangements. Limit review access to what is needed and record how it will be removed afterwards.

  3. Review configurations

    Examine the agreed identity, storage and logging settings. Interpret findings in the context of intended use and the information available.

  4. Plan remediation

    Give cloud owners a prioritised view of configuration gaps. Validate proposed changes against application dependencies before implementation.

  5. Keep the evidence current

    Record changes and agree any follow-up checks. New services and configuration changes can introduce gaps after the review.

Two colleagues working through a review together at a desk

Work is authorised in writing before any assessment begins, and stays within the agreed scope.

Compare approaches

Cloud configuration review or cloud penetration testing?

Related services answer different questions. Confirm which scope you are buying before you compare quotes.

Compare the purpose and scope of related approaches
ApproachWhat it tells youScope to confirm
Cloud security reviewExamines agreed AWS, Azure or Google Cloud settings for configuration gaps.Focuses on permissions, storage exposure and logging within the agreed scope.
Penetration testingInvestigates exploitable behaviour in agreed cloud-hosted applications or networks.Requires a separate test scope and applicable hosting permissions.
Continuous cloud monitoringChecks for changes or signals over time according to the monitoring service.A configuration review is an assessment, not a promise of continuous detection or response.

Illustrative example, not a client case study

A storage resource is accessible more widely than intended

How to read a finding: evidence, decision and next action
Scope
A storage resource intended for a private application workload.
Observed configuration
The access policy permits a wider audience than the resource owner intended. The record identifies the account/project and resource.
Evidence boundary
Permissions describe possible access. They do not establish that data was read. Available activity logs may support a separate investigation.
Owner and action
The cloud owner validates application dependencies, restricts unintended access and confirms legitimate access still works.
Verification
Retain the updated policy and validation result. Review equivalent resources where the same configuration pattern was reused.

This is a teaching example of a finding record, not an extract from a customer report or a promise of a particular report template.

Cost and preparation

What affects the scope and cost?

The providers, account or project count, services in scope, review depth and access arrangements determine the quote. Multi-cloud coverage needs explicit boundaries for each environment. Confirm whether follow-up checks and additional SaaS applications are included.

What to prepare for your enquiry

List providers, accounts, subscriptions or projects, critical workloads and technical owners. Explain existing identity and logging arrangements and any restrictions on reviewer access. Agree the permission set, evidence-sharing method and removal of temporary access.

Plan the engagement around your deadline

Allow for access preparation, the assessment, report delivery and your team’s remediation work. Confirm the delivery format, dates and any follow-up checks in your quote so each team knows when its input is needed.

A person planning an engagement with a notebook and laptop
Questions

Cloud security reviews questions

Practical answers about scope, cost and what happens next.

Compare all six security services
What are cloud security reviews?

A cloud security review examines agreed configuration settings in AWS, Azure or Google Cloud. It focuses on how access, storage exposure and logging are configured within the environment in scope.

Link to this answer
Can you review more than one cloud provider?

Yes. Reviews can cover agreed AWS, Azure and Google Cloud environments. Each environment, the depth of review and required access are included in the scope and quote.

Link to this answer
Does the review cover Microsoft 365?

This service is described around agreed AWS, Azure and Google Cloud configurations. Microsoft 365 or other SaaS applications should be raised separately during scoping, not assumed to be included in an Azure review.

Link to this answer
Is cloud penetration testing included?

No. A configuration review and a penetration test are different services. If you need controlled attempts to exploit a cloud-hosted application or network, agree that scope and the required permissions separately.

Link to this answer
Do you need administrator access?

The access required depends on the agreed review. We confirm an appropriate permission set or evidence-based approach during scoping; unrestricted administrator access is not a default requirement.

Link to this answer
Is the cloud provider responsible for all of our security?

No. Responsibilities depend on the service model. The provider manages parts of the underlying service, while your organisation still makes decisions about its identities, data and configuration. A review should identify the customer-controlled settings that are in scope.

Link to this answer
Will changing cloud permissions break our applications?

It can if dependencies are not understood. A review identifies issues and recommended changes; your cloud team should validate and implement fixes through its change process. Do not assume that the review includes live configuration changes.

Link to this answer
How much do cloud security reviews cost?

The providers, account or project count, services in scope, review depth and access arrangements determine the quote. Multi-cloud coverage needs explicit boundaries for each environment. Confirm whether follow-up checks and additional SaaS applications are included.

Link to this answer
Does this service provide compliance certification?

No. Security testing and reviews can help identify gaps, but certification requires a separate assessment under the relevant scheme. Buying this service does not guarantee certification.

Link to this answer
Your next step

Choose the support you need.

Explore a different assessment, manage remediation or prepare for certification.

Related service

Penetration testing

A qualified tester attempts to exploit weaknesses in agreed applications, APIs or networks, with written authorisation. Includes a report, fix guidance and a retest of the findings.

Explore

Related service

Device security reviews

Review laptop and mobile-device protection, including encryption, screen locks, updates and lost-device risks.

Explore

Software

The Fig platform

Manage compliance gaps, remediation and supporting evidence.

Explore

Certification

Cyber Essentials

Explore certification options for your organisation.

Explore
Further reading

Further technical guidance

Independent sources that explain the methods and controls behind the review.

Accountability

Working with Fig

Work with Fig directly or through your MSP. Your proposal identifies the contracting entity, assessment scope and delivery responsibilities.

The companies

Meet the companies behind Fig

See the entities, licences and people behind the platform and our assessments.

Explore

MSP partners

Security services for MSP partners

Offer these services under your own brand and retain the client relationship.

Explore

Published evidence

Company details and published evidence

Verify our company details, licences and the claims we make in public.

Explore

Let’s agree the right scope.

Tell us what you need from cloud security reviews, the systems involved and any deadline. We’ll discuss the options and provide a quote.

Request a cloud review