Sanctus Cybersecurity Sanctus Cybersecurity

Services / Cloud Security Review

Cloud Security Review for Iowa Businesses

A cloud security review checks how your cloud environment, such as Amazon Web Services (AWS), is actually configured. We look for the settings attackers go after first, such as overly broad permissions, exposed storage, and missing logs, and give your team a prioritized plan to fix them.

Default settings aren't secure settings

Moving to the cloud didn't move responsibility for security to your provider. They secure the data centers and the underlying platform. How your accounts, users, networks, and storage are set up is still up to you.

Cloud environments also grow quickly. A test account that was never cleaned up, an access key created for a one-off project, or a storage bucket opened up to share a file can stay that way for years without anyone noticing.

What we review

Identity and access management

Who can do what in your cloud accounts, whether permissions follow least privilege, and which users, roles, and service accounts have far more access than they need.

MFA and access keys

Whether multi-factor authentication protects every account that matters, especially administrators, and whether long-lived access keys are rotated, scoped, and still needed.

Network rules and segmentation

Security groups, network access rules, and virtual network design, looking for services exposed to the internet that shouldn't be and workloads that can reach more than they should.

Storage permissions and public access

Storage buckets, such as Amazon S3, that are public or shared more widely than intended, along with encryption and backup settings.

Logging, monitoring, and alerting

Whether activity in your cloud accounts is logged, for example through AWS CloudTrail, kept long enough to investigate an incident, and watched by someone who would notice something unusual.

Checked against recognized benchmarks

We measure your configuration against recognized security benchmarks for your platform, such as the CIS AWS Foundations Benchmark for AWS. Automated checks give us full coverage, and we review every result by hand so your report only contains what's real and relevant.

The review is non-destructive. We work from read-only access and never change anything in your environment.

How it works

  1. 1. Scoping

    We talk through which cloud accounts and workloads you use and what prompted the question, then agree on scope. You set up read-only access for the review, and you get a quote before work starts.

    A few days, mostly on your schedule

  2. 2. Review

    We check your configuration setting by setting against recognized security benchmarks for your platform, then review the results by hand to confirm what matters and remove the noise.

    Typically one to two weeks, depending on scope

  3. 3. Reporting and walkthrough

    You receive a plain-English report and a prioritized plan, then we walk your team through what we found and what to fix first.

    Report within a week, then a one to three hour walkthrough

What you receive

  • Executive summary you can share with leadership, your insurer, or a customer asking about your cloud security
  • Findings report listing each misconfiguration with its severity, why it matters, and the exact setting to change
  • Prioritized remediation roadmap so your team fixes the riskiest exposures first
  • Results walkthrough with whoever manages your cloud environment

What a cloud security review costs

Cloud security reviews start at $4,000. Where yours lands depends on how many cloud accounts are in scope and how large the environment is.

If you also run systems on premises or want a broader look at your security program, a security posture review covers both.

Who it's for

  • Small and mid-sized businesses running workloads or data in the cloud
  • Teams that set up their cloud environment quickly and never had it reviewed
  • Organizations answering insurer or customer questions about how their cloud is secured
  • Businesses preparing for growth, a new application launch, or an audit

Reviews are performed by GPEN, GCIH, and GSEC certified consultants. We are independent. We don't manage your cloud or resell cloud services, so we have no reason to downplay what we find.

Cloud security review questions

How much does a cloud security review cost?

Cloud security reviews start at $4,000. The price depends on how many cloud accounts are in scope and how large the environment is. We scope every review up front, so you have a quote before any work starts.

Which cloud platforms do you review?

Most of our cloud work is in Amazon Web Services (AWS), and the security fundamentals carry across cloud platforms. If your business runs on a different platform, contact us and we'll scope it with you honestly.

Do you need access to our cloud accounts?

Yes, but only read-only access. You create a read-only auditor account or role for the review, and you can remove it as soon as we're finished. We never change anything in your environment.

Isn't our cloud provider responsible for security?

Only part of it. Cloud providers secure the underlying infrastructure, but how your accounts, identities, networks, and storage are configured is your responsibility. Most cloud breaches come from those settings, not from the provider.

How long does a cloud security review take?

Scoping usually takes a few days, mostly on your schedule. The review itself typically takes one to two weeks, depending on how much is in scope. The report is ready within a week of the review, and the results walkthrough usually takes one to three hours.

How is this different from a security posture review?

A security posture review looks at your whole security program, including people, processes, and on-premises systems. A cloud security review goes deep on one area, the configuration of your cloud environment, setting by setting.

Ready to find out where you stand?

Tell us what's prompting the question. We'll come back with a few questions of our own, not a sales pitch.

Find Out Where You Stand