Skip to content

Utilities Studio / Cybersecurity

Cloud security services

Know which cloud permissions and configurations need your attention.

Review AWS, Azure, and Google Cloud security. Assess IAM permissions, exposed services, and workload boundaries, with a prioritized hardening plan.

Your cloud team needs changes it can put into practice.

If you run the cloud environment, a list of configuration warnings still leaves you with the hard decisions. Which permissions expose sensitive data? Which changes affect a workload? We review the accounts and services in scope and connect the gaps to practical hardening work for your team.

The assessment

Cloud security services

A cloud security assessment examines how cloud resources are configured, who can access them, and which paths could expose data or workloads. We review your agreed environment and document the changes your infrastructure team can make. Where you need exploitation testing rather than a configuration review, we scope cloud penetration testing separately.

Inside the scope

AWS, Azure, and Google Cloud

The accounts, subscriptions, or projects named in scope, including their shared responsibilities and access boundaries.

Cloud IAM

Human and workload identities, role assignments, excessive permissions, and paths to privileged resources.

Exposure and segmentation

Public services, network rules, and access to sensitive storage or management interfaces.

Containers and workloads

Kubernetes and Docker configurations, workload access, and the cloud resources they depend on when included in scope.

What your team receives

  • Cloud exposure assessment
  • Permission and configuration findings
  • Prioritized hardening plan

Working with your team

From scope to remediation.

01

Agree the scope

Tell us what is driving the work and which systems matter. We agree access, exclusions, and operational limits, including who to contact if the assessment uncovers an urgent issue.

02

Investigate and document

Assess the systems in scope and document the evidence. Findings explain the affected assets and business impact, with the limits of the investigation made clear.

03

Review the next actions

Review the findings with the people responsible for fixing them. Work through priorities and questions about remediation. The proposal sets out any follow-up verification.

What are you paying for?

Account count, workload complexity, identity architecture, configuration review depth and remediation support.

Planning around your deadline

Timing depends on access and the breadth of workloads. We agree on the assessment window, findings review and any implementation phase separately.

The practitioner behind the work

Led by Sheeraz Ali.

Sheeraz Ali is our Head of Cybersecurity. His work spans application, cloud, network, and AI assessments. His personal track record includes leading pentests at Cobalt and building the internal pentest programme at SolarWinds.

Read Sheeraz's security background

Sheeraz's personal track record

Pentest engagements at Cobalt
245
Vulnerabilities identified at Cobalt
1,592
CVEs discovered
28+
Machines and labs authored at Hack The Box
300+

His website lists OSCP, CRTP, CRTE, CREST CRT and CPSA, CBBH, and CKA.

At SolarWinds, he delivered 120+ internal pentests. As CTO at Pwned Labs, he built a platform serving 40,000+ practitioners. He co-developed Mobexler, selected for Black Hat Arsenal, and presented research at Nullcon and c0c0n.

Explore his career timeline

FAQ

Questions before you book.

Can you assess containers too?

Kubernetes and Docker security can be included in the scope, along with the cloud identities, network paths and workloads they depend on.

Is cloud security the cloud provider’s responsibility?

Responsibility is shared. The provider secures parts of the underlying infrastructure; your responsibilities depend on the service you use and include how you configure access and protect your data. We scope the review around the services in your environment.

Can you review an environment without moving it?

Yes. Our team can assess an existing environment and recommend changes within it. Migration is a separate decision, not a prerequisite for a security review.

All cybersecurity services

What do you need to get moving?

Tell us what your team needs to resolve, which systems are involved, and any deadline. We will work through the scope and reporting needs with you.