Skip to main content
Loyca
Service reference 15Testing & AssessmentACTIVE PRACTICE PROTOCOL

Cloud Security Assessment

Misconfiguration is the new vulnerability

Configuration review of AWS, Azure, or GCP against benchmarks, with an emphasis on identity and exposure.

PROTOCOL OVERVIEW

Executive Context & Technical Scope

Cloud breaches are rarely exploits; they are permissions. We review your accounts against CIS benchmarks and the provider's own guidance, then go further: over-privileged roles, cross-account trust, public storage, unencrypted data at rest, and the gaps in logging that would leave you unable to reconstruct an incident.

TARGET PROFILES

Who Requires This Protocol

Teams that grew into cloud without a landing zone
Organisations preparing for cloud-scoped compliance
Anyone who has ever found a public bucket

ENGAGEMENT ARTIFACTS

Verifiable Outputs & Deliverables

CIS benchmark assessment per account or subscription

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

IAM privilege analysis and least-privilege recommendations

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

Public exposure and encryption review

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

Logging and detection coverage gap analysis

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

PRACTITIONER FAQ

Frequently Asked Scoping Questions

Do you need admin access?
Read-only security auditor roles are sufficient for assessment. We provide the exact policy documents to create.
Can this be continuous?
Yes — we can implement policy-as-code checks in your pipeline so drift is caught when it is introduced rather than at the next review.
PRACTICE CONTINUUM

INTELLIGENCE WITHOUT LIMITS

Scope Cloud Security Assessment for your organization.

Get a fixed-scope proposal, verifiable deliverables list, and exact timeline for cloud security assessment.

Direct Hotline:+254 740 658 068
NO-OBLIGATION GUARANTEE

What to expect in your scoping call

  • Direct Senior Lead

    You talk to a seasoned cybersecurity consultant, never a sales script.

  • Strict Confidentiality

    We operate under mutual NDA before discussing sensitive architecture.

  • Actionable Next Steps

    Immediate priorities and costed options, whether you engage us or not.

Message Loyca on WhatsApp