Cloud Security Audit

Find out what is actually wrong with your AWS account.

A cloud security audit is an independent review of how your cloud environment is configured, measured against a recognised standard. We examine identity, network, encryption, logging and firewall posture across your AWS accounts, then hand you a report that says what is broken, how serious each item is, and what to fix first. HAZERCLOUD is an AWS Advanced Tier Services Partner and is itself ISO 27001:2022 certified.

Audit scopeREAD ONLY

Evidence-based, not opinion-based.

  • IAM and access. Policies, roles, keys, MFA, privilege escalation paths.
  • Network exposure. Security groups, NACLs, public resources, TLS.
  • Encryption. At rest and in transit, including backups and KMS key policy.
  • Logging and detection. CloudTrail, flow logs, GuardDuty, Security Hub.
  • Firewall rules. Rule sets that accumulated without an owner.
  • Email and DNS. SPF, DKIM, DMARC, dangling records, certificates.
What The Audit Covers

Six areas where cloud environments actually fail.

Breaches rarely come from exotic attacks. They come from an over-permissive role, a security group someone opened for a demo, or logging that was never switched on. These are the six areas we work through, and the order reflects where real findings cluster.

01 · IDENTITY

Identity and access control

IAM users, roles and policies reviewed for least privilege. Wildcard permissions, unused credentials, missing MFA, long-lived access keys, over-broad cross-account trust, and root account usage. This is where the highest-severity findings almost always are, which is why we start here rather than at the network edge.

IAMAccess AnalyzerSCPsMFA
02 · NETWORK

Network exposure

VPC layout, subnet placement, security groups and NACLs. What is reachable from the internet and whether it should be: public buckets, internet-facing databases, management ports open to the world, and load balancer TLS configuration. We map the attack surface from the outside in, the way an attacker would enumerate it.

VPCSecurity GroupsNACLsALB / TLS
03 · ENCRYPTION

Encryption and key management

Encryption at rest across EBS, RDS, S3 and snapshots, and encryption in transit at every hop. KMS key policies, rotation, and who can actually decrypt what. Unencrypted backups are a common finding: the primary volume is protected while the snapshot sitting beside it is not.

KMSEBS / RDSS3Snapshots
04 · LOGGING

Logging and detection

CloudTrail coverage across regions and accounts, log retention and tamper resistance, VPC flow logs, GuardDuty and Security Hub enablement, and whether anyone is actually alerted when something fires. Logs nobody reads are not detection, and an alert with no owner is not a control.

CloudTrailGuardDutySecurity HubFlow Logs
05 · FIREWALL

Firewall and perimeter rules

Security group and NACL rule review, AWS WAF configuration where it exists, and rule sets that have accumulated over years. A firewall security audit is mostly the disciplined removal of rules that no longer have an owner or a reason, which is unglamorous and consistently valuable.

AWS WAFRule reviewEgress control
06 · EMAIL & DNS

Email and DNS posture

SPF, DKIM and DMARC records, Route 53 configuration, dangling DNS entries that invite subdomain takeover, and certificate expiry. An email security audit belongs here because domain spoofing does not require any access to your cloud account at all, and it is routinely the cheapest gap to close.

SPF / DKIMDMARCRoute 53ACM
Methodology

Measured against a standard, not a hunch.

An audit only means something if it measures you against something external. We assess against two reference points at once, so the output is useful to your engineers and to your auditor without being rewritten for either.

Reference point one

ISO 27001 control areas

  • Access control. Findings mapped to the controls an assessor will ask about.
  • Cryptography. Key management and encryption posture, documented.
  • Operations security. Change, patching and logging practice.
  • Communications security. Network segregation and transfer protection.
  • We hold it ourselves. HAZERCLOUD is ISO 27001:2022 certified, so we build to a standard we are audited against.
Reference point two

AWS Well-Architected Security pillar

  • Identity foundations. Root, federation, and permission boundaries.
  • Detective controls. What is logged, what is alerted, who responds.
  • Infrastructure protection. Network and host-level defence in depth.
  • Data protection. Classification, encryption, and lifecycle.
  • Incident response. Whether you could actually investigate an incident.
The two views answer different questions. ISO 27001 tells your auditor whether a control exists; the Well-Architected Security pillar tells your engineers whether it works on AWS. Running both is what stops an audit becoming either a compliance paper exercise or a pile of scanner output. See ISO 27001 on AWS for the certification path, and DevSecOps for keeping the gaps closed once they are fixed.
How To Perform A Cloud Security Audit

The seven steps, in order.

If you want to run this yourself, this is the sequence we use. The order matters: inventory drives scope, and scope drives everything after it. Skipping straight to a scanner is the most common way an audit produces noise instead of decisions.

01 · INVENTORY

Inventory what exists

List every AWS account, region and running resource from the API, not from an org chart. Most teams find something here: a forgotten test account, an old region with live instances, a service nobody owns. You cannot audit what you have not enumerated.

02 · EVIDENCE

Turn on the evidence sources

CloudTrail in all regions, Config recording, VPC flow logs, GuardDuty, Security Hub, IAM Access Analyzer. If these are off, switch them on and let them collect. An audit against an account with no history sees the snapshot but not the behaviour.

03 · IDENTITY

Review identity first

Pull every IAM user, role, policy and access key. Look for wildcards, unused credentials, absent MFA, and any role that can escalate to administrator. Identity findings are usually the highest severity, so they come before the network work rather than after it.

04 · EXPOSURE

Map exposure from the outside in

Enumerate what is publicly reachable: open security groups, public buckets, internet-facing databases, exposed management ports, and DNS records pointing at resources that no longer exist. Compare that against what should be reachable. The gap is your attack surface.

05 · DATA

Check data protection

Confirm encryption at rest and in transit, then check the key policies behind it. Include backups and snapshots, which are routinely left unencrypted while the primary volume is fine. Verify retention and deletion actually happen rather than existing only in a policy document.

06 · SEVERITY

Rate findings by real severity

Score each finding by exploitability and blast radius, not by how alarming a scanner made it look. A public bucket of marketing images is not a public bucket of customer records. Without this step you hand the team a list they cannot prioritise, and nothing gets fixed.

07 · REMEDIATION

Write remediation someone can act on

Every finding needs an owner, a concrete fix and a position in the queue. Separate the configuration changes that ship this week from the work needing an architecture decision, so the team clears easy wins instead of stalling on hard ones. Then re-test to confirm the fix held.

The Deliverable

What you actually get back.

One report that works for three audiences without being rewritten: your engineers, your leadership, and your auditor.

FINDINGS

Rated by severity

Every issue scored by exploitability and blast radius, with the evidence behind it: the policy document, the rule, the log line. No unexplained scanner output, and no padding the count with informational noise to make the report look thorough.

PLAN

Prioritised remediation

An ordered plan separating configuration changes that can ship this week from work that needs an architecture decision. Each item names what to change and why it matters, so an engineer who was not in the audit can pick it up and act on it.

EVIDENCE

Artefacts for auditors

Findings mapped to ISO 27001 control areas and the Well-Architected Security pillar, with the remediation trail attached. This is what shortens a certification conversation, because the questions an auditor asks are already answered in writing.

After The Audit

Fixing what the audit found.

The audit is deliberately independent of the remediation and priced separately, so the findings stay honest. If you want us to do the work as well, these are the routes.

Configuration → hardened

DevSecOps and hardening

Closing the configuration findings and putting guardrails in the pipeline so the same issues do not come back: IAM baselines, infrastructure as code policy checks, image scanning, and secrets handling.

DevSecOps services
Weakness → proven risk

VAPT and penetration testing

Where the audit says a weakness exists, penetration testing proves whether it is genuinely exploitable. Useful when you need to show a board or a customer real risk rather than a theoretical one.

VAPT and penetration testing
Cloud → application layer

Application security assessment

This audit covers the cloud environment. If the risk lives in your own code, APIs or mobile apps, that is the application layer and it is assessed separately, including source code review.

Application security assessment
Point in time → continuous

Ongoing monitoring

An audit is a snapshot. If nobody is watching afterwards, drift starts the next day. CloudOps covers 24/7 monitoring, incident response and patching under SLA.

CloudOps and managed services
Common Questions

What buyers ask before a cloud security audit.

If your question is not here, ask it on the call. We would rather scope honestly than sell an audit you do not need.

How long does a cloud security audit take?+
Scope drives it, and the honest answer is that we cannot quote a duration before we know how many AWS accounts and workloads are in play. As a rough guide, a single-account environment with a handful of services is usually a one to two week exercise from kickoff to report. A multi-account organisation with shared services, several VPCs and a mix of legacy and current workloads takes longer, because most of the time goes into understanding what is actually deployed rather than into running tools. We agree the scope and the timeline in writing before we start.
What is the difference between a security audit, a penetration test, and VAPT?+
An audit reviews configuration and controls against a standard: is MFA enforced, is logging on and retained, are security groups tight, is data encrypted. It tells you where you do not meet the bar. A penetration test is adversarial: a tester actively tries to break in and proves which weaknesses are genuinely exploitable. VAPT combines a broad vulnerability assessment with that focused exploitation work. They answer different questions, and most teams need the audit first, because there is little value in paying someone to exploit a gap you could have closed by turning on a setting. Our penetration testing work lives on the VAPT page.
Do you audit Azure and Google Cloud environments too?+
AWS is where our depth is. We are an AWS Advanced Tier Services Partner and our certifications, tooling and delivery experience are concentrated there, so an AWS audit is the strongest thing we sell. We are also a Google Cloud partner and can review GCP environments. Azure is not our specialism, and we would rather tell you that than take the engagement and learn on your environment. If your estate is mostly Azure, ask us and we will say so plainly.
What does a cloud security audit cost?+
It depends on the number of accounts, the number of workloads, and whether you want the remediation work as well as the findings. We do not publish a single price because a one-account startup and a twenty-account group are not the same job. The starting point is a free 30 minute review where we look at your environment and scope the audit properly, after which you get a fixed-scope quote rather than an open-ended day rate. If the review suggests you do not need a full audit yet, we will say that too.
Will the audit disrupt our production environment?+
No. A security audit is a read-only exercise. We work from AWS-native evidence: IAM policy and access-analyzer output, Config rules, CloudTrail and VPC flow logs, Security Hub and GuardDuty findings, security group and NACL definitions, KMS and encryption settings. Nothing is exploited and nothing is changed. Active exploitation is penetration testing, which is a separate engagement with its own written authorisation and agreed test window.
Do you fix the problems you find, or only report them?+
Both, and they are priced separately so the audit stays independent. The report is written so your own engineers can act on it without us. If you would rather we did the work, remediation runs as a follow-on engagement: hardening and pipeline security through our DevSecOps practice, exploit validation through VAPT, and ongoing monitoring through CloudOps. Plenty of clients take the report, fix the top findings themselves, and bring us in only for the parts they do not want to own.
Can we use the audit report as evidence for ISO 27001 or SOC 2?+
It produces useful evidence, but it is not a certification and we are careful about that distinction. We are ISO 27001:2022 certified ourselves, and we map findings to the relevant control areas, so the report and the remediation trail give your auditor something concrete to look at. What it cannot do is certify you. An accredited certification body issues ISO 27001 certificates and a licensed CPA firm issues SOC 2 reports. We build and document the environment so that process goes smoothly.
Start with the review

30 minutes. We will tell you if you need the audit.

Bring your AWS environment and we will look at it with you. If the obvious gaps are things your team can close in a week, we will say so. If a full audit is warranted, you get a fixed scope and a fixed quote before anything starts.

AWS Advanced Tier Services Partner · ISO 27001:2022 · ISO 9001:2015

30 min Free Consultation →