Security Audit
A fixed-price, fixed-scope audit of your environment, cloud or on-prem. You get a prioritized findings report you can act on immediately.
Every audit covers the fundamentals attackers actually use: who can access what, what’s exposed to the network, whether you’d notice a breach, and where your data can leak. Whether cloud-native (AWS, Azure, GCP), on-prem, or hybrid, the checklist adapts to the environment. The rigor doesn’t change.
What the findings report looks like
Here's a representative slice of a report, ranked worst-first. Every finding follows the same shape: what we saw, why it matters, the fix, and the effort to do it.
Customer data reachable from the public internet
An S3 bucket holding exported customer records has Block Public Access disabled and a policy that grants read to everyone. Anyone who finds the bucket name can download it, and with no access logging you can't tell whether someone already has.
Fix: turn on account-level Block Public Access, remove the public grant, enable access logging, and sweep for other exposed buckets. Effort: ~2 hours, plus rotating anything that was exposed.
You wouldn't see a breach in progress
CloudTrail runs in one region only, threat detection is off, and no alert reaches a human. An attacker working in an unlogged region leaves no trail, and even logged activity is nobody's job to catch.
Fix: enable multi-region CloudTrail to a locked-down bucket, turn on GuardDuty, and route findings somewhere a person actually reads. Effort: ~half a day.
Loaded guns that haven't fired yet
Fourteen security groups allow inbound from anywhere on ports the instances currently keep closed, and three IAM roles hold full-admin permissions they have never used. No active exposure today, but each one turns the next small mistake into a big one.
Fix: scope the security groups to known sources and right-size the roles to their real usage. Effort: ~half a day.
That ranking is the point: you get a prioritized list, not a scanner dump. Fix the top of it and you've closed the real risk.
What you get
- ✓Prioritized findings report (what's wrong, why it matters, in what order to fix it)
- ✓Attack-surface inventory of the audited environment
- ✓Remediation plan and live readout call (Standard tier)
Pricing
Baseline
$2,500
One environment: a single cloud account, subscription, or project, or one on-prem site (up to 25 systems).
- ✓Identity & access review
- ✓Network exposure & segmentation review
- ✓Logging & detection coverage review
- ✓Prioritized findings report
Standard
$5,000
Up to three environments: cloud accounts, subscriptions, projects, or on-prem sites (up to 25 systems each), audited as one footprint.
- ✓Everything in Baseline, across every in-scope environment
- ✓Data storage & backup exposure review
- ✓Written remediation plan with effort estimates
- ✓Live readout call with your team
Add-on: Vulnerability Assessment +$1,000
Authenticated vulnerability scanning of everything in scope, external attack surface and internal systems, mapped to known CVEs and dangerous defaults. Findings fold into the same prioritized report. Choose it at kickoff; billed alongside your audit.
Payment is handled securely by Stripe. By booking you agree to the engagement terms. Not sure which tier fits? Ask us.
FAQ
- How long does it take?
- Baseline is typically delivered within one week of kickoff; Standard within two.
- What access do you need?
- Read-only credentials scoped at the kickoff call. For on-prem Baseline audits we do a short scoping call first to confirm remote access is workable.
- Is this a penetration test?
- No. It is a configuration and architecture audit. It finds the misconfigurations and exposures attackers look for, without active exploitation. Add the vulnerability assessment if you also want scanning for known CVEs and unpatched services; for full exploitation testing we can refer a pentest partner.
- How big can an on-prem site be?
- Fixed-price tiers cover sites up to roughly 25 servers and network devices. Bigger, or not sure how to count? The pre-audit scoping call sorts it out, and larger sites get a custom quote that reflects the real work.
- What if we have more than three environments?
- That needs custom scope so the report stays thorough instead of thin. Book an intro call or email us and we'll quote it properly.
- What if I have questions before buying?
- Book an intro call or email us, and we'll respond within one business day.