Your situation

Cloud security assessment: reviewing configuration and processes

You use Azure, AWS, Google Cloud or Microsoft 365 and are unsure whether you are making full use of the security options? In the cloud security assessment, we review your configuration and the agreed processes for using the cloud.

Reviewing processes for cloud use and technical configurations – with suitable CIS Benchmarks and remediation recommendations.

Free of charge and without obligation.

  • Cloud testing methods published in iX
  • BSI-certified for IS penetration testing
  • CISSP qualification in the cloud testing team
Top view of joint map work with notes, compasses and navigation instruments
Cloud security assessment: keeping the whole environment in view, not just individual services.

Your situation

You have moved services to the cloud and are wondering whether configuration and processes are really secure?

More and more organisations use hybrid or pure cloud architectures in Microsoft Azure, Amazon Web Services (AWS) or Google Cloud Platform (GCP) to shift effort away from conventional IT operations. For services such as Microsoft Office or Atlassian Confluence, the move to the cloud is often not even wanted, but unavoidable.

The cloud simplifies operation and scaling, but it does not relieve you of administration and security. Cloud environments must be configured and used just as securely as on-premises structures. Complex structures, many available components and dependencies between functions make this more difficult. The question is: are you making full use of the security options of your environment?

In the cloud security assessment (CSA), we audit your cloud use from a process and a technical perspective – for cloud environments, Kubernetes and container environments as well as SaaS services such as Microsoft 365, Google Workspace, Zoom or Atlassian Cloud. The technical review is based primarily on the CIS Benchmarks. You receive specific remediation recommendations.

You offer cloud services yourself and need evidence according to the BSI criteria catalogue? Then our C5 consulting is the right fit. We test applications in the cloud in a penetration test.

Services & results

Five project steps: from kick-off meeting to results report

You find out where you are not yet making full use of your cloud’s security options – in Microsoft Azure, AWS, Google Cloud, Microsoft 365 and Kubernetes and container environments. The basis is workshops on your processes using a questionnaire drawn from best practices and standards, and a technical review of the configuration of the agreed environments.

The cloud security assessment is divided into kick-off meeting, organisational assessment, technical review, clarification of inconsistencies and results report. You can also commission the organisational and technical parts separately; for pure cloud services such as Microsoft 365, the organisational part is omitted.

Kick-off meeting: clarifying the environment and existing security

At the start, we clarify which cloud environment or cloud service is to be reviewed and which security steps you have already implemented. This forms the basis for deciding which tests make sense. We plan the next steps together.

Organisational cloud security assessment

In the first part of the review, our assessors work with you in workshops to establish the current state of your processes for cloud use. The basis is a questionnaire drawn from best practices, information security standards and our project experience. Topics include, for example:

  • Network security
  • Protection against malware and attack detection

Technical cloud security assessment according to CIS Benchmarks

In the second part of the review, we examine the technical configuration of your environment and identify missing, incomplete or insecure settings. As best practice, we primarily use the CIS Benchmarks – the industry standard for hardening measures, available for the common cloud environments and services as well as for Kubernetes. We include Kubernetes and container environments in the review.

With pure SaaS services such as Microsoft 365, Google Workspace, Zoom or Atlassian Cloud, you have less influence on the IT processes. Here, we carry out a purely technical review using the same approach.

Clarifying inconsistencies

Before we write the report, we clarify with the people responsible on your side any points that do not emerge clearly from the workshop and technical review.

Results report with recommendations

The report documents the vulnerabilities identified in the use or configuration of your cloud environment.

Your CSA report

Findings on processes and configuration with remediation recommendations to better protect your processes and data.

Our expertise

We have been offering the cloud security assessment since 2023 as part of our portfolio of technical security tests. secuvera is a BSI-certified IT security service provider for penetration testing and has been carrying out pentests since 2000.

Our colleague Viktor Rechel described how large cloud environments can be checked for misconfigurations and security risks efficiently, reproducibly and at scale using specialised tools in the iX special “Security Tools” 2025.

To combine process and technical reviews, our assessors know not only the technical tools but also standards such as ISO/IEC 27001 and IT-Grundschutz. The questionnaire for the organisational assessment combines both with our project experience.

Getting started

Narrowing down the cloud environment and the modules needed

Describe the environment and existing security

Describe the cloud environment or cloud service you use and the security measures you have already chosen. On this basis, we discuss which tests make sense and what access is needed.

Agree on suitable modules

You can commission the organisational or the technical assessment separately. We select the modules according to your environment and your specific questions.

Agree on your cloud assessment
Dividers and compass on a historical world map
Assessment modules tailored precisely to your cloud landscape.

Your cloud configuration is the subject of the review

The agreed environments, services and configurations are reviewed. The assessment is not a C5 attestation and no assurance of complete cloud security.

Questions about the cloud security assessment

Which cloud environments can be assessed?

The service covers common environments such as Azure, AWS and Google Cloud, Kubernetes and container environments, and SaaS services such as Microsoft 365, Google Workspace, Zoom or Atlassian Cloud. At the start, we clarify the specific services in use and the settings you can influence. The review criteria, access and modules depend on this.

What is the difference between an organisational and a technical cloud assessment?

The organisational module looks at processes for using the cloud in workshops with the people responsible on your side. The technical review examines configurations for missing, incomplete or insecure settings, in particular using suitable CIS Benchmarks.

Can we have only our Microsoft 365 configuration reviewed?

Yes. For pure cloud services, the proposal describes a technical review of the settings you can influence. The organisational assessment is omitted. The approach and criteria are tailored to the specific service.

Do both modules of the cloud security assessment always have to be commissioned?

No. If required, only the organisational or only the technical part can be carried out. The choice depends on your environment and on whether you want to answer questions about responsibilities and processes or about configuration.

Do we receive a C5 attestation from the assessment?

No. You receive an assessment of the cloud use or configuration reviewed and remediation recommendations for the findings. Preparing a cloud service for a C5 attestation is a different service; the attestation is issued by a public auditor.

Articles on this topic (in German)

All 3 articles on the topic (in German)

How can we support you with a cloud security assessment?