Service
Scope

What we test, review, and assess.

Outcome of this engagement

Cloud Configuration Review helps your team asses whether your cloud environment is configured to resist real attacker techniques, not just satisfy a benchmark.

Identity & access
  • IAM roles, policies, service principals, and privileged access
  • PIM, break-glass accounts, federation, SSO, and conditional access
  • Permission paths to sensitive systems, data, or administrative control
Network & data exposure
  • Network segmentation, exposed services, and public access paths
  • Storage, databases, key vaults, secrets, and encryption configuration
  • Cross-account, cross-subscription, or cloud-connected exposure
Detection & operations
  • Logging, alerting, and SIEM coverage
  • Cloud workload protection and posture management
  • Backup, recovery, resilience, and operational control gaps
What You Receive

Cloud findings your team can act on.

  • Executive summary for non-technical stakeholders
  • Prioritized findings with business and security impact
  • Evidence-backed configuration and control findings
  • Identity and access risk observations
  • Data exposure and segmentation findings
  • Attack-path narrative where applicable
  • Practical remediation guidance for cloud and security teams
  • Benchmark alignment where useful
  • Risk context to guide prioritization
  • Findings review meeting
  • Retesting of remediated findings within the defined engagement window
  • Letter of Attestation, where applicable
Beyond THE REPORT

Cloud confidence should come from tested controls, not clean dashboards.

Methodology Preview

A transparent process from scope to retesting.

01
Define
02
Uncover
03
Report
04
Remediate
05
Retest
See Full Methodology
Why Canary Trap

Cloud review led by people who think like attackers.

Senior-led testing

Testing is led by experienced offensive security professionals, not handed off to junior scanner operators.

Attacker-aligned analysis

We focus on the cloud configurations attackers actually target, including identity, access, secrets, exposed services, storage, and privilege paths.

Control validation

Benchmarks can show what is misaligned. Canary Trap helps identify which gaps create practical exposure and what they could mean for the environment.

Practical reporting

Findings include the technical detail needed for remediation and the business context needed for leadership, compliance, and operational decisions.

Project management

Every engagement includes clear communication, defined expectations, and project management throughout the testing lifecycle.

Retesting and validation

Retesting helps confirm that remediated findings have actually been addressed, not just marked complete.

Trust signals

Canary Trap is SOC 2 Type II certified, maintains an NPS above 95, and specializes in offensive security testing.

Related Services

Cloud risk rarely stays confined to cloud.

M365 Security Controls Review
Internal Network Penetration Testing
Secure Code Review
FAQ

Cloud configuration review questions, answered plainly.

Next Step

Ready to scope your Cloud Configuration Review?

Book a Scoping Call