Skip to content

Guides

Cloud Security Health Check: the 5 things to check first

Most cloud breaches do not come from exotic zero-days — they come from a handful of boring misconfigurations. If you only have an afternoon, start here. This is the same order we work in when we assess multi-cloud environments.

1. Identity & access (IAM) — check this first

Over-privileged identities are the number-one cause of cloud breaches. Look for:

  • Human users and roles with *:* or broad admin policies
  • Long-lived access keys — especially any older than 90 days, or unused
  • Missing MFA on privileged and root/owner accounts
  • Over-broad cross-account trust and third-party integration roles

2. Data exposure & storage

Find where your crown-jewel data lives, then confirm it isn't reachable:

  • Public S3 buckets / GCS buckets and any public ACLs or bucket policies
  • Unencrypted stores and volumes; snapshots shared beyond the account
  • Databases exposed to the internet instead of private subnets

3. Network exposure

  • Security groups / firewall rules open to 0.0.0.0/0
  • Management ports (SSH 22, RDP 3389) exposed to the public internet
  • Unnecessary public endpoints and missing segmentation between workloads

4. Logging & monitoring

If you were breached tonight, could you reconstruct it tomorrow?

  • CloudTrail / Cloud Audit Logs enabled across every account and region
  • Logs retained long enough, and protected from tampering or deletion
  • Alerting on high-risk events (root use, policy changes, key creation)

5. Configuration & posture drift

  • Baseline every account against the CIS Benchmark for your provider
  • Catch drift across accounts, projects, subscriptions, and tenants
  • Tie each finding to the frameworks you answer to — SOC 2, HIPAA, PCI-DSS, ISO 27001

A note on honesty

A health check finds and prioritizes real exposure. It is not a certification or a promise you will never be breached — closing the findings is what changes your risk.

Want this done for you — across every account?

A Cloud Security Health Check is a read-only assessment across all five domains, delivered as a prioritized report mapped to your frameworks. No agents, no production risk.

Request a health check

Who prepares with checklists

Operators using prep guides

FinTech, healthcare, and CRE teams preparing for a health check.

Take free readiness check