Cloud Security Health Check: the 5 things to check first
Most cloud breaches do not come from exotic zero-days — they come from a handful of boring misconfigurations. If you only have an afternoon, start here. This is the same order we work in when we assess multi-cloud environments.
1. Identity & access (IAM) — check this first
Over-privileged identities are the number-one cause of cloud breaches. Look for:
- Human users and roles with
*:*or broad admin policies - Long-lived access keys — especially any older than 90 days, or unused
- Missing MFA on privileged and root/owner accounts
- Over-broad cross-account trust and third-party integration roles
2. Data exposure & storage
Find where your crown-jewel data lives, then confirm it isn't reachable:
- Public S3 buckets / GCS buckets and any public ACLs or bucket policies
- Unencrypted stores and volumes; snapshots shared beyond the account
- Databases exposed to the internet instead of private subnets
3. Network exposure
- Security groups / firewall rules open to
0.0.0.0/0 - Management ports (SSH 22, RDP 3389) exposed to the public internet
- Unnecessary public endpoints and missing segmentation between workloads
4. Logging & monitoring
If you were breached tonight, could you reconstruct it tomorrow?
- CloudTrail / Cloud Audit Logs enabled across every account and region
- Logs retained long enough, and protected from tampering or deletion
- Alerting on high-risk events (root use, policy changes, key creation)
5. Configuration & posture drift
- Baseline every account against the CIS Benchmark for your provider
- Catch drift across accounts, projects, subscriptions, and tenants
- Tie each finding to the frameworks you answer to — SOC 2, HIPAA, PCI-DSS, ISO 27001
A note on honesty
A health check finds and prioritizes real exposure. It is not a certification or a promise you will never be breached — closing the findings is what changes your risk.
Want this done for you — across every account?
A Cloud Security Health Check is a read-only assessment across all five domains, delivered as a prioritized report mapped to your frameworks. No agents, no production risk.
Request a health check




