Skip to content

What you walk away with

A sample findings report

Cloud Security Health Check

Prioritized Findings Report

Northwind Financial, Inc.

Illustrative company — sample data only

SAMPLE
Report
CHS-SAMPLE-0000
Scope
AWS · Azure · Google Cloud
Prepared by
Kief Studio × JDR Security Solutions

Executive summary

Posture is recoverable, but two critical exposures put customer data and the management plane one credential away from compromise. Both are closable in days.

2 Critical
3 High
3 Medium
1 Low
9 Findings

Top risks to close first

  • A public storage bucket exposes exported customer records to any authenticated principal.
  • The AWS management-account root has no MFA — a single credential is full-account takeover.
  • Audit logging is disabled in 2 of 14 accounts, leaving blind spots with no reconstructable trail.

Scope & method

AWS14 accounts (AWS Organizations)
Azure3 subscriptions
Google Cloud2 projects

Read-only assessment across identity, data, network, logging, and configuration. No agents installed; nothing written to production.

Domain scorecard

Identity & access Needs attention Root MFA gap + an over-privileged CI role.
Data security Critical Public bucket + unencrypted shared snapshots.
Network exposure Moderate Exposed management port + broad security groups.
Logging & monitoring Gap Audit logging off in two accounts; short retention.
Configuration & posture Moderate New resources inherit an insecure baseline.
Framework mapping Evidenced Every finding tied to CIS, SOC 2, PCI-DSS, and more.

Findings register

IDSeverityDomainFindingCloud
F-01CriticalData securityPublic object storage exposes exported customer recordsAWS
F-02CriticalIdentity & accessManagement-account root has no MFAAWS
F-03HighNetwork exposureManagement port open to the internetAWS
F-04HighIdentity & accessOver-privileged CI role with a stale static keyAWS
F-05HighLogging & monitoringAudit logging disabled in two accountsAWS
F-06MediumConfiguration & postureNew resources inherit an insecure baselineAzure
F-07MediumData securityUnencrypted database snapshots shared cross-accountAWS
F-08MediumNetwork exposureOver-permissive firewall rulesGoogle Cloud
F-09LowLogging & monitoringAudit log retention below policyAWS

Selected findings in detail

Critical F-01 Data security · AWS

Public object storage exposes exported customer records

Risk: A storage bucket of exported records is readable by any authenticated principal. Once copied, the disclosure cannot be undone — this is a breach and a notification event.

Fix: Restrict the bucket to least-privilege principals and enforce account-wide public-access blocking. Confirm no data was accessed via access logs.

PCI-DSSSOC 2CCPA/CPRA
Critical F-02 Identity & access · AWS

Management-account root has no MFA

Risk: The organization root can do anything, and it is protected by a password alone. A single phished or leaked credential is full-account takeover.

Fix: Enable a hardware MFA device on root, vault the credentials, and alert on any root usage.

CIS BenchmarksSOC 2
High F-03 Network exposure · AWS

Management port open to the internet

Risk: RDP (3389) is open to 0.0.0.0/0 on a production host — directly brute-forceable administrative access from anywhere.

Fix: Restrict access to a bastion or just-in-time access and close the public rule.

CIS BenchmarksPCI-DSS
High F-04 Identity & access · AWS

Over-privileged CI role with a stale static key

Risk: A deploy role holds AdministratorAccess and a two-year-old access key — the single credential most likely to end up in a public repo or build log.

Fix: Scope the role to the exact deploy actions in use, move to short-lived OIDC tokens, and remove the static key.

CIS BenchmarksSOC 2
High F-05 Logging & monitoring · AWS

Audit logging disabled in two accounts

Risk: CloudTrail is off in 2 of 14 accounts — blind spots where an incident would leave no reconstructable trail.

Fix: Enable an organization-wide trail to a central, access-controlled, tamper-resistant sink.

CIS BenchmarksSOC 2NIST CSF

Remediation roadmap

Now — first 2 weeks

  • Enable root MFA and vault the credentials (F-02)
  • Close the public storage bucket and confirm no access (F-01)
  • Close the internet-facing management port (F-03)

Next — 2 to 6 weeks

  • Scope the CI role and rotate to short-lived tokens (F-04)
  • Enable organization-wide audit logging (F-05)
  • Set secure-by-default configuration policies (F-06)

Ongoing

  • Encrypt and scope database snapshots; set retention (F-07)
  • Tighten firewall rules and segment workloads (F-08)
  • Extend log retention and monitor for drift (F-09)

Frameworks evidenced

CIS BenchmarksNIST CSFSOC 2PCI-DSSHIPAAISO 27001CCPA/CPRA

This is a sample. Every company, finding, and value here is illustrative. A real health check identifies and prioritizes your actual exposure and maps it to your frameworks — it is an assessment, not a certification or a guarantee against breach.

Kief Studio JDR Security Solutions

Cloud Health Sec · By Kief Studio · in partnership with JDR Security Solutions

Want this for your own cloud?

A health check finds and prioritizes real exposure. It is not a certification or a promise you will never be breached — closing the findings is what changes your risk.

Take free readiness check