Cloud Security

03 - Cloud Security

Cloud Security

Secure cloud environments across Azure, AWS and Google Cloud. RTCS provides cloud security consulting and assessment for Australian organisations using Azure, AWS, Google Cloud and Microsoft 365. We identify cloud misconfigurations, exposed services, excessive permissions, weak identity controls, insecure storage, logging gaps and governance issues - with practical risk reduction, clear reporting and actionable remediation.

  • Azure, AWS and Google Cloud security reviews
  • Microsoft 365 and Entra ID security reviews
  • Cloud identity, access and privileged role review
  • Public exposure and internet-facing service assessment
  • Storage, database and secret management review
  • Logging, monitoring and SIEM integration review
  • Cloud governance and configuration baseline review
  • Cloud penetration testing where in scope
  • Remediation guidance, retesting and security roadmap
Discuss This Service
Platforms
Microsoft Azure - AWS - Google Cloud - Microsoft 365 - Entra ID
Review Areas
Identity - access - networking - storage - logging - governance - public exposure - secrets
Engagement Types
Configuration review - identity review - exposure assessment - cloud pentest - roadmap
Outputs
Risk-rated findings - evidence - remediation roadmap - executive summary - optional retest
Essential Eight CIS Benchmarks ISO 27001 NIST CSF
3
Hyperscalers Covered
M365
Entra ID & Tenant Review
10+
Control Domains Assessed
AU
Onshore Delivery
01 / Context

Cloud platforms move faster than security catches up.

Cloud platforms give organisations flexibility and scale, but they also introduce risk when identity, access, networking, storage, logging and configuration controls are not managed properly. RTCS helps Australian organisations identify and reduce that risk across the platforms they actually use.

02 / Why It Matters

Cloud environments change in minutes. Risk follows.

New resources can be deployed in minutes. Permissions expand over time. Storage can be exposed accidentally. Security groups become too permissive. Logs may not be enabled. Admin accounts may not be protected properly. These issues can create serious risk where cloud services support customer data, production applications, backups, identity services or sensitive workloads.

A cloud security review answers the questions that matter

Q1

Are cloud services exposed to the internet unnecessarily?

Q2

Are admin accounts protected with strong identity controls?

Q3

Are users, groups and service accounts over-permissioned?

Q4

Is sensitive data stored securely?

Q5

Are storage accounts, buckets and databases publicly exposed?

Q6

Are security logs enabled and monitored?

Q7

Are cloud workloads segmented properly?

Q8

Are secrets, keys and credentials protected?

Q9

Are cloud risks visible to security and leadership teams?

03 / Platform Reviews

Deep reviews of the platforms you actually run.

RTCS reviews the configuration, identity and exposure surfaces of each major hyperscaler and Microsoft 365. Each review is scoped to your environment and focused on practical risk.

Azure Security Review

Azure role assignments, Entra ID integration, network security groups, storage accounts, Key Vault access, exposed VMs, Defender for Cloud, diagnostic logging, subscription governance and Azure Policy alignment.

AWS Security Review

IAM users, groups and roles, public S3 exposure, security groups, EC2 access, CloudTrail and CloudWatch, KMS and secrets, RDS exposure, Lambda permissions, GuardDuty, Security Hub and account structure.

Google Cloud Security Review

IAM roles and service accounts, project and organisation permissions, Cloud Storage exposure, VPC firewall rules, Compute Engine and Cloud SQL access, Secret Manager, Cloud Logging and Security Command Center.

Microsoft 365 & Entra ID

Conditional Access, MFA enforcement, privileged roles and PIM, legacy authentication, enterprise apps and consent, guest access, SharePoint and Teams sharing, mailbox controls, audit logging and security defaults.

04 / Identity & Access

Identity is the new perimeter.

Excessive permissions, unmanaged admin accounts and poorly controlled service accounts create the biggest single risk in modern cloud. RTCS assesses cloud identity and access controls to identify where privileges are too broad or poorly governed.

  • Administrative accounts
  • Role assignments
  • Service accounts & service principals
  • Privileged access workflows
  • MFA coverage
  • Conditional Access controls
  • Break-glass accounts
  • Guest access
  • Permission inheritance
  • Stale or unused access
05 / Exposure

Public exposure assessment.

Cloud systems are often exposed through public IP addresses, open management ports, public storage, permissive firewall rules or internet-facing databases. RTCS identifies cloud assets that are exposed and assesses whether that exposure is expected, necessary and secure.

Public IP addresses Exposed virtual machines Open management ports Public storage services Internet-facing databases Kubernetes & container services Public load balancers Misconfigured firewall rules Unrestricted inbound access External attack surface
06 / Governance & Logging

Governance & Logging

Configuration & Governance

Cloud account and subscription structure, resource ownership, tagging and asset visibility, security baselines, policy enforcement, change control, deployment practices, monitoring responsibilities, compliance reporting and risk acceptance processes.

Logging & Monitoring

Identity sign-in logs, admin activity logs, cloud audit logs, storage access logs, network flow logs, security alerts, SIEM integration, log retention, alert coverage and incident response visibility.

07 / What We Assess

A control surface that covers the whole environment.

Identity & access management Privileged access MFA & Conditional Access Public exposure Network security controls Storage & database security Key & secret management Logging & monitoring Cloud workload protection Security baseline alignment Cloud governance Third-party access Service account permissions Cloud policy enforcement Backup & recovery controls Incident response readiness
08 / Review vs Pentest

Review vs Pentest

Cloud Security Review

Assesses configuration, identity, exposure, governance and control effectiveness across the cloud environment. Best for identifying broad control gaps and prioritising remediation.

Cloud Penetration Testing

Goes deeper into specific attack paths and validates whether weaknesses can be exploited. Best for proving real-world impact on high-value workloads or pre-production environments.

Both are useful. A cloud security review tells you where the gaps are. Cloud penetration testing tells you which gaps an attacker would actually use.

Scope to Support

A practical, staged engagement that identifies cloud risk, prioritises real impact, and supports your team through remediation.

01
Scope

Confirm cloud platforms, accounts, subscriptions, projects, workloads, users, exclusions and access requirements.

02
Discover

Review cloud assets, identities, permissions, exposed services, storage, logging, networking and security controls.

03
Assess

Identify misconfigurations, excessive access, exposed services, weak controls and governance gaps.

04
Prioritise

Risk-rate findings based on exposure, exploitability, business impact and affected data or systems.

05
Report

Provide a clear report with findings, evidence, affected resources and remediation guidance.

06
Support

Where required, support remediation planning, retesting and cloud security roadmap development.

09 / When & Who

When & Who

When to Conduct a Review

  • After moving workloads to Azure, AWS or GCP
  • Before launching a cloud-hosted application
  • After major cloud architecture changes
  • To review Microsoft 365 and Entra ID controls
  • To assess public exposure and misconfiguration
  • To support audit or compliance requirements
  • After a security incident or near miss
  • Before onboarding enterprise customers
  • As part of annual security assurance

Who This Service Is For

  • Use Azure, AWS, Google Cloud or Microsoft 365
  • Store sensitive data in cloud platforms
  • Need to review identity and access controls
  • Have internet-facing cloud workloads
  • Need independent cloud security assurance
  • Want to reduce misconfiguration risk
  • Need to improve logging and monitoring
  • Need to assess cloud governance
  • Want a clear remediation roadmap

Cloud security requires visibility, strong identity controls, secure configuration and ongoing governance. Talk to us about a cloud security assessment, Microsoft 365 review, Entra ID review, cloud exposure assessment or cloud penetration test.

Common Questions

What is a cloud security assessment?

A cloud security assessment reviews cloud platforms, workloads, identities, permissions, networking, storage, logging and governance to identify security risks and misconfigurations.

Which cloud platforms do you assess?

RTCS can assess Azure, AWS, Google Cloud, Microsoft 365 and Entra ID environments.

Do you assess Microsoft 365 security?

Yes. RTCS reviews Microsoft 365 and Entra ID controls, including MFA, Conditional Access, privileged roles, app consent, guest access, SharePoint, Teams, email security and audit logging.

Do you test for public cloud exposure?

Yes. RTCS reviews public exposure across cloud workloads, storage, databases, management ports, firewall rules and internet-facing services.

Can you help with cloud remediation?

Yes. RTCS provides remediation guidance and can support your team with prioritised actions, retesting and cloud security roadmap development.

Do you provide a report?

Yes. RTCS provides a clear report with findings, evidence, risk ratings, affected resources and remediation guidance.

Available across Australia.

RTCS delivers cloud security reviews for Australian businesses, including Microsoft 365, Azure, AWS and Google Cloud environments. See cyber security services across Australia for national delivery context.