Independent cloud security audit

Your cloud is probably fine.
Probably is the problem.

We read your AWS, Azure, GCP and Kubernetes estate the way somebody attacking it would, write down what we found and how we proved it, and stay on it until it is fixed. Every finding comes with the evidence, the fix and an honest estimate of what the fix costs you.

10 days
Scope to report
312
Controls per account
0
Findings without evidence
REPORT · SAMPLE
36 findings · 5 accounts
2Critical
7High
13Medium
9Low
5Informational
SBX-IAM-004Critical

The deployment role can assume every other role in the account

arn:aws:iam::4471xxxx9002:role/ci-deploy
SBX-NET-011Critical

A production database answers on the public internet

rds:eu-west-2:orders-primary · sg-0a91xxxx4e
SBX-DAT-002High

Seven months of application logs are stored unencrypted and never expire

s3://acme-app-logs-prod

Worked examples, written against invented accounts. Client findings never leave the client.

What we do

Four pieces of work, and the last one is the reason for the first three

An audit that ends at a report has moved nothing. The whole engagement is built around the fixes actually landing, which is why the retest is included rather than sold separately.

How an audit runs

Six steps, and four of them are yours to check

Nothing here happens without you seeing it first: you create the access, you set the window, you get the findings as we confirm them rather than in one delivery at the end.

01Scope

A 45-minute call and a list of accounts. We tell you what we would look at, what it costs and what we would need — before anything is signed.

02Access

A read-only role you create, scoped to the audit, with an external id and an expiry. You can revoke it in one click and we will notice within the hour.

03Collect

Automated collection across every account and region, including the ones nobody mentioned on the call. This part is machine work and it takes about a day.

04Verify

The part that takes the time. Every candidate finding is reproduced by hand, and anything we cannot reproduce is dropped rather than downgraded.

05Report

Findings with evidence and fixes, a prioritised backlog your team can work straight from, and a two-page summary written for the person who signs things.

06Retest

Included, not an upsell. We come back to each closed finding and prove it is closed, and the report gets a second dated column.

What you actually get

This is a finding. All of it.

Not a summary of one. Every finding in a Safebox2 report is written out like this, because a finding without its evidence is an opinion and a finding without its fix is somebody else's problem.

SBX-IAM-004Critical

The deployment role can assume every other role in the account

arn:aws:iam::4471xxxx9002:role/ci-deploy
Evidence
Its inline policy allows sts:AssumeRole on Resource: "*". From a build container we assumed the database administration role and read a credential out of Secrets Manager. 14:22 UTC, day two.
Impact
Anyone who can open a pull request can reach production data. That includes contractors, and it includes anyone who steals a laptop belonging to someone who can.
Fix
Scope the trust policy to the four roles the pipeline actually assumes, and add a condition on the repository and branch. The pipeline needs no other change.
Effort
Under an hour, plus a pipeline run to confirm
CIS AWS 1.16ISO 27001 A.5.15SOC 2 CC6.3

Worked examples, written against invented accounts. Client findings never leave the client.

Every finding carries
  • A reference stable enough to quote back at us in a year.
  • A severity against a scale we publish, so you can argue with it.
  • The resource as your own console names it, never paraphrased.
  • The request, the response and the timestamp.
  • The impact in a sentence your board can read.
  • The specific change, with the policy written out.
  • Honest engineering hours, including the awkward ones.
Severity, defined

A rating you can hold us to

Most reports rate findings against a scale nobody publishes, which makes every rating unarguable and therefore worthless. Here is ours. If you think something is rated wrong, this is the page you get to point at.

Critical

Exploitable now, from outside, with no credential we had to be given. We call you before the report.

High

Exploitable by anyone who already has a foothold — a supplier, a contractor, a stolen laptop.

Medium

Needs a second thing to go wrong first, and the second thing is plausible.

Low

Real, worth fixing, and nobody is getting in through it this quarter.

Informational

Not a weakness. Something about the estate you should know before the next change.

SPREAD · FIRST AUDIT36 findings
2Critical
7High
13Medium
9Low
5Informational

A typical first audit of a mid-sized estate. Two things that need a phone call, seven that need a sprint, and a long tail that needs a quarter.

Medians across anonymised engagements. Nothing on this site identifies a client, an estate or an account.

Why identity comes first

Nobody breaks in any more. They sign in and keep going

Almost every cloud incident worth the name is a chain of permissions that somebody granted deliberately, one hop at a time. That chain does not appear in a vulnerability report, a compliance questionnaire or a dashboard — you have to follow it.

IAM · Identity and accessNET · Network and exposureDAT · Data and encryptionLOG · Logging and detectionSUP · Supply chain and workloadsWRK · Configuration and drift
SBX-IAM-004 · REACHCritical
ci-deployROLES3 · artefactsSecrets ManagerRDS · ordersKMS · data keyECR · registryCloudWatch

Worked examples, written against invented accounts. Client findings never leave the client.

Measurable risk reduction

The only number that matters is the second one

An audit produces a score. What the engagement is judged on is where that score is ninety days later, so we publish the curve, including the part where it stops falling.

WEIGHTED RISK · 90 DAYS25240
0100200300DAY 0142842567090

A typical 90-day window on our own scale, illustrative rather than any one client’s. The flat part is the point: what is left after a month needs a change window, not an afternoon.

84%Weighted risk removed

Median across the first 90 days

100%Criticals closed

Within 14 days, every engagement so far

3 of 4Fixes made by your team

We pair on the fourth

Compliance

We will tell you what a technical audit cannot cover

A framework is mostly policies, people and suppliers. We evidence the estate, and we are specific about the controls that are yours to prove some other way — one square each, so the remainder is countable rather than rounded off.

ISO 27001:2022
Evidenced31 / 34

The international standard for an information security management system. Annex A carries 93 controls; a cloud audit speaks directly to the technological ones.

SOC 2 Type II
Evidenced24 / 29

The report North American customers ask for. Trust Services Criteria, tested over a window rather than on one day.

PCI DSS v4.0
Evidenced41 / 52

Required if you touch card data. Prescriptive, technical, and unforgiving about scope — most of the work is proving what is out of it.

Where we stop

Four things we will not do

Every one of these costs us work we could otherwise have taken. That is what makes them worth printing.

We do not test anything without written authorisation.

From somebody who can actually give it, naming the accounts and the window. If your provider needs notice, we get it. No exceptions, including for the demo.

We do not sell the tools we recommend.

We take no commission, no referral fee and no partner margin from any vendor. If the honest answer is that you already own something that does the job, that is the answer.

We do not hand over a scanner export with a logo on it.

Tooling gives us candidates. If a human here did not reproduce it, it does not go in the report — which is why our finding counts are lower than the tools’ and why they are all real.

We do not rate everything Critical.

A report where nothing is Low is a report nobody finishes, and a practice that cries wolf gets ignored on the day it matters. Our scale is published so you can hold us to it.

Next step

Tell us what you are running, and what is worrying you about it.

You will get a straight read on whether an audit is worth doing right now, what it would cover, and what it would cost — before anything is signed and without anybody being sold to.