Cloud Security Assessment (CSA)
Your cloud environment tested by engineers who build cloud infrastructure themselves
Azure Certified experts. AWS & GCP. Hands-on cloud engineers.
Half of the Netherlands runs on Azure, but how many organizations truly know what's happening in their tenant? We audit cloud environments with the knowledge of engineers who have migrated enterprise workloads to the cloud for years. From lift-and-shift disasters to modern cloud-native architectures - we built it and we know where things go wrong.
Have Neo Security perform a cloud assessment? You get the certainty that your cloud setup actually works.
What is a cloud security assessment (CSA)?
A cloud security assessment (CSA) is a thorough check of your complete cloud environment. From IAM to network, from storage to compute resources. We don't just look at what's configured, but especially at what's actually happening in your environment. We test the security of your cloud environment in a practical way.
Where others print a report from a CSPM tool, we dive into the console. We manually test what automated tools miss.
We manually check what automated tools miss. For example: that service principal with too many rights, a storage account with "temporary" public ACL configuration, that 'one' legacy application with hardcoded credentials.
CSPM is a tool, not a solution. Why have a human look at the console?
The reality behind the dashboards and alerts your CSPM tool generates.
“With a perfect CSPM dashboard there are still gaps in security. Tools see configurations, we see workflows. We had an environment that was just set up. CIS benchmark scores were 100% according to the tool, everything was green in that dashboard. Until we saw the PowerApp flows with hardcoded credentials. Why missed? They were retrieved with Curl in PHP.”
Benjamin Korper
Founder & CEO
What is CSPM/CNAPP actually? A tool, not a solution.
Cloud Security Posture Management (CSPM) and Cloud Native Application Protection Platform (CNAPP) are tools that continuously scan your cloud configurations. Useful for the basics, but with many pitfalls:
- They miss context ("why is this set this way?")
- They generate false positives ("this should be open")
- They don't see design flaws ("this architecture is fundamentally insecure")
We use these tools for large environments to lay a foundation, never as an endpoint. Do you regularly get reports from a tool as manual CSA? Call us, we'll explain.
Why hands-on cloud assessment (CSA)?
Azure-specific pitfalls
- Management Groups chaos after organic growth
- Azure AD (Entra ID) with overly complex Conditional Access
- Network Security Groups that contradict each other
- Key Vault permissions that no one understands anymore
Multi-cloud complexity
More and more organizations run hybrid:
- Azure for Windows workloads
- AWS for modern applications
- GCP for data analytics
- On-premise legacy that needs to integrate
We understand this complexity because we set it up ourselves.
Our cloud assessment approach
Discovery - What do you actually have?
Subscription inventory
- •Which subscriptions/accounts exist?
- •Who pays for what? (detecting shadow IT)
- •Which resources run where?
- •Cost analysis - are you paying for forgotten resources?
Identity deep dive
- •Service principals and managed identities audit
- •Privileged identity Management review
- •MFA coverage and conditional access policies
- •Guest users and external collaboration
Configuration review - How is it set up?
Network architecture
- •VNet/VPC structure and peering
- •Network Security groups and firewall rules
- •Private endpoints and service endpoints
- •ExpressRoute/Direct connect settings
Data Security
- •Storage account settings
- •Database firewall settings
- •Encryption at rest and in transit
- •Backup and disaster recovery validation
Compliance check
- •Regulatory compliance (GDPR, NIS2)
- •Industry standards (ISO 27001, SOC2)
- •Azure policy/AWS config settings
- •Tagging strategy and enforcement
Hands-on testing
Privilege escalation paths
We test whether a developer can gain admin rights:
- •Via nested group memberships
- •Through resource permissions
- •Via automation accounts
- •Through CI/CD pipelines
Data exfiltration scenarios
Can data leave your organization without you knowing?
- •Storage account misconfigurations
- •Database export permissions
- •Unmonitored data movements
- •Shadow copies and backups
Lateral movement
Once inside, how far can we get?
- •Cross-subscription access
- •Managed identity abuse
- •Key vault secret sprawl
- •Network segmentation bypass
Practical roadmap - from finding to solution
Detailed roadmap with priorities, quick wins and long-term improvements. We focus on what truly poses risk.
“At a corporate we found 47 Global Administrators. After our assessment there were 3, with PIM for the rest. That saves not only in security, but also in sleep quality.”
Erik Homma
Senior Cloud Architect
What does it concretely deliver?
For the management team
Executive dashboard
- Risk heat map per business unit
- Compliance status overview
- Cost optimization opportunities
- Benchmark against industry peers
For the platform team
Technical playbook
- Terraform/Bicep templates for remediation
- PowerShell scripts for bulk changes
- Architecture patterns for redesign
- Monitoring queries for threat hunting
For Security Operations Centers
Detection package
- KQL queries for Azure Sentinel
- Custom alerts for risk patterns
- Incident response runbooks
- Threat hunting procedures
Cloud-native vs lift-and-shift reality check
“A client had lifted their complete on-premise environment 1-to-1 to Azure. Quite a lot of money on compute resources while the cluster was idle. Your tooling could have marked this as green.”
Arno Westerdijk
Senior IT Consultant
The typical Azure migration evolution:
We help you go directly to phase 4.
Specific focus areas for CSA
Azure active directory (Entra ID)
- •Conditional Access policies that actually work
- •Privileged Identity Management implementation
- •B2B collaboration security
- •Legacy auth protocol elimination
Container & kubernetes
- •AKS/EKS/GKE security standards
- •Container registry scanning
- •Network policies and service meshes
- •Pod security policies
DevOps & CI/CD pipelines
- •Azure DevOps/GitHub security
- •Pipeline privilege reviews
- •Secret management in CI/CD
- •Infrastructure as Code scanning (Terraform, Bicep, etc.)
Serverless & paaS resources
- •Function App security
- •API Management settings
- •Logic Apps/Step Functions review
- •Managed database security
Why Neo Security for cloud security assessment (CSA)?
We are builders first
Our consultants have designed and built complex cloud environments themselves.
Real insights
You already have CSPM tools. We translate the output to what really matters.
Pragmatic
Not everything needs to be perfect. We focus on what truly poses risk.
Available 24/7
Cloud incidents don't wait. One phone call and we dive into your environment.
The investment in cloud security
What does it cost NOT to do it?
- Data breach€3.5 million avg.
- Compliance fineUp to 4% revenue
- RansomwareWeeks downtime
- ReputationPriceless
What does a CSA deliver?
- Direct:Security quick wins and risks
- 3 months:Optimized architecture and risks
- 6 months:Lower cloud costs and risks
- 12 months:Mature cloud security posture and risks
Start today with cloud security assessment (CSA)
Your data is in the cloud. Do you know who can access it?
For acute cloud security questions:
+31 20 716 5487Cloud Security assessment (CSA) quickscan
Curious about your cloud's status? We offer a no-obligation CSA Quickscan:
- Automated scan of your Azure/AWS/GCP tenant
- Top 10 risk identification and solutions
- Cost indication for remediation and implementation
- No obligations
From subscription governance to Zero Trust architecture. We help improve and optimize your environment.