Skip to main content

Cloud Security Assessment (CSA)

Your cloud environment tested by engineers who build cloud infrastructure themselves

Azure Certified experts. AWS & GCP. Hands-on cloud engineers.

Half of the Netherlands runs on Azure, but how many organizations truly know what's happening in their tenant? We audit cloud environments with the knowledge of engineers who have migrated enterprise workloads to the cloud for years. From lift-and-shift disasters to modern cloud-native architectures - we built it and we know where things go wrong.

Have Neo Security perform a cloud assessment? You get the certainty that your cloud setup actually works.

What is a cloud security assessment (CSA)?

A cloud security assessment (CSA) is a thorough check of your complete cloud environment. From IAM to network, from storage to compute resources. We don't just look at what's configured, but especially at what's actually happening in your environment. We test the security of your cloud environment in a practical way.

Where others print a report from a CSPM tool, we dive into the console. We manually test what automated tools miss.

We manually check what automated tools miss. For example: that service principal with too many rights, a storage account with "temporary" public ACL configuration, that 'one' legacy application with hardcoded credentials.

CSPM is a tool, not a solution. Why have a human look at the console?

The reality behind the dashboards and alerts your CSPM tool generates.

With a perfect CSPM dashboard there are still gaps in security. Tools see configurations, we see workflows. We had an environment that was just set up. CIS benchmark scores were 100% according to the tool, everything was green in that dashboard. Until we saw the PowerApp flows with hardcoded credentials. Why missed? They were retrieved with Curl in PHP.

Benjamin Korper

Founder & CEO

What is CSPM/CNAPP actually? A tool, not a solution.

Cloud Security Posture Management (CSPM) and Cloud Native Application Protection Platform (CNAPP) are tools that continuously scan your cloud configurations. Useful for the basics, but with many pitfalls:

  • They miss context ("why is this set this way?")
  • They generate false positives ("this should be open")
  • They don't see design flaws ("this architecture is fundamentally insecure")

We use these tools for large environments to lay a foundation, never as an endpoint. Do you regularly get reports from a tool as manual CSA? Call us, we'll explain.

Why hands-on cloud assessment (CSA)?

Azure-specific pitfalls

  • Management Groups chaos after organic growth
  • Azure AD (Entra ID) with overly complex Conditional Access
  • Network Security Groups that contradict each other
  • Key Vault permissions that no one understands anymore

Multi-cloud complexity

More and more organizations run hybrid:

  • Azure for Windows workloads
  • AWS for modern applications
  • GCP for data analytics
  • On-premise legacy that needs to integrate

We understand this complexity because we set it up ourselves.

Our cloud assessment approach

Week 1

Discovery - What do you actually have?

Subscription inventory

  • Which subscriptions/accounts exist?
  • Who pays for what? (detecting shadow IT)
  • Which resources run where?
  • Cost analysis - are you paying for forgotten resources?

Identity deep dive

  • Service principals and managed identities audit
  • Privileged identity Management review
  • MFA coverage and conditional access policies
  • Guest users and external collaboration
Week 2

Configuration review - How is it set up?

Network architecture

  • VNet/VPC structure and peering
  • Network Security groups and firewall rules
  • Private endpoints and service endpoints
  • ExpressRoute/Direct connect settings

Data Security

  • Storage account settings
  • Database firewall settings
  • Encryption at rest and in transit
  • Backup and disaster recovery validation

Compliance check

  • Regulatory compliance (GDPR, NIS2)
  • Industry standards (ISO 27001, SOC2)
  • Azure policy/AWS config settings
  • Tagging strategy and enforcement
Week 3

Hands-on testing

Privilege escalation paths

We test whether a developer can gain admin rights:

  • Via nested group memberships
  • Through resource permissions
  • Via automation accounts
  • Through CI/CD pipelines

Data exfiltration scenarios

Can data leave your organization without you knowing?

  • Storage account misconfigurations
  • Database export permissions
  • Unmonitored data movements
  • Shadow copies and backups

Lateral movement

Once inside, how far can we get?

  • Cross-subscription access
  • Managed identity abuse
  • Key vault secret sprawl
  • Network segmentation bypass
Week 4

Practical roadmap - from finding to solution

Detailed roadmap with priorities, quick wins and long-term improvements. We focus on what truly poses risk.

At a corporate we found 47 Global Administrators. After our assessment there were 3, with PIM for the rest. That saves not only in security, but also in sleep quality.

Erik Homma

Senior Cloud Architect

What does it concretely deliver?

For the management team

Executive dashboard

  • Risk heat map per business unit
  • Compliance status overview
  • Cost optimization opportunities
  • Benchmark against industry peers

For the platform team

Technical playbook

  • Terraform/Bicep templates for remediation
  • PowerShell scripts for bulk changes
  • Architecture patterns for redesign
  • Monitoring queries for threat hunting

For Security Operations Centers

Detection package

  • KQL queries for Azure Sentinel
  • Custom alerts for risk patterns
  • Incident response runbooks
  • Threat hunting procedures

Cloud-native vs lift-and-shift reality check

A client had lifted their complete on-premise environment 1-to-1 to Azure. Quite a lot of money on compute resources while the cluster was idle. Your tooling could have marked this as green.

Arno Westerdijk

Senior IT Consultant

The typical Azure migration evolution:

1
Lift-and-shift migration- "It needs to work"
2
Cost shock- "Why is it so expensive?"
3
Security incident- "Who left this open?"
4
Modernization- "Let's do it right"

We help you go directly to phase 4.

Specific focus areas for CSA

Azure active directory (Entra ID)

  • Conditional Access policies that actually work
  • Privileged Identity Management implementation
  • B2B collaboration security
  • Legacy auth protocol elimination

Container & kubernetes

  • AKS/EKS/GKE security standards
  • Container registry scanning
  • Network policies and service meshes
  • Pod security policies

DevOps & CI/CD pipelines

  • Azure DevOps/GitHub security
  • Pipeline privilege reviews
  • Secret management in CI/CD
  • Infrastructure as Code scanning (Terraform, Bicep, etc.)

Serverless & paaS resources

  • Function App security
  • API Management settings
  • Logic Apps/Step Functions review
  • Managed database security

Why Neo Security for cloud security assessment (CSA)?

We are builders first

Our consultants have designed and built complex cloud environments themselves.

Real insights

You already have CSPM tools. We translate the output to what really matters.

Pragmatic

Not everything needs to be perfect. We focus on what truly poses risk.

Available 24/7

Cloud incidents don't wait. One phone call and we dive into your environment.

The investment in cloud security

What does it cost NOT to do it?

  • Data breach€3.5 million avg.
  • Compliance fineUp to 4% revenue
  • RansomwareWeeks downtime
  • ReputationPriceless

What does a CSA deliver?

  • Direct:Security quick wins and risks
  • 3 months:Optimized architecture and risks
  • 6 months:Lower cloud costs and risks
  • 12 months:Mature cloud security posture and risks

Start today with cloud security assessment (CSA)

Your data is in the cloud. Do you know who can access it?

For acute cloud security questions:

+31 20 716 5487

Cloud Security assessment (CSA) quickscan

Curious about your cloud's status? We offer a no-obligation CSA Quickscan:

  • Automated scan of your Azure/AWS/GCP tenant
  • Top 10 risk identification and solutions
  • Cost indication for remediation and implementation
  • No obligations

From subscription governance to Zero Trust architecture. We help improve and optimize your environment.