DSE Cybersecurity · Technical security assessment

See how your cloud is actually configured — with evidence.

A point-in-time assessment of how your cloud accounts, administrative identities, network exposure, logging, and guardrails actually stand against the control outcomes your board, customers, and insurers ask about. We work from the evidence you can produce, rate the gaps by business impact, and hand you a sequenced plan a named owner can execute. Vendor-neutral by design.

For leaders who own cloud risk. Advisory and readiness work. Not a penetration test, not an audit, not a certification.

Named methodology

One method. Current state, then the road to fix it.

The Cloud Security Configuration Review Method follows DSE's bounded-evidence assessment method: a bounded evidence request, focused interviews, a business-context severity rating, and a roadmap with named owners. The lane-specific layer is a cloud control map covering account and tenancy structure, identity and privilege, network and exposure, logging and detection readiness, data protection, and backup and recovery posture.

01 · Scope

Scope and boundary

We agree the systems, environments, data types, review period, and exclusions in writing before any evidence is collected, with a stated reason for each exclusion.

02 · Evidence

Bounded evidence request

A defined request for client-provided exports, screenshots, screen shares, and documents. We do not request administrator credentials and we do not run automated scans.

03 · Interviews

Focused interviews

Short, targeted conversations with the people who own the controls, to test how the design actually operates rather than how a diagram says it should.

04 · Rating

Business-context severity

We rate each observed gap by likelihood and business impact, and record evidence strength alongside it. Severity is a business-context rating, not a vulnerability score, and the method is explained in the report.

05 · Findings

Evidence-linked findings

Each finding states what we observed, why it matters, the supporting evidence, the recommended action, and a named accountable owner.

06 · Roadmap

Roadmap with named owners

Immediate actions and a sequenced roadmap that balances risk reduction, dependencies, effort, and cost, with named owners and an executive readout for leadership.

Typical timebox: 3 to 5 weeks after kickoff and timely evidence access. Larger, multi-environment, or high-complexity engagements are scoped separately. Fees are scoped after the diagnostic and confirmed in writing before work begins.

Evidence reviewed

What we review, and what we do not touch.

We assess client-provided configuration exports, architecture diagrams, identity and access exports, network and firewall rule exports, logging and retention settings, and policy documents, supplemented by screen shares where a live view is faster than an export. We reconcile what the documents claim against what the exports show.

We do not request administrator credentials, we do not connect tooling to your environment, and we do not run automated scans. The review is manual and evidence-based, so it stays inside a boundary you can see and revoke.

Deliverables

Named artifacts. Not a slide deck.

01

Cloud control map

Your accounts, environments, and administrative boundaries mapped against the control outcomes in scope, with the evidence produced for each.

02

Configuration findings register

Every observed gap with the evidence, a business-context severity, an accountable owner, and a target date. The working document the engagement is built around.

03

Identity and privilege review

Administrative access, standing privilege, and break-glass paths reviewed against least-privilege intent, with the exposures that matter flagged for tightening.

04

Exposure and logging summary

Internet-facing exposure, network segmentation, and logging and detection readiness described in business terms, not raw tool output.

05

Target architecture sketch

A vendor-neutral description of the target-state design and its trade-offs, so a build decision is grounded in evidence rather than a marketing diagram.

06

Prioritized remediation roadmap

Immediate actions and a sequenced plan balancing risk reduction, dependencies, effort, and cost, with an executive readout.

Sample output

A scorecard leaders can act on.

Synthetic sample — not client data. It contains no client information and is not a finding about any organization.

The sample table scrolls horizontally on smaller screens. Keyboard users can focus the labeled table region and use horizontal navigation.

Synthetic cloud configuration scorecard excerpt — not client data
Control areaObserved evidenceSeverityRecommended move
Administrative identityPrivileged roles exist without a documented break-glass path or periodic access review.HighDefine break-glass, enforce review cadence, assign an identity owner.
Network exposureTwo management ports are reachable from the public internet outside the documented allow list.HighRestrict to known sources, confirm the allow list, record the exception owner.
Logging readinessControl-plane logging is enabled but retention is shorter than the stated evidence requirement.ModerateExtend retention to the requirement, confirm a named reviewer of the log evidence.

Final ratings depend on the environment, the evidence, and the agreed method. We do not convert findings into a purported certification score.

Frameworks referenced

Framework structure, no vendor claims.

We organize findings using NIST CSF 2.0 as the structure and reference CISA's Cross-Sector Cybersecurity Performance Goals as a supporting baseline. These frameworks shape how we describe outcomes; they do not make this a NIST or CISA audit, and we name no cloud provider as a capability claim.

How the work is delivered

Accountable delivery, disclosed clearly.

DSE delivers through documented in-house expertise and qualified specialists from our expert network, selected for the technologies and risks in scope. DSE remains accountable for scope, quality, integration, and outcomes. Where specialist or partner delivery is involved, we disclose that role clearly.

Accountable owner: DSE delivery leadership.

Clear boundaries

Evidence-based advice, not assurance.

This is a point-in-time assessment of the cloud accounts, identities, configuration evidence, and documentation in the agreed scope. It is not legal advice, not an audit, not a certification, and not an attestation. It does not guarantee compliance or any enforcement or examination outcome. It does not make your organization secure and does not prevent, detect, or reduce the likelihood of any security incident; it documents risk against a defined scope at a point in time. DSE does not operate a 24/7 security operations center, does not provide continuous monitoring or managed detection and response, does not perform live incident response or digital forensics and incident response (DFIR), does not run penetration tests, and does not resell licenses. Where you need any of those, we help you scope the requirement and select a provider you contract directly. Remediation implementation is performed only where it is separately scoped in writing. Counsel, auditors, and assessors retain their respective roles.