Damocles cloud security

Find the cloud identity and configuration paths that expose more than you intended.

Damocles Cloud Security Review compares deployed cloud reality with the intended architecture and operating model, then prioritises the identity, exposure and resilience changes that reduce the greatest blast radius.

Identity and privilegeNetwork and public exposureData and workload securityLogging, backup and resilience
The customer problem

Cloud risk accumulates across identities, services and accounts even when each individual setting appears reasonable.

A service role with broad permissions, a public endpoint, a shared data store, weak administrative separation and missing audit logs can combine into an attack path that no single configuration check explains.

The review follows identity, network and data paths across the authorised cloud scope, compares them with the intended design and separates immediate risk reduction from structural improvements that require architecture or operating-model change.

01

Reduce privilege paths

Identify users, roles, service identities, trust relationships and permissions that create unnecessary reach.

02

Close accidental exposure

Find public services, permissive network paths, shared data and management interfaces that are broader than intended.

03

Improve detection and recovery

Identify missing logs, alerting, backup, key-management and resilience controls needed to investigate and recover.

Service coverage

Review the controls that define cloud blast radius and recovery capability.

The scope can cover a landing zone, one workload, selected accounts or subscriptions, or a broader cloud operating model.

ID

Identity and access

Users, groups, roles, service identities, federation, privileged access, cross-account trust and administrative separation.

NW

Network and exposure

Public services, private connectivity, security groups, routing, segmentation, management paths and service endpoints.

DS

Data and storage

Public access, sharing, encryption, key use, retention, backups and sensitive-data handling.

WL

Workloads and managed services

Compute, containers, serverless functions, databases, queues, managed services and security-relevant defaults.

LG

Logging and detection

Audit logs, security events, retention, centralisation, alerting, source health and investigation readiness.

RS

Resilience and recovery

Backup, immutability, recovery paths, regional dependencies, administrative recovery and operational continuity.

Technical assurance

Validate the controls protecting your cloud environment.

Review cloud identities, configuration, networking, data services and operational controls to expose excessive access, unintended exposure and weak recovery or monitoring paths.

Identity and privilege

Roles, policies, federation and administrative access.

Network exposure

Public services, trust boundaries and private connectivity.

Data protection

Storage access, encryption and sensitive-data exposure.

Workload security

Compute, container and serverless configuration.

Secrets and keys

Credential storage, key lifecycle and service access.

Logging and monitoring

Coverage, retention and visibility of material events.

Resilience and recovery

Backups, recovery controls and critical dependencies.

Governance guardrails

Configuration baselines, exceptions and change controls.

14governed test areas
4authorised testing perspectives
6controlled evidence outputs
2framework / control evidence mappings
What we actually test

Representative technical coverage with the evidence produced.

These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.

Jump to full coverage matrix ↓
Coverage area

Identity and privileged access

Damocles enumerates principals, roles, policies, trust relationships and privileged assignments and traces representative administrative paths.

Evidence producedEvidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to identity and privileged access.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Public exposure

Damocles identifies public endpoints, addresses and resource policies and corroborates approved exposure from an external position.

Evidence producedEvidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to public exposure.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Network controls

Damocles reviews virtual networks, security groups, network policy, routing and private-service boundaries against intended flows.

Evidence producedEvidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to network controls.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Storage configuration

Damocles examines storage resource access, public settings, encryption, retention and representative identity permissions.

Evidence producedEvidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to storage configuration.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Key and secret management

Damocles reviews key and secret stores, access policy, rotation metadata, workload retrieval paths and administrative custody.

Evidence producedEvidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to key and secret management.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Logging

Damocles reconciles required cloud log sources with enabled destinations, retention and representative event availability.

Evidence producedSource-health state, event timestamps, investigation timeline and linked action or escalation record.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Showing 6 representative areas. The full governed matrix contains 14 coverage areas.

Standards and assurance coverage

See how this engagement is structured, classified and mapped before opening the full evidence matrix.

References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.

01 · Test method

How testing is structured

Testing is structured by the governed service profile and the procedures expressly included in the authorised scope.

02 · Finding language

How weaknesses and severity are classified

Findings are reported against the governed service coverage and customer impact. Separate classification references are shown only where they are part of the approved profile.

03 · Control evidence

What maps into compliance and assurance work

2governed evidence mappings across 2 approved frameworks, with framework-level context where exact controls are not claimed.
2 contextual
ISO/IEC 27001 2022 with Amendment 1:2024Contextual
Framework-level context

The scoped technical behaviour relevant to cloud security review.

ISO/IEC 27002 2022Contextual
Framework-level context

The scoped technical behaviour relevant to cloud security review.

Jump to full control mapping ↓
04 · Evidence package

What the customer can use after the engagement

A prioritised cloud review with configuration evidence, affected resources, remediation guidance and validation outcomes.

  • Authorised scope and rules of engagement
  • Coverage matrix
  • Retest and residual-risk record
  • + 3 additional controlled outputs

What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.

How we test

Manual validation backed by controlled evidence.

Damocles uses a read-only cloud role and platform exports to trace identity, exposure, data and administrative paths, with bounded external checks where authorised. Configuration evidence is point-in-time and is not a complete cloud compliance assessment; write actions and resilience tests require separate approval.

How to read the mapping

Evidence is mapped to the part of a control we can actually assess.

Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.

All relevant frameworks
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Information Security Manual June 2026ISO/IEC 27001 2022 with Amendment 1:2024ISO/IEC 27002 2022Prudential Standard CPS 234 Information Security effective 1 July 2019Prudential Practice Guide CPG 234 Information Security published June 2019
Testing perspectives4 authorised viewpoints and access models

Read-only cloud configuration reviewer

Enumerates in-scope accounts, resources and policies through a read-only platform role and configuration exports.

Included when
Used for identity, network, storage, key, logging and workload configuration review.
Access required
Read-only role, account or subscription inventory, regions and excluded resources.
Limitations
Point-in-time configuration does not prove continuous operation or complete compliance.

Identity and privilege-path reviewer

Traces role assignments, policies, trust relationships and administrative paths to sensitive cloud resources.

Included when
Used where cloud identity escalation or excessive privilege is in scope.
Access required
Identity inventory, policy documents, role trust and representative principal context.
Limitations
Does not validate every principal, session or conditional policy unless represented.

External exposure validator

Confirms approved public endpoints, storage exposure and network reachability from outside the cloud boundary.

Included when
Used to corroborate public-exposure configuration with live observations.
Access required
Approved hostnames, addresses, resources and test windows.
Limitations
Does not authorise exploitation or testing of provider-managed infrastructure.

Workload or service owner where evidence is required

Explains ownership, operational intent and remediation dependencies for sampled workloads and services.

Included when
Used when configuration cannot be interpreted without service context.
Access required
Named owners, intended data classification, availability needs and operational procedures.
Limitations
Owner statements are supporting context, not proof that technical controls operate.
Exact test coverage and evidence14 governed coverage areas
What Damocles tests, the evidence produced and the scope boundary for each controlled coverage area.
Coverage areaWhat Damocles testsPerspective and accessEvidence producedReferences and limits
Identity and privileged accessDamocles enumerates principals, roles, policies, trust relationships and privileged assignments and traces representative administrative paths.Identity and privilege-path reviewer
Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for identity and privileged access.
Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to identity and privileged access.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Identity and privileged access when the platform resource and responsibility are included in the read-only review.

Limit: The conclusion is limited to the sampled identity and privileged access; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope.

Public exposureDamocles identifies public endpoints, addresses and resource policies and corroborates approved exposure from an external position.Read-only cloud configuration reviewer
Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for public exposure.
Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to public exposure.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Public exposure when the platform resource and responsibility are included in the read-only review.

Limit: The conclusion is limited to the sampled public exposure; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope.

Network controlsDamocles reviews virtual networks, security groups, network policy, routing and private-service boundaries against intended flows.Read-only cloud configuration reviewer
Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for network controls.
Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to network controls.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Network controls when the platform resource and responsibility are included in the read-only review.

Limit: The conclusion is limited to the sampled network controls; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope.

Storage configurationDamocles examines storage resource access, public settings, encryption, retention and representative identity permissions.Workload or service owner where evidence is required
Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for storage configuration.
Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to storage configuration.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Storage configuration when the platform resource and responsibility are included in the read-only review.

Limit: The conclusion is limited to the sampled storage configuration; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope.

Key and secret managementDamocles reviews key and secret stores, access policy, rotation metadata, workload retrieval paths and administrative custody.Workload or service owner where evidence is required
Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for key and secret management.
Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to key and secret management.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Key and secret management when the platform resource and responsibility are included in the read-only review.

Limit: The conclusion is limited to the sampled key and secret management; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope.

LoggingDamocles reconciles required cloud log sources with enabled destinations, retention and representative event availability.Workload or service owner where evidence is required
Log-source inventory, representative event identifiers, workflow records and responsible contacts.
Source-health state, event timestamps, investigation timeline and linked action or escalation record.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when the relevant telemetry and analyst or customer workflow can be observed during the review window.

Limit: Absent or delayed telemetry prevents a detection conclusion, and observation of one event cannot prove continuous detection of all attacks.

Monitoring and alertingDamocles reviews alert rules, coverage, destinations and operational ownership for selected cloud security events.Read-only cloud configuration reviewer
Log-source inventory, representative event identifiers, workflow records and responsible contacts.
Source-health state, event timestamps, investigation timeline and linked action or escalation record.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when the relevant telemetry and analyst or customer workflow can be observed during the review window.

Limit: Absent or delayed telemetry prevents a detection conclusion, and observation of one event cannot prove continuous detection of all attacks.

Workload configurationDamocles examines representative workload identity, image or runtime settings, exposed interfaces, update controls and service configuration.Workload or service owner where evidence is required
Current configuration export or read-only access, diagrams, owners and representative validation endpoints.
Configuration excerpts, object or rule identifiers and observed validation results; the record names the tested workload configuration object, path or control and its observed result.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review.

Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised.

Data protectionDamocles traces classified data through selected storage, processing, transfer and deletion controls using configuration and owner evidence.Read-only cloud configuration reviewer
Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for data protection.
Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to data protection.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Data protection when the platform resource and responsibility are included in the read-only review.

Limit: The conclusion is limited to the sampled data protection; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope.

Resilience and recoveryDamocles reviews backup, replication, recovery settings and documented exercises without claiming live recovery unless observed.Read-only cloud configuration reviewer
Architecture, dependency list, monitoring view, authorised failover window and rollback owner.
A timestamped failover observation showing state, convergence, service checks, monitoring and recovery or rollback.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed only when a customer-approved recovery or failover scenario, observer and rollback window are available.

Limit: The result covers the exercised failure mode; activity stops at the rollback threshold and does not predict every compound failure.

Administrative pathsDamocles traces console, API, automation and emergency administrative paths to sensitive accounts and resources.Read-only cloud configuration reviewer
Named source and destination test points, expected flow matrix and a safe test window.
Source-to-destination results linked to rule, route or boundary evidence.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing.

Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity.

Ownership and operational responsibilitiesDamocles maps sampled resources and controls to named service owners, platform responsibilities and remediation dependencies.Workload or service owner where evidence is required
Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for ownership and operational responsibilities.
Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to ownership and operational responsibilities.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Ownership and operational responsibilities when the platform resource and responsibility are included in the read-only review.

Limit: The conclusion is limited to the sampled ownership and operational responsibilities; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope.

Platform-specific applicabilityDamocles records account, subscription or project, region, service and shared-responsibility constraints for every sampled conclusion.Read-only cloud configuration reviewer
Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for platform-specific applicability.
Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to platform-specific applicability.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Platform-specific applicability when the platform resource and responsibility are included in the read-only review.

Limit: The conclusion is limited to the sampled platform-specific applicability; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope.

Configuration review versus cloud complianceDamocles distinguishes point-in-time configuration findings from broader governance, operational effectiveness and cloud compliance.Workload or service owner where evidence is required
Current configuration export or read-only access, diagrams, owners and representative validation endpoints.
Configuration excerpts, object or rule identifiers and observed validation results; the record names the tested configuration review versus cloud compliance object, path or control and its observed result.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review.

Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised.

Framework and control mappings2 governed evidence mappings
Where scoped technical evidence maps to approved security frameworks and control objectives.
Framework and controlsMapping typeWhat Damocles assessesEvidence producedApplicability and limits
ISO/IEC 27001 2022 with Amendment 1:2024
Framework-level context
ContextualThe scoped technical behaviour relevant to cloud security review.Scoped observations and coverage status that a qualified assessor may consider.

Applies: Only when the customer confirms that the framework and environment are applicable.

Limit: Exact identifiers and licensed text are withheld; this is not certification or a complete framework assessment.

ISO/IEC 27002 2022
Framework-level context
ContextualThe scoped technical behaviour relevant to cloud security review.Scoped observations and coverage status that a qualified assessor may consider.

Applies: Only when the customer confirms that the framework and environment are applicable.

Limit: Exact identifiers and licensed text are withheld; this is not certification or a complete framework assessment.

Assurance boundary: Damocles maps assessed coverage and observations to agreed objectives as traceable technical evidence. The review is not a certification, does not establish complete compliance, and does not confirm controls outside the authorised scope.

Report and evidence outputs6 controlled output types

Authorised scope and rules of engagement

Records authorised scope and rules of engagement produced from the authorised Cloud security review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Coverage matrix

Records coverage matrix produced from the authorised Cloud security review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Retest and residual-risk record

Records retest and residual-risk record produced from the authorised Cloud security review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Cloud identity and exposure map

Records cloud identity and exposure map produced from the authorised Cloud security review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Cloud configuration evidence

Records cloud configuration evidence produced from the authorised Cloud security review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Ownership and remediation matrix

Records ownership and remediation matrix produced from the authorised Cloud security review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.
What you receive

A prioritised cloud review with configuration evidence, affected resources, remediation guidance and validation outcomes.

Common engagement options

Choose the review boundary that matches the cloud decision being made.

The statement of work defines providers, accounts, subscriptions, projects, regions, workloads, evidence methods and whether engineering support is included.

Foundation
LZ

Landing-zone review

Assess identity, account structure, networking, logging, guardrails and administrative controls used by multiple workloads.

Workload
WR

Critical workload review

Assess one business service and its identities, data stores, network paths, secrets, logging and recovery dependencies.

Identity
IR

Cloud identity and privilege review

Focus on federation, privileged roles, service identities, cross-account trust and permission paths.

Exposure
EX

Internet exposure review

Identify public services, management paths, storage, APIs and network controls exposed beyond the intended design.

Resilience
DR

Logging, backup and recovery review

Assess evidence availability, alerting, retention, backup separation, restoration and response readiness.

Migration
MR

Pre-migration or post-migration review

Review the target design before cutover or validate the deployed environment after major cloud change.

Delivery lifecycle

Compare the intended cloud architecture with the configuration teams actually operate.

Read-only access, configuration exports, architecture evidence and customer interviews are selected according to the provider and authorised scope.

01

Define the business services

Confirm critical workloads, data sensitivity, identities, providers and the intended operating model.

02

Collect authorised evidence

Gather configuration, identity, network, logging, data and workload evidence using approved methods.

03

Trace privilege and exposure

Follow identity, data and network paths that could expand attacker reach or operational impact.

04

Validate control gaps

Confirm material misconfiguration, design weakness and missing detection or recovery capability.

05

Prioritise the changes

Separate immediate quick wins from structural identity, network and operating-model improvements.

06

Review remediation

Support architecture decisions and review changed configuration where included.

What you receive

A cloud remediation roadmap tied to the services and dependencies the business actually uses.

The review should make identity and exposure paths visible to technical teams while giving leaders a clear view of material risk and required investment.

ES

Executive risk summary

Material cloud exposure, affected business services, likely impact and the decisions requiring attention.

AM

Architecture and trust-path map

Identity, network, data and administrative relationships that define blast radius.

CF

Configuration findings

Affected services, evidence, risk, conditions and specific remediation guidance.

QW

Quick-win plan

High-value changes that can reduce exposure without major redesign.

SR

Structural roadmap

Longer-term identity, landing-zone, logging, recovery and governance improvements.

RW

Remediation workshop

A technical review with cloud, security and platform owners to agree the implementation path.

What we need from the customer

The review needs clear cloud ownership, representative evidence and access to the people who understand the workload design.

The customer provides the authorised account or subscription scope, read-only access or exports, architecture diagrams, workload owners, identity and federation context, critical data and service information, and any known incidents or audit concerns.

Where evidence is incomplete, Damocles records the limitation and avoids presenting an unsupported conclusion. Production changes are not made unless separately authorised as engineering work with change control and rollback.

What happens after delivery

The Cloud Security Review engagement continues until the customer understands the work, the owners and the remaining risk.

The report or service record is the beginning of remediation, not the end of the engagement. These steps keep the outcome usable after formal delivery.

01

Confirm the material issues

Damocles walks the customer through the findings, evidence, affected scope, dependencies and uncertainty so there is agreement on what requires action.

02

Assign ownership

Each material recommendation is allocated to the team that can implement it, with a clear expected outcome and realistic dependency on other changes.

03

Sequence remediation

Quick risk reduction, structural change, compensating controls and longer-term engineering are separated so the customer can plan the work sensibly.

04

Capture implementation evidence

Configuration records, change references, screenshots, test results, source state or other agreed evidence are retained for later review.

05

Verify the result

Where included, Damocles reviews the changed state, performs a retest or reassessment, and records whether the original exposure is resolved, reduced or still present.

06

Record residual risk

Issues that cannot be fully removed remain visible with the accepted limitation, compensating control, review date and decision owner.

Commercial structure and change control

How a Cloud Security Review engagement is scoped and kept commercially clear.

The proposal identifies the authorised scope, delivery method, assumptions, customer inputs, working window, deliverables, briefing, remediation support and any included retest or follow-up. Fixed-scope engagements are priced against that agreed boundary; retainers and managed services use the recurring quantity and service model stated in the schedule.

When the environment, target count, repositories, locations, access, service coverage or required evidence changes materially, Damocles records the impact before continuing. The customer can approve a variation, reduce the scope, defer the additional work or create a separate engagement. Hidden scope expansion is avoided because it produces poor testing and unreliable delivery dates.

Third-party licences, specialist platforms, travel, after-hours work, emergency response, remediation engineering and work outside the agreed deliverables are included only when listed in the proposal. Existing customer technologies can be used where they are supported and suitable; Damocles does not require a particular vendor simply to deliver the service.

Continuing the work in Guardian

Cloud findings can continue as an owned remediation program rather than a one-time architecture report.

Guardian can retain each material finding, affected service, owner, due date, remediation plan, evidence and closure review alongside other customer risks and actions.

This allows cloud, security and leadership teams to distinguish immediate exposure from longer-term architecture work and report progress using the same operational record.

Questions buyers ask before engagement

Practical questions about Cloud Security Review.

The final answer depends on the customer environment and scope, but these are the points that should be resolved before work begins.

Q1

How long will it take?

Timing depends on scope, access, environment stability, customer availability and the review depth required. The proposal states the expected delivery window and the assumptions that can change it.

Q2

Can the scope change after work starts?

Yes, but the change is recorded. Damocles explains the coverage, timing and commercial impact before additional work is performed.

Q3

Will Damocles work with our existing team or provider?

Yes. Internal teams, developers, cloud partners, infrastructure providers and MSPs can participate where responsibilities, access and communication paths are clear.

Q4

How are findings prioritised?

Priority considers practical exploitability or failure likelihood, exposure, affected business capability, data, privilege, dependency, available compensating controls and remediation effort.

Q5

Is remediation included?

Remediation guidance and handover are included as stated in the proposal. Implementation, managed change, emergency work and extensive engineering are separate unless expressly included.

Q6

How is closure verified?

Closure uses the method suitable for the issue: retesting, rescanning, code or configuration review, operational evidence, restored source health, tabletop follow-up or another agreed validation method.

Scope, assumptions and boundaries

The review reflects the authorised cloud scope and evidence available at the time.

Source-code review, penetration testing, SaaS-provider internals, non-cloud network infrastructure, production implementation and continuous cloud monitoring are included only where separately scoped.

The review does not imply cloud certification, universal service coverage or guaranteed regional availability, data residency, recovery time or detection performance.

Take the next practical step

Review the cloud workload, landing zone or identity model before exposure becomes harder to unwind.

Tell us the providers, account structure, critical workloads, data sensitivity and current concern. We will define the evidence, access and review depth required.