Cloud Security
AWS Security
Secure AWS architecture, least-privilege IAM, detection with GuardDuty and Security Hub, and posture management that keeps multi-account estates defensible as they grow.
Cloud Security
We design and harden Google Cloud environments: resource hierarchy and organisation policy, least-privilege IAM, VPC and network controls, Security Command Center and logging, Workload Identity, and GKE security — with remediation delivered in Terraform.
Google Cloud's resource hierarchy is one of its strongest security features and one of the most commonly wasted. Projects proliferate outside any folder structure, organisation policies stay at defaults, and basic roles such as Editor get granted because they are the fastest way to unblock someone.
Service account keys are a persistent weak point. Long-lived JSON keys end up in CI systems, laptops and repositories, and remain valid long after the person or pipeline that needed them is gone.
Security Command Center may be switched on, but findings, audit logs and GKE events are frequently unmonitored, with no defined owner and no routing into the systems the on-call engineer actually watches.
Google Cloud rewards teams that use its hierarchy properly. Organisation policy, folder-scoped IAM, VPC Service Controls and Workload Identity together remove whole categories of risk — but only if they are designed as one model rather than enabled piecemeal after an audit finding.
Adapted to your environment and constraints — but the shape of the work is consistent.
We review the organisation, folder and project structure and apply organisation policy constraints — restricting external IPs, blocking service account key creation, enforcing uniform bucket-level access, constraining domain-restricted sharing and allowed regions — so the default state is secure.
Replace basic roles with predefined and custom roles, use IAM Recommender and policy analysis to strip unused permissions, apply IAM conditions, and eliminate service account keys in favour of Workload Identity Federation and Workload Identity for GKE.
Shared VPC and subnet design, firewall rule review and tightening, Private Google Access and Private Service Connect, VPC Service Controls perimeters around sensitive data, and Cloud Armor at the edge.
Security Command Center configured and tuned, organisation-level audit log sinks to a restricted log bucket or BigQuery, log-based alerting for high-signal events, and integration with your SIEM and on-call rotation.
GKE hardening, Binary Authorization for trusted images, Artifact Registry controls and vulnerability scanning, CMEK where required, Secret Manager adoption, and Terraform modules plus policy-as-code checks so new projects inherit the baseline.
What changes as a result of the engagement.
Confirmed in the proposal before work starts, and adjusted to scope.
The specific capabilities available under this service. Engagements usually draw on a subset — we scope to the problem, not the catalogue.
Recognise your situation? A 30-minute discovery call is the fastest way to find out whether this is the right engagement.
Book a security consultationIncrementally. We inventory every key and its consumer, migrate workloads to Workload Identity Federation or GKE Workload Identity one consumer at a time, monitor for authentication failures, then disable key creation at the organisation policy level once the estate is clean.
For environments holding regulated or high-value data, usually yes — they are one of the few controls that meaningfully limits data exfiltration. They do need careful perimeter design and a dry-run period, which is exactly what we plan for rather than enabling them blind.
Yes. Our practice includes ongoing work securing cloud-native platforms on Google Cloud — SecOps, DevSecOps, compliance automation and incident response for a production AI-powered product platform.
These engagements are often scoped together — the underlying risks overlap.
Cloud Security
Secure AWS architecture, least-privilege IAM, detection with GuardDuty and Security Hub, and posture management that keeps multi-account estates defensible as they grow.
Cloud Security
Cluster hardening, workload isolation, admission control, image supply-chain integrity and runtime detection for EKS, GKE, AKS and self-managed Kubernetes.
DevSecOps & AppSec
Build security into the delivery pipeline instead of bolting it on at the end — secure SDLC, CI/CD hardening, IaC scanning, supply-chain controls and guardrails engineers will actually keep.
Tell us what you are trying to secure and where it hurts. We will tell you what we would do first, whether or not you engage us.