Services

Cloud Security for Microsoft 365, Azure, AWS and Google Workspace

The cloud shifts responsibility, it does not remove it. We review your tenant against the benchmarks that matter, fix the identity and sharing settings that cause real breaches, and show you what you already pay for but have not enabled.

PLATFORMS
Microsoft 365, Azure, AWS, Google Workspace
BENCHMARKS
CIS Foundations, Microsoft Secure Score
FOCUS
Identity, Sharing, Logging, Backup
OUTPUT
Prioritised Hardening Plan
In short

Is data in Microsoft 365 or AWS automatically secure?

No. Cloud providers secure the underlying platform, but you remain responsible for your own configuration, identities, access controls and data — the shared responsibility model. Most cloud breaches are caused by customer misconfiguration, not by a provider failure.

The shared responsibility model, in plain terms

Microsoft, Amazon and Google secure the buildings, hardware, hypervisors and core platform. You are responsible for everything you configure on top: who has accounts, what those accounts can reach, what is shared externally, whether MFA is enforced, and whether your data is backed up somewhere the platform cannot lose it.

That division is where most incidents happen. The provider almost never fails. The customer configuration frequently does — a storage bucket set to public, a guest account from a finished project still holding access, a global administrator with no MFA because it is "a service account".

Microsoft 365: where SME risk concentrates

For most UK small businesses, the Microsoft 365 tenant is now the crown jewels — it holds the email, the documents, the customer data and the identities that unlock everything else. It is also where business email compromise happens, and that is the single most common serious incident we deal with.

The fixes are well understood and mostly free with licences you already hold: enforce MFA for every user including administrators, block legacy authentication protocols that bypass MFA entirely, restrict who can create mailbox forwarding rules to external addresses, limit anonymous sharing links, and turn on the audit logging that makes an investigation possible.

  • MFA enforced on all accounts, including break-glass administrators
  • Legacy authentication protocols blocked outright
  • Conditional access policies for location, device and risk
  • External auto-forwarding restricted and alerted on
  • Anonymous and organisation-wide sharing links reviewed and constrained
  • Unified audit logging enabled with adequate retention
  • Third-party backup, since native retention will not survive a malicious deletion

Azure, AWS and Google Cloud reviews

Where clients run infrastructure rather than just office software, we review against the CIS Foundations Benchmark for the relevant platform. The recurring findings are consistent across every platform: over-permissive identity and access management roles, storage exposed more broadly than intended, security groups open to the whole internet, absent or unretained audit logging, and unencrypted data at rest.

Where infrastructure is defined in Terraform or CloudFormation we review the code as well as the deployed state, because fixing the console without fixing the template means the misconfiguration returns at the next deployment.

  • IAM roles and policies reviewed for least privilege and unused permissions
  • Storage buckets and volumes checked for public exposure and encryption
  • Network security groups and firewall rules reviewed for over-broad access
  • Audit logging, retention and alerting verified as investigable
  • Infrastructure-as-code templates reviewed alongside deployed state
  • Kubernetes RBAC and pod security where containers are in use

Cloud data is not backed up by default

This surprises people, so it is worth stating directly: Microsoft 365 retention policies and recycle bins are not a backup. They protect against accidental deletion for a limited window. They do not protect against a malicious administrator, a compromised account systematically purging mailboxes, or a ransomware event that syncs encrypted files up to SharePoint.

Microsoft says as much in its own service agreement, which places responsibility for data backup on the customer. A third-party backup for your cloud tenant is inexpensive and is one of the first things we recommend.

What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Agreement Ready

Master Services Agreement (MSA)

The umbrella commercial agreement: scope, fees, IP, liability, confidentiality and termination. Work is ordered under Statements of Work.

UK Electronic Communications Act 2000 · eIDAS (EU) No 910/2014 · SHA-256 Verified

Request This Agreement →
Frequently asked questions

Cloud Security — your questions answered

Does Microsoft back up our Microsoft 365 data?
Not in the way most businesses assume. Microsoft provides limited retention and recycle-bin recovery, and its service agreement places responsibility for data backup on the customer. A separate third-party backup is needed to survive malicious deletion or a ransomware event.
How long does a cloud security review take?
A Microsoft 365 tenant review for a typical SME takes two to three days including the report. A combined review of a cloud tenant plus Azure or AWS infrastructure is scoped individually, generally around a week.
What is the single most important cloud security control?
Multi-factor authentication on every account, with legacy authentication protocols blocked so it cannot be bypassed. It prevents the large majority of account compromises, and in most licences it costs nothing extra to enable.
We use Google Workspace rather than Microsoft. Can you help?
Yes. We review Google Workspace against equivalent baselines — two-step verification coverage, admin role scoping, external sharing controls, third-party app access, audit log retention and Drive data exposure.
Do you fix what you find, or only report it?
Either. Many clients want the report and hand it to their IT provider. Others ask us to implement the hardening directly. We quote both options so you can choose.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about cloud security?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.