Nobody's tracking what's running in the cloud. Ten minutes to change that.
A free 28-question self-assessment for the people who look after cloud estates. It covers the ten working parts of cloud security, from identity and inventory to compliance evidence. It returns a maturity band with plain-English next steps, in about ten minutes. With it comes a working toolkit: registers, runbooks, baseline packs, and board-reporting packs. The assessment runs in your browser. Your answers never leave your device.
Two free ways to see if the toolkit fits.
1. Take the free assessment
28 questions across the ten working parts of cloud security — identity, inventory, workloads, infrastructure code, SaaS use, detection, incident response, vendors, multi-cloud governance, and compliance evidence. About ten minutes. You get a weighted score and a maturity band, from Minimum-viable practice to Platform-grade. Runs in your browser. No email required; nothing is sent anywhere.
Take the free assessment →2. Read the free guide
"Your First Cloud Security Fixes" walks through the five moves that pay off fastest — from the access-key audit to the one-page incident card. Plain English, and yours to keep.
Read the free guide →This is for the people who run a cloud estate.
It measures how your cloud is operated (identity, inventory, baselines, and compliance evidence) across one account or many. If you need a general small-business security baseline instead, see the SMB Security Assessment; if your focus is scanning, triage, and patching, that's Vulnerability Management.
Three tiers: one for a single owner, one for the first security hire, one for estates at scale.
- Cloud Account & Asset Register Starter Kit — the known-accounts list, the high-risk resource inventory, and the monthly bill-review habit
- Cloud Backup & Recovery Starter — what to back up, sensible settings, and the restore test that proves recovery works
- Cloud Identity First-Fixes Runbook — multi-factor authentication everywhere, the access-key audit, and root-account discipline
- First Cloud Posture Review Runbook — close public access, switch on logging, and run your provider's posture check
- Public Storage & Exposure Checklist — find and close accidentally public buckets, snapshots, and shares
- Cloud Offboarding & Credential Rotation Runbook — close every door a leaver could still open
- Cloud Incident Card & Contacts Pack — the one-page incident card and the first-hour steps for a stolen credential
Enough if you own a small cloud estate and need to lock down the basics.
Buy Solo — $49- Configuration Baseline & Exception Pack — the baseline register, the exception log, and expiry rules
- Cloud Logging & Detection Starter Pack — what to log, where alerts go, and which ones matter first
- Cloud Vendor Due-Diligence & Contract Pack — vendor tiers, the questionnaire, and contract hygiene
- Cloud Incident Response Runbook Pack — scenario runbooks with ready-to-adapt communication templates
- Infrastructure-as-Code Security Review Checklist — catch a misconfiguration before it deploys
- SaaS Hardening Quick-Start — Microsoft 365 and Google Workspace, from enforced MFA to email authentication
- Cloud Network Exposure & Segmentation Checklist — no admin port open to the whole internet, and blast radius contained
- Everything in Solo
Choose this when a growing estate needs structure: identity, config, and a real programme.
Buy Team — $99- Multi-Cloud Governance Pack — one control catalogue, with per-provider recipes
- Compliance Evidence Pipeline Pack — controls as automated checks, feeding an evidence store auditors can trust
- Cloud Metrics & Board Reporting Pack — outcome metrics, drift signals, and the one-page board report
- Platform & Software-as-a-Service (SaaS) Posture Pack — clusters, pipelines, SaaS discovery, and collaboration-suite hardening
- Top 20 Cloud Misconfigurations & Their Fixes — the sweep for any estate you run or inherit
- Everything in Solo and Team
Step up here for multi-provider scale with auditors and a board to answer to.
Buy Enterprise — $299Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.
How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.
The companion books: the field guide and the workbook behind this toolkit.
The books teach the discipline; the toolkit does the work with you. The Cloud Security field guide covers the judgement; the Operator's Workbook carries the templates.
If this is your situation, one of these usually is too
Vulnerability Management
Cloud workloads are part of the estate you scan and patch. Vulnerability Management covers the programme around them — scanning, triage, deadlines, and reporting.
AI Security Assessment
The same maturity-assessment approach, pointed at the AI your organisation builds and buys — shadow AI, vendor checks, policy, and board reporting. Most cloud estates now host both.
The situation this toolkit is built for, written up.
Inheriting a cloud account nobody set up properly — ~7 min read.