How This Works

Answer 28 questions across ten areas — from identity and inventory through workloads, detection, incident response, vendors, and compliance evidence. Each takes 10–20 seconds. At the end you'll get a weighted maturity score, a tier band, a breakdown by area, and a recommended set of priority actions. The questions reflect widely recognised cloud security practice; which recommendations fit your organisation is your call.

Part 1 — Identity & Access (The Cloud's Perimeter)

The root account sits above every other control. Hardware-backed MFA, no access keys on root, and an alert on any root sign-in are the standard discipline.

A key created years ago still works today unless someone deactivates it. Keys belonging to leavers are a common breach entry point.

Without SSO, every account keeps its own leaver checklist. The accounts missed on that checklist keep live credentials for ex-staff.

Part 2 — Inventory & Configuration Baselines

Most organisations undercount their cloud estate. The monthly bill is the one discovery channel nothing can hide from.

Unintended public access is the most common cloud exposure pattern. Account-level "block public access" settings close most of it in one step.

Cloud security posture management (CSPM) tools — including the providers' free tiers — flag misconfigurations continuously. A finding queue nobody reviews is a tool, not a programme.

Part 3 — Workloads, Containers & Kubernetes

Short-lived workloads inherit their security from the image or template that produced them. Securing the pattern secures every instance built from it.

The cluster is a security surface of its own, and its front door is the API server. Skip if you run no clusters: answer "Yes" to keep scoring fair.

Cluster networks are flat by default. Default-deny network policies contain a foothold to one workload. Skip if you run no clusters: answer "Yes".

Part 4 — Infrastructure as Code

A misconfiguration in code is deployed automatically, again and again, until the code is fixed. Caught in the pull request, it costs a comment instead of an incident. Skip if you define no infrastructure in code: answer "Yes".

A pipeline that can deploy anything is an administrator and deserves the same guarding. Drift between code and the live estate is configuration nobody reviewed. Skip if you run no pipelines: answer "Yes".

Part 5 — SaaS Discovery & Posture

Most organisations find far more SaaS than they ever reviewed. The tools you have not discovered are the tools you cannot secure.

Leavers keep access to every tool outside SSO until someone remembers it exists. Vendors default to convenient sharing, not safe sharing.

A suite super-administrator can read any mailbox and any file. Forgotten app grants are standing access to your data that nobody is watching.

Part 6 — Logging, Detection & Identity Threats

These logs are the forensic record of everything done to your cloud. Attackers work in the regions you forgot to log.

The native detectors catch credential abuse and cryptomining patterns at low cost. An alert in an unwatched console is not detection.

In the cloud, identity is the perimeter. Identity threat detection and response (ITDR) treats a stolen credential as the perimeter breach it is.

Part 7 — Cloud Incident Response & Forensics

Without a written plan, the response is improvised at the worst hour. The first version can be one laminated page.

The attacker's clock runs in seconds; approval chains do not. A written containment-authority note turns the worst hour into procedure.

The cloud deletes evidence on its own schedule. Log retention, snapshots, and one practised capture drill decide whether forensics is possible.

Part 8 — Vendor Due Diligence & Contract Hygiene

Vendor estates grow past their registers quietly. Tiered assessment puts the effort where the sensitive data is.

An assessment without contract terms cannot be enforced. The notification clause decides whether you learn of a vendor's breach from the vendor or from the news.

Exit questions are cheapest before signature. "What could we take with us in ninety days?" is the test.

Part 9 — Multi-Cloud & Hybrid Governance

The providers implement the same concepts differently; a practice built for one does not transfer. Skip if you deliberately run a single provider: answer "Yes".

A contained estate with an owner and a review date is a decision. An unknown one is a finding. Nothing should be simply unaccounted for.

Part 10 — Compliance Evidence & Programme Review

The mapping table is every audit's index. One control, evidenced once, can satisfy several frameworks at the same time.

A timestamped check history proves a control operated all year. A screenshot proves one instant — expensively.

Programmes improve deliberately or drift quietly. One page a quarter to the people who fund the work is what keeps it alive.

Answer all 28 questions to see your report.

Your Cloud Security Maturity Results

0 / 68
Identity & access
0 / 10
Inventory & configuration
0 / 10
Workloads, containers & clusters
0 / 6
Infrastructure as code
0 / 4
SaaS discovery & posture
0 / 6
Logging, detection & identity threats
0 / 8
Incident response & forensics
0 / 8
Vendor due diligence & contracts
0 / 6
Multi-cloud & hybrid governance
0 / 4
Compliance evidence & review
0 / 6

The book series scores a programme by its weakest dimension, not its average. Whatever your overall band, your lowest bars above are the recommended place to start.

Your Recommended Priority Actions

Ready to Close These Gaps?

The free assessment shows where you stand. The paid editions add the working documents — account register, identity runbook, baseline and exception packs, incident runbooks, vendor questionnaires, board-report templates and more — so you have the artefacts, not just the score.

See the Editions + Toolkit →