Secure Cloud Start
A landing zone delivered as code in your repository, with guardrails and cost control from the first account.
- Duration
- 6–10 weeks
- Price
- €20,000 to €40,000
- excl. VAT, indicative
Four practices, held by one team.
Services
Security that ships with the code, and evidence that collects itself.
A security report that arrives after the platform is built describes a problem. A guardrail in the pipeline prevents one. The difference in cost is roughly two orders of magnitude, and it is the reason this practice exists inside a security firm rather than next to one.
We design landing zones as code in your repository, wire security testing into the pipelines your teams already use, and tune it until the output is trusted — because a scanner nobody reads is worse than no scanner at all. Then we make the same controls produce their own audit evidence, timestamped and exportable, which is what makes an ISO 27001 or SOC 2 certificate affordable to keep.
And we watch the bill. FinOps usually returns fifteen to thirty per cent of cloud spend, which tends to fund the rest of the work.
Decide what moves, where it lands, and what it will cost before the first migration.
Application-by-application analysis of what to retire, retain, rehost, replatform or rebuild, with the business case and the regulatory constraints in the same table.
A structured comparison of AWS, Azure, GCP, OVHcloud, Scaleway, S3NS and Bleu against your technical, contractual, sovereignty and exit requirements.
A review of an existing workload against the provider's framework, covering operational excellence, security, reliability, performance, cost and sustainability.
A data platform with ownership, quality and lineage defined from the start, and access controls that let analytics happen without opening the whole warehouse.
A landing zone built as code, then workloads moved onto it without a rebuild.
Account structure, network, identity, logging, encryption and guardrails delivered as code in your repository, so every new environment inherits the same baseline.
Wave planning, runbooks, cutover rehearsals and rollback criteria, with the security and compliance checks built into each wave rather than added at the end.
Containerisation and refactoring of applications where it pays, with base images, build pipelines and platform targets defined once and reused.
Connectivity between data centres, clouds and sites designed for segmentation and observability, not just for reachability.
Who owns what, how it is monitored, and why the bill stopped growing.
Who can create what, who pays for it, who secures it and who is called at night — written down, agreed, and enforced by policy rather than by memory.
Cost allocation, commitment strategy, rightsizing and waste elimination, typically returning fifteen to thirty per cent of the bill within the first quarter.
Posture management that runs every day and reports in the language of your control framework, so cloud evidence for ISO 27001 or SOC 2 is produced automatically.
A documented, tested exit strategy for critical cloud services, which DORA requires financial entities to hold and most contracts quietly assume will never be used.
Metrics, logs and traces that answer real questions, with service level objectives defined with the business and alerting that does not wake people for nothing.
Where your data physically sits, who can legally compel access to it, and what it would take to change that — documented for the regulator and the board.
Controls inside the pipeline, producing their own audit evidence as they run.
Measured against DORA metrics, OWASP SAMM, NIST SSDF and SLSA, with the difference between what the documentation claims and what the pipelines actually do.
Security requirements, review gates and acceptance criteria defined per stage, light enough that teams keep them and firm enough to satisfy an auditor.
Structured threat modelling of your critical services, run as a workshop with the engineers who build them, producing backlog items rather than a document nobody reopens.
Hardening of GitHub Actions, GitLab CI or Azure DevOps: least-privilege runners, pinned actions, protected branches, signed artefacts and no long-lived credentials.
Security testing wired into the pipeline with thresholds that block what matters and stay quiet otherwise, because a scanner nobody trusts is a scanner nobody reads.
Secrets out of repositories and pipelines, into a vault with short-lived credentials and workload identity, plus detection for the ones already leaked.
SBOM generation, dependency policy, artefact signing and provenance to SLSA levels, aligned with what the Cyber Resilience Act will require you to produce.
Policies expressed as code and enforced before deployment, so a non-compliant resource fails the pull request instead of appearing in an audit six months later.
Training built on your own codebase and findings, plus a security champion network that gives teams someone to ask before the review rather than after it.
Cluster review against the CIS Kubernetes benchmark: RBAC, admission control, network policy, workload identity, secrets handling and node hardening.
Minimal base images, reproducible builds, registry scanning and signing, with a patch path that does not require rebuilding every service by hand.
Paved paths that make the secure option the fastest option: golden templates, self-service environments and GitOps delivery with the guardrails already inside.
Detection of what happens after deployment: anomalous process behaviour, container escapes, unexpected network flows, with response actions defined in advance.
Service level objectives, error budgets, incident review without blame, and toil measured so that automation is funded by evidence rather than by conviction.
One telemetry pipeline serving both engineering and security, with retention set by regulatory requirement rather than by default configuration.
Controls for ISO 27001, SOC 2, NIS2 and DORA implemented as automated checks that produce their own timestamped evidence, which is what makes a certificate affordable to keep.
Change management that satisfies auditors without a weekly committee: approvals in the pull request, deployment records generated automatically, emergency path documented.
Recovery expressed as code and tested on a schedule, so the recovery time objective is a measured number rather than an aspiration in a document.
A standing engineering capacity that keeps the pipeline, the guardrails and the evidence working as your platform changes, with a named engineer and a monthly review.
A landing zone delivered as code in your repository, with guardrails and cost control from the first account.
Security controls inside your pipeline, tuned so the team keeps them after we leave.
A cluster audit against the CIS benchmark, with the hardening applied and verified.
SBOM, signing and provenance in place, mapped to what the Cyber Resilience Act will ask for.
Standing engineering capacity that keeps pipelines, guardrails and compliance evidence working as your platform changes, with a named engineer and a monthly review.
Continuous cost management: allocation kept accurate, commitments managed, waste removed each month, and savings reported as measured figures.
Continuous scanning of what you own and what is exposed in your name, with findings filtered, prioritised and tracked to closure rather than published as a raw list.
Discuss this service — Vulnerability and attack-surface management
Secure Cloud Start if the foundation needs building. DevSecOps Kickstart if the code ships weekly and security is still outside the pipeline.