Security is a
design decision.
Flat networks, shared identities, cloud accounts without separation, backups inside the same trust boundary as production: we review network, identity and cloud architecture against recognised reference models and show which design decisions make attacks easier.
What is included.
Whether the design holds — before it is built, or before it breaks.
Network and segmentation
Zones, transitions, remote access, OT connectivity; where an incident can spread.
Identity architecture
Tiering, privileged access workstations, trust relationships, cloud federation, service accounts.
Cloud landing zone
Account and subscription structure, networking, encryption, logging, policy enforcement.
Recovery
Backup isolation, restore order, dependencies on identity and network.
Five steps,
one deliverable.
Documents
Review architecture documents, diagrams and policies.
Interviews
Architects, operations, security.
Spot checks
Verify configuration at the critical points.
Assessment
Against reference models; justify each weakness with an attack scenario.
Target state
Propose the target architecture and the migration steps.