secureskies
Cyber Security/Evaluate/Architecture Assessments

Security is a
design decision.

Flat networks, shared identities, cloud accounts without separation, backups inside the same trust boundary as production: we review network, identity and cloud architecture against recognised reference models and show which design decisions make attacks easier.

FormatReviewdocuments + interviews + spot checks
ScopeNetwork · identity · cloudbackup · segmentation
BenchmarkAWS/Azure Well-ArchitectedMicrosoft tiering · Zero Trust
OutcomeArchitecture findingsplus target architecture
01 · Service

What is included.

Whether the design holds — before it is built, or before it breaks.

Network and segmentation

Zones, transitions, remote access, OT connectivity; where an incident can spread.

Identity architecture

Tiering, privileged access workstations, trust relationships, cloud federation, service accounts.

Cloud landing zone

Account and subscription structure, networking, encryption, logging, policy enforcement.

Recovery

Backup isolation, restore order, dependencies on identity and network.

02 · Process

Five steps,
one deliverable.

01

Documents

Review architecture documents, diagrams and policies.

02

Interviews

Architects, operations, security.

03

Spot checks

Verify configuration at the critical points.

04

Assessment

Against reference models; justify each weakness with an attack scenario.

05

Target state

Propose the target architecture and the migration steps.

03 · Who it fits

When this service
applies.

Ahead of major work: cloud migration, data-centre build, AD consolidation
After an incident, for root-cause analysis at design level
Group subsidiaries working to parent-company standards
More services · Evaluate

Does your backup sit in the same
trust boundary as production?