+1 (780) 800-8357 info@atgic.ca 7445 Roper Rd NW, Edmonton, AB
Referral Program FAQ
$ CAD
  • $ CAD
  • $ USD
  • € EUR
  • £ GBP
  • ₹ INR
  • $ AUD
  • $ SGD
  • CHF CHF
  • RM MYR
  • ¥ JPY
  • د.إ AED
  • ؋ AFN
  • L ALL
  • AMD AMD
  • ƒ ANG
  • Kz AOA
  • ZK ZMW
  • ৳  BDT
  • $ ARS
  • Afl. AWG
  • ₼ AZN
  • KM BAM
  • $ BBD
  • лв. BGN
  • .د.ب BHD
  • Fr BIF
  • $ BMD
  • $ BND
  • Bs. BOB
  • R$ BRL
  • $ BSD
  • Nu. BTN
  • P BWP
  • Br BYN
  • Br BYR
  • $ BZD
  • Fr CDF
  • $ CLP
  • ¥ CNY
  • $ COP
  • ₡ CRC
  • $ CUP
  • $ CUC
  • $ CVE
  • Kč CZK
  • Fr DJF
  • kr. DKK
  • RD$ DOP
  • د.ج DZD
  • EGP EGP
  • Nfk ERN
  • Br ETB
  • $ FJD
  • R ZAR
  • ﷼ YER
  • T WST
  • Vt VUV
  • ₫ VND
  • Bs F VEF
  • Bs. VES
  • UZS UZS
  • £ FKP
  • ₾ GEL
  • £ GGP
  • ₵ GHS
  • £ GIP
  • D GMD
  • Fr GNF
  • Q GTQ
  • $ GYD
  • $ HKD
  • L HNL
  • kn HRK
  • G HTG
  • Ft HUF
  • Rp IDR
  • ₪ ILS
  • £ IMP
  • د.ع IQD
  • ﷼ IRR
  • kr. ISK
  • £ JEP
  • $ JMD
  • د.ا JOD
  • KSh KES
  • сом KGS
  • ៛ KHR
  • Fr KMF
  • ₩ KPW
  • ₩ KRW
  • د.ك KWD
  • $ KYD
  • ₸ KZT
  • ₭ LAK
  • ل.ل LBP
  • රු LKR
  • $ LRD
  • L LSL
  • $ UYU
  • د.ل LYD
  • د.م. MAD
  • MDL MDL
  • Ar MGA
  • ден MKD
  • Ks MMK
  • ₮ MNT
  • UM MRU
  • P MOP
  • UGX UGX
  • ₴ UAH
  • Sh TZS
  • ₨ MUR
  • .ރ MVR
  • MK MWK
  • $ MXN
  • MT MZN
  • N$ NAD
  • ₦ NGN
  • C$ NIO
  • kr NOK
  • CFA XOF
  • XPF XPF
  • $ XCD
  • CFA XAF
  • ₨ NPR
  • $ NZD
  • ر.ع. OMR
  • B/. PAB
  • S/ PEN
  • K PGK
  • ₱ PHP
  • ₨ PKR
  • zł PLN
  • ₲ PYG
  • ر.ق QAR
  • lei RON
  • рсд RSD
  • ₽ RUB
  • Fr RWF
  • ر.س SAR
  • $ SBD
  • ₨ SCR
  • ج.س. SDG
  • kr SEK
  • £ SHP
  • Le SLL
  • Sh SOS
  • $ SRD
  • £ SSP
  • Db STN
  • NT$ TWD
  • ل.س SYP
  • $ TTD
  • ₺ TRY
  • T$ TOP
  • E SZL
  • ฿ THB
  • m TMT
  • د.ت TND
  • ЅМ TJS

Cloud Security

The cloud provider secures the platform. Everything you configure on top of it is yours — and that's where almost every cloud incident starts. We review your tenancy against the benchmarks, close the gaps that matter, and leave you with a baseline that holds as you grow.

Azure · AWS · Google Cloud · Microsoft 365 CIS Benchmarks · ISO/IEC 27017 Canadian data residency guidance
The misunderstanding

"It's in the cloud, so it's secure" is half a sentence

Every major provider publishes a shared responsibility model, and every major provider holds up their end. The breaches happen on the other side of the line: a storage bucket left public, an identity with standing admin rights, an unmonitored service principal, logging that was never turned on.

A cloud security review draws that line explicitly for your services, then tests everything on your side of it. The result is a documented baseline — so the next engineer who spins up a resource inherits the standard instead of inventing one.

  • Identity is the new perimeterPrivileged roles, standing access, service principals and conditional access reviewed first
  • Data exposure, found deliberatelyPublic storage, over-shared files, unencrypted volumes and forgotten snapshots
  • Logging you'd actually want in an incidentAudit logs enabled, retained long enough, and alerting on the events that matter
  • Residency handled explicitlyWhere data is stored, replicated and supported from — and what that means for your obligations
Platforms

Reviewed against the benchmark for the platform you run

Generic cloud advice ages badly. We assess each platform against its own current benchmark and the services you've actually deployed.

Microsoft Azure

Entra ID roles and conditional access, network security groups, key vault, Defender coverage and subscription-level guardrails.

Amazon Web Services

IAM policy sprawl, S3 exposure, VPC design, KMS usage, CloudTrail coverage and organization-level service control policies.

Google Cloud

Project and folder hierarchy, IAM bindings, service account keys, VPC service controls and audit log configuration.

Microsoft 365

Mailbox and file sharing exposure, admin role assignment, MFA and legacy authentication, retention, and external guest access.

How we work

Baseline, assess, remediate, hold the line

  1. 01 Inventory & boundary Every subscription, account and tenant in use — including the ones a department signed up for without telling IT.
  2. 02 Configuration assessment Read-only review against CIS benchmarks and ISO/IEC 27017, covering identity, data, network, logging and workload.
  3. 03 Prioritized remediation Findings ranked by real exposure, each with the specific setting to change and the impact of changing it.
  4. 04 Documented baseline A written standard plus guardrail recommendations, so new resources land compliant instead of drifting.
Common questions

Cloud security FAQ

Read-only reviewer access, scoped to the subscriptions in scope and time-limited to the engagement. We can also work entirely from configuration exports your team generates if you'd rather not provision accounts at all — it takes longer but changes nothing about the findings.

It depends on your sector and the personal information involved — public bodies in some provinces face stricter rules than private companies. What matters most in practice is knowing where data actually rests and who can access it in support, then documenting that honestly. Our privacy impact assessment covers this in depth when personal information is in play.

Please don't. A baseline set during migration costs a fraction of retrofitting it afterwards, and landing zone decisions made now are the hardest to unwind later. We're happy to review the design before the workloads move rather than the tenancy after they have.

It's a useful signal and we always look at it, but it weights recommendations by the provider's own model rather than your business risk — and it can't see the shared mailbox with client records in it, or the contractor who still has access. A review adds context the score has no way of knowing.

Know what you own in the shared responsibility model

Tell us which platforms you run and roughly how much sits in each — we'll scope a review with a fixed price and a firm date. We respond within one business day.