Architecture review
Whether the current design supports what the business needs it to do: workload placement, coupling between services, scaling behaviour under load, and the decisions that are now constraining you. Across AWS, Azure, and GCP, including estates spanning more than one.
Cost and commitment analysis
Where the money goes and how much of that is avoidable: idle and oversized resources, storage tiering, egress, and commitment coverage against actual usage. Most estates carry a double-digit percentage of spend that buys nothing, and finding it usually pays for the assessment.
See also: IT Services
Security posture
Identity and permission boundaries, public exposure, encryption, network segmentation, and logging coverage. Assessed against the obligations that actually apply to you rather than a generic benchmark, since a control that matters for CUI may be irrelevant for a public marketing site.
Compliance boundary review
Where the assessment boundary sits in the current estate and whether it is defensible. A boundary that expanded by accident is a boundary you are paying to evidence, and narrowing it is often the single largest reduction in compliance cost available.
See also: Compliance Readiness
Resilience review
What happens when a component, a zone, or a region fails, and whether recovery has been tested rather than assumed. Backups that have never been restored are a common and expensive finding.
Sequenced recommendations
Findings ordered by payback rather than by category, so the work that funds the rest goes first. Cost findings frequently pay for the security work, which is a large part of why the three are assessed together.