Professional Services

Cloud Security

Assessing Risks To Protect Your Data

The cloud offers organisations a great opportunity to improve on operational efficiency, gain market share, deliver a better experience for their users and customers and realise cost savings. As a result, transformation projects are underway across companies of all sizes and industries.

Kaon Security have tailored their cyber security offerings to meet the demands of customers who wish to ensure an adequate level of security is applied to their data, network and systems regardless of the cloud services model they are working with (including SaaS, PaaS and IaaS environments).

We can assist in cloud decision making in advance of migrating, this is especially useful for organisations who wish to ensure security best practice is in place as a foundation for a successful and safe migration. From mapping your existing environment through to reviewing current and future state architecture we are able to collaborate with you to provide practical cyber security guidance and advice in this complex process.

Many organisations have already made a partial or full migration to the cloud. Some are aware that cloud applications are being used in their environment but they do not have full visibility of what exactly is being used and who is using it. Kaon Security are able to apply their substantial experience to provide you with an accurate understanding of your current risk levels and the practical steps you can take to assure yourself of the security of your (and your customers’) data.

Two office workers planning a digital transformation project on a PC and laptop
Business man remote working in a coffee shop using a secure Microsoft 365 environment

Microsoft 365 Security Review

The Microsoft 365 online productivity suite has proven to be a very popular solution for organisations that recognise the business benefits of using cloud based technology. The introduction of Copilot has magnified both the capabilities and exposure of the service.

Microsoft 365 and Copilot requires organisations to make some key security configuration decisions; making the right decisions can be challenging given the depth of options to choose from. You will need to consider (for example):

  • different access control options to manage identity and access control

  • data resiliency arrangements for protecting information and recovering it from potential corruption

  • the best way to prevent data leakage using encryption and controlling forwarding options

A “set and forget” approach won’t work as the Microsoft 365 cloud environment is inherently dynamic.

Microsoft Copilot works with everything a user can already access. Files that were overshared years ago, but never found, can now surface in a single prompt. At the same time, staff can build and share AI agents that connect to business systems and act on their behalf. Many of the Microsoft settings that control this are open by default, and they change every few months.

  • Oversharing becomes visible. Microsoft Copilot doesn't create new access, but it makes existing access easy to use.

  • Agents spread quickly. Without clear rules on who can build, share and publish them, nobody knows what exists or who owns it.

  • The platform keeps moving. New AI settings, retiring features and changed defaults mean your most recent configuration may no longer be safe.

Kaon Security’s Microsoft 365 Security Review service assists organisations to improve their IT security posture by optimising their Microsoft 365 and Copilot security configuration.

A detailed report provides an executive summary of the Microsoft 365 security review, a risk analysis commentary and security recommendations. Specifically written for business people, the executive summary will allow you to discuss how to improve your Microsoft 365 and Copilot security posture.

A detailed “Key Observations” section is provided in the report for the CIO or IT Manager covering our security findings, a risk analysis commentary and our recommended next steps for remediation.

Azure Security Review

Microsoft’s successful Azure platform comprises of interoperable cloud computing services that incorporate open-source, standards-based technologies plus proprietary solutions from Microsoft and other technology companies.

The Azure infrastructure is a complex environment made up of interlinked virtual machines, storage accounts, application services and databases utilising complex virtual networks and load balancers. Additionally all of these objects are categorised as a Resource within Resource Groups.

When deploying the Azure solution organisations need to make some key security configuration decisions, and making the right decisions can be challenging given the range of configuration options to choose from. A “set and forget” approach won’t work as the Azure cloud environment is inherently very dynamic.

The Azure Security Review service assists organisations to improve their IT security posture by optimising their Azure configuration.

In delivering this service our experts investigate and assess key areas of the Azure infrastructure including the current configuration and available supporting customer information. We then conduct a risk analysis of the Azure implementation, make recommendations to improve the organisational cyber security posture and provide remediation points.

Some of the areas we investigate and verify include:

  • Resource Groups
  • Storage Accounts
  • Virtual Machines and Networks
  • Application Services
  • SQL and Cosmos databases
  • Load Balancing

The detailed report provides an executive summary of the Azure security review, a risk analysis commentary and security recommendations.

A detailed “Key Observations” section is provided in the report for the CIO or IT Manager covering our security findings, a risk analysis commentary and our recommended next steps for remediation.

IT professionals optimising Azure security configurations

Frequently Asked Questions

Moving to or managing the cloud can raise a lot of questions. Here are some of the most common ones we hear about Cloud Security, with straightforward answers to help you understand how we can support your organisation.

What Is Cloud Security?

Security is a shared responsibility in the cloud computing environment. Cloud providers (like AWS, Azure, or Google Cloud) are responsible for the security of the cloud, encompassing the physical infrastructure, hardware, software, and network that underpins the cloud services. However the customer is responsible for security in the cloud, which means they are responsible for securing their data, applications, and configurations within the cloud environment.

Cloud security refers to the technologies, policies, processes, and procedures used to protect data, systems, and services hosted in cloud environments. It includes key areas such as:

  • Access control and identity management
  • Data encryption and protection
  • Configuration management
  • Security monitoring and logging
  • Incident detection and response
Why Is Cloud Security Important?

Cloud platforms offer flexibility and scalability but also introduce unique risks. Common threats include:

  • Misconfigurations that expose sensitive data
  • Weak or compromised identity controls
  • Unclear responsibility for security between provider and customer

Robust cloud security helps prevent breaches, service outages, and unauthorised access.

What Does A Cloud Security Assessment Include?

A Cloud Security assessments strengthen your cloud posture by providing:

  • Risk and misconfiguration assessments

  • Policy and control reviews aligned to best practice

  • Configuration guidance for cloud platforms and services

  • Access management improvements

  • Monitoring and alerting recommendations for suspicious activity

The goal is to ensure your cloud environment is secure, well-governed, and resilient against evolving cyber threats.

Can A Cloud Security Assessment Be Performed Across Multi-Cloud Or Hybrid Environments?

Yes. We work with organisations using AWS, Microsoft 365, Azure, and private or hybrid cloud setups. Our assessments are tailored to your environment, regardless of size or complexity.

Can A Cloud Security Assessment Identify Misconfigurations In Our Cloud Environment?

Absolutely. Misconfigurations are a leading cause of cloud-related breaches. We assess your Microsoft 365, Azure, AWS and other environments against security best practices and highlight misconfigured settings that may increase risk.

Is Your Service Aligned With Industry Standards?

Yes. Our assessments align with established cloud security frameworks, standards and best practice guidance.

Can A Cloud Security Assessment Help Prepare For An Audit Or Certification?

Yes. We identify gaps in your cloud security controls, documentation, and processes so you can prepare confidently for audits or certifications, reducing the risk of last-minute issues.

What Cloud Platforms Can Be Assessed As Part Of A Cloud Security Assessment?

We support all major platforms, including:

  • Amazon Web Services (AWS)
  • Microsoft Azure
  • Microsoft 365 environments
What’s The Difference Between SaaS, PaaS And IaaS?

SaaS (Software as a Service) refers to applications that are delivered over the internet rather than hosted on your organisation's local network. Common examples include Microsoft 365, Salesforce and Dynamics 365. The service provider is responsible for managing the application and the underlying infrastructure.

PaaS (Platform as a Service) provides a managed platform for developing, running and managing applications. The provider maintains the infrastructure, servers and operating systems, while you retain control of your applications and data.

IaaS (Infrastructure as a Service) provides access to core computing resources such as servers, storage and networking. The provider manages the physical infrastructure, while your organisation is responsible for the operating systems, applications and data hosted on those resources.

Contact Us Today

Fill in the form below or call us on +64 9 570 2233