How to Review Your Cloud Security Settings

Close-up of a key in a locked office drawer for secure storage and privacy.

Cloud security settings can drift as teams add accounts, launch services, and change how they work. A focused review helps you find exposed data, excessive permissions, missing records, and network paths that should be restricted. Start by listing every cloud account and the services in use, then check settings against your organisation’s needs. Record what you find, assign an owner to each issue, and prioritize changes that could expose sensitive systems or information.

Check access and account controls

Review who can sign in to each cloud account, including employees, contractors, administrators, and service accounts. Remove access for people who have left or changed roles, and confirm that each active account has a business purpose. Use individual accounts rather than shared credentials so actions can be traced to the person or service that performed them.

Give users only the permissions needed for their work. Check administrator roles, broad permissions, and long-lived access keys first. Require multifactor authentication for administrative and other sensitive accounts, and review sign-in protections such as session duration and recovery methods. Set a regular process for checking permissions, especially after role changes or project closures.

Review storage and data exposure

Inventory storage services that hold files, databases, backups, and application data. Check whether any storage is publicly accessible, shared with external accounts, or reachable through an overly broad link. Confirm that access rules match the data’s sensitivity and that teams know who owns each storage location.

Check encryption settings for stored data and for transfers between systems. Review backup coverage, retention periods, and whether backups are protected from accidental deletion or unauthorized access. Remove obsolete data and test that important backups can be restored. Where your provider supports alerts for public access or policy changes, enable them and make sure someone receives the notifications.

Verify logging and alert coverage

Confirm that audit logs capture sign-ins, permission changes, administrative actions, and changes to important resources. Check that logging covers every account and region your organisation uses; gaps can make it difficult to understand what happened during an incident. Set retention to meet your operational and compliance needs, and restrict who can alter or delete logs.

Make sure logs reach a place where the right people can review them. Configure alerts for events such as unusual sign-ins, new administrator access, disabled logging, and changes to public storage. Test alert delivery and document who responds. If your team cannot review every notification, tune alerts to focus on actions that could put sensitive data or critical services at risk.

Limit network access and exposure

Review firewalls, security groups, and other network rules for services exposed to the internet. Remove unused rules and narrow broad access wherever possible, especially for remote administration, databases, and internal tools. Specify the necessary source networks and ports rather than allowing connections from any address.

Map how cloud services communicate with one another and check that private systems do not have unnecessary public routes. Review virtual networks, gateways, load balancers, and remote access paths for outdated configurations. After making changes, test the services that depend on them and keep a record of the approved rules, their owners, and the reason each exception remains in place.

A useful cloud settings review is repeatable: inventory accounts, check the same control areas, record owners, and track fixes through completion. Revisit the review after major changes and on a schedule that fits your organisation’s risk. If you need help assessing your cloud environment, Forth Cloud Security can discuss a practical review.