Consultancy
Independent reviews that tell you
what is actually working.
Most organisations cannot be certain that what their provider says is happening actually is - or what has quietly drifted out of shape in their own environment. We send certified engineers to review what is really in place across your cloud platforms, your SOC, and your security posture, and tell you honestly what we find.
Three services
Sometimes the right answer is a focused project, not a subscription.
Managed services are right for most ongoing security challenges. But there are situations where sending in experienced specialists to do specific work gets you further, faster.
Service one
Cloud Security Posture Analysis
A structured posture analysis of your cloud environment, covering Microsoft 365, Azure, Google Workspace and Google Cloud Platform. Two certified engineers connect in remotely and review what is actually configured - identity and access, conditional access and MFA coverage, data exposure and sharing, third-party app and OAuth risk, email and domain integrity, endpoints, and licensing - measured against vendor and industry benchmarks.
You get an honest picture of what is working as well as what is not. Findings that are already secure are confirmed as compliant, so you know what to leave alone. Nothing is remediated during the engagement, which keeps the findings fully independent - and if you want help fixing what we find, remediation is available as a follow-on engagement, with guided self-remediation support included with the report.
Every engagement is scoped to your environment - whether you are a 12-person team on Google Workspace or a multi-tenant Microsoft estate, we review what you actually run.
Platforms we review
- Microsoft 365
- Azure
- Google Workspace
- Google Cloud Platform
What we look at
Read-only by design
Read-only by design. Access is time-bound to the engagement, granted to named individuals, MFA-enforced, and visible in your audit log - we never ask you to share admin credentials. Everything is revoked when the engagement closes.
What you receive
- A findings report with every issue risk-rated and prioritised - quick wins separated from strategic items - with plain-English context, business impact, and source evidence for each
- Confirmation of what is already configured well, not just what is broken
- A prioritised remediation roadmap your team can act on, sequenced by risk and effort
- Identification of stale accounts and unused licences - reviews of this type routinely surface recurring savings that offset a significant portion of the engagement fee
- A findings playback session with the engineers who did the work, walking through every finding with full Q&A
- Post-report guidance: ad-hoc support for your team as they self-remediate the findings
Engagement overview
- Duration
- Typically 5 days of assessment, with the report and findings playback arranged around your availability
- Team
- 2 certified security engineers
- Delivery
- Remote, via secure read-only access to your environment
- Platforms
- Scoped to your environment - Microsoft 365, Azure, Google Workspace, Google Cloud Platform
- Output
- Risk-rated findings report, prioritised roadmap, findings playback, post-report guidance
Confirm scope and platforms, establish secure read-only access.
Deep review across identity, data exposure, applications, email, endpoints and licensing, measured against benchmarks.
Every finding risk-rated and evidenced, presented at a findings playback with a prioritised roadmap and agreed next steps.
Service two
SOC Reviews
If a third party runs your SOC, this review tells you what is actually happening - not what you have been told is happening. Built around Microsoft Sentinel and Defender, and validating signals from across your estate including AWS and GCP, two certified security engineers independently assess whether the right data is being ingested, whether that data is actively used by detection rules, and whether your monitoring spend is proportionate to the security value delivered.
The review covers your log sources and any duplication, detection rules and alarms mapped against the MITRE ATT&CK framework, orphaned data that is ingested but never used by any detection, alert noise, SOC automation, threat intelligence usage, and log ingestion and retention costs - all measured against best practice. Every engagement is scoped to your estate: typically five to ten days, with smaller environments sitting at the lower end.
Review scope
- Microsoft Sentinel
- Microsoft Defender
- AWS signals
- Google Cloud signals
“Logging without detection is cost without value. Detection without coverage is confidence without evidence.”
How we review
Platform-level review
Performed once across your whole estate: architecture and workspace design, full data connector and ingestion inventory, identity and privileged access signal coverage, endpoint and cloud integration, SOC automation, and 12-month ingestion and cost trend analysis.
Workspace-level variance review
Each workspace individually assessed: ingestion volumes, business alignment, detection coverage, orphaned data, and cost density versus detection yield. This structure avoids duplication while making sure business-specific coverage is validated.
What you receive
- Platform and workspace inventory report - connectors, ingestion volumes, and retention settings across your estate
- Coverage and gaps matrix - a clear view of present, missing, and unused security signals
- Detection effectiveness summary - rule-to-data mapping, orphaned ingestion, alert noise, and coverage mapped against MITRE ATT&CK
- Cost optimisation plan - targeted recommendations with estimated cost impact, prioritised
- Governance and control observations - access models, privileged access, and operational findings
- A prioritised remediation and use-case backlog your team, or ours, can act on
Engagement overview
- Duration
- Typically 5–10 days, scoped to your estate; delivery can be split into batches around your operations
- Team
- 2 Microsoft-certified security engineers
- Delivery
- Remote or on-site
- Access
- Read-only throughout - reader-level roles only, time-bound, and revoked at close. We change nothing, which keeps the findings fully independent
- Flex promise
- If additional complexity is identified during scoping, we accommodate it within the engagement at no additional cost
Confirm your environment layout, validate read-only access, review your existing SOC's scope of works, and target the review from day one.
The estate-wide assessment described in the two-layer explainer.
Workspace-by-workspace findings.
Findings consolidated, risk-rated and quality-assured, then formally presented to your stakeholders with a walkthrough of the prioritised backlog.
Knowledge transfer built in
Knowledge transfer is built into every phase - your team works alongside our engineers, so when we leave, you understand exactly what was found and why.
Service three
Framework Gap Analysis
A structured assessment of your current security posture against two of the most widely adopted frameworks in the UK: CIS 18 Controls and the NIST Cyber Security Framework. We map what you have in place, identify the gaps, and produce a prioritised improvement roadmap your team can act on.
The output is designed to be used directly. Whether you need it for an insurance review, a board presentation, or to inform your next security investment, the assessment gives you a clear, evidenced baseline.
What you receive
- Current posture mapped against CIS 18 Controls
- Current posture mapped against the NIST Cyber Security Framework
- Identified gaps with severity and risk context
- A prioritised improvement roadmap
- Board-ready summary report
- Knowledge transfer session included as standard
Engagement overview
- Frameworks
- CIS 18 Controls and NIST Cyber Security Framework
- Duration
- Typically 3 days
- Team
- 1 qualified cyber security consultant
- Output
- Framework assessment report and prioritised roadmap
- Delivery
- Remote or on-site
Incident response readiness
We also deliver incident response readiness as consultancy: tabletop exercises that test your team against realistic scenarios, and incident response and business continuity plan development. Scoped to your organisation - ask on a discovery call.
FAQs
Frequently asked questions
No. All of our consultancy engagements are available standalone. You do not need a managed SOC contract with Aruga, and there is no ongoing commitment involved. Many clients come to us specifically for one of these projects before deciding whether to expand the relationship further.
Get started
Not sure which engagement is right for you?
Tell us where you are and what you are trying to achieve. A 30-minute call is all it takes to work out whether one of these services is the right fit.

