Azure Environment Review
A fixed-scope, read-only assessment of your Azure estate against the Microsoft Well-Architected Framework, with an eye to ISO 27001 and NIS2. You get a written report, a prioritised remediation plan, and a walkthrough. We change nothing in your environment — this is an assessment, not a project.
Fixed scope, fixed price — quoted on enquiry.
You'll recognise the situation.
- You're in Azure but nobody is sure it's built right.
- The board or an auditor is asking NIS2 or security questions you cannot yet answer.
- You're about to migrate more workloads and want to fix the foundation first.
- You've inherited an Azure estate and need an honest picture of it.
How it runs.
Five business days from the day read-only access is granted. The walkthrough is on day five.
Day 1 — Kick-off
We confirm scope, take read-only access, and agree the subscriptions and workloads in scope.
Days 2–3 — Assessment
We work through the five Well-Architected pillars — reliability, security, cost optimisation, operational excellence, performance efficiency — plus identity, networking and governance.
Day 4 — Analysis
We turn findings into a prioritised remediation plan, ranked by risk and effort.
Day 5 — Report & walkthrough
You get the written report and plan, and we walk your team through it on a call.
The deliverable.
- A written report: findings by Well-Architected pillar, with evidence and a risk rating for each.
- A prioritised remediation plan: what to fix, why it matters, and the rough effort.
- A 60–90 minute walkthrough call with your team.
- The raw findings, so nothing is hidden behind a summary.
What's in it.
- 01Executive summary
- 02Scope and method
- 03Findings by Well-Architected pillar
- 04Identity and access
- 05Networking and segmentation
- 06Security operations and logging
- 07Cost
- 08Governance and policy
- 09Prioritised remediation plan
- 10Appendix — evidence
Prerequisites.
- Reader and Security Reader access to the subscriptions in scope.
- A named technical contact for the kick-off and any questions.
- Any existing architecture documentation, if you have it.
What it isn't.
- We make no changes — the review is read-only.
- It is not a penetration test.
- It is not a full ISO 27001 audit or NIS2 certification — it tells you where you stand.
- Delivering the remediation is a separate engagement, at your option.
What happens next.
You own the report. Fix it with your own team, or we can deliver the remediation as a separate fixed-scope engagement. There is no obligation either way.
Frequently asked.
- Do you change anything in our environment?
- No. The review is read-only. We take Reader-level access and make no changes.
- Who from our side needs to be involved?
- One named technical contact for the kick-off and to grant access. Beyond that, we work independently until the walkthrough.
- What access do you need?
- Reader and Security Reader on the subscriptions in scope. Nothing that lets us make changes.
- Is this a penetration test?
- No. It is an architecture and configuration review against the Well-Architected Framework, not an offensive security test.
- Does it certify us for NIS2 or ISO 27001?
- No. It tells you where you stand against them and what to fix. Certification is a separate, formal process.
- What does it cost?
- Fixed scope, fixed price — quoted on enquiry. Larger or multi-tenant estates are scoped and quoted accordingly.
- What if we have several subscriptions or tenants?
- We agree the scope up front. A larger estate takes more time, and that is reflected in the quote before we start.
- Can you fix what you find?
- Yes — as a separate engagement, with no obligation. Many clients fix the quick wins themselves and bring us in for the harder items.
Where this leads.
Azure Security & Zero Trust
Identity-first designs that assume breach — built to stand up to NIS2 and an auditor.
Learn moreAzure Landing Zones
Enterprise-scale foundations built to the Well-Architected Framework — governance, networking and identity from day one.
Learn moreSecurity Operations & Management
Ongoing protection with Microsoft Defender for Cloud and Azure Arc across your estate.
Learn moreAzure Environment Review — start with a conversation.
Fixed scope, fixed price — quoted on enquiry.