Cloud Security

Google Cloud Security Consulting

We design and harden Google Cloud environments: resource hierarchy and organisation policy, least-privilege IAM, VPC and network controls, Security Command Center and logging, Workload Identity, and GKE security — with remediation delivered in Terraform.

The problem we solve

Google Cloud's resource hierarchy is one of its strongest security features and one of the most commonly wasted. Projects proliferate outside any folder structure, organisation policies stay at defaults, and basic roles such as Editor get granted because they are the fastest way to unblock someone.

Service account keys are a persistent weak point. Long-lived JSON keys end up in CI systems, laptops and repositories, and remain valid long after the person or pipeline that needed them is gone.

Security Command Center may be switched on, but findings, audit logs and GKE events are frequently unmonitored, with no defined owner and no routing into the systems the on-call engineer actually watches.

Google Cloud rewards teams that use its hierarchy properly. Organisation policy, folder-scoped IAM, VPC Service Controls and Workload Identity together remove whole categories of risk — but only if they are designed as one model rather than enabled piecemeal after an audit finding.

Our approach

Adapted to your environment and constraints — but the shape of the work is consistent.

  1. Get the hierarchy and guardrails right

    We review the organisation, folder and project structure and apply organisation policy constraints — restricting external IPs, blocking service account key creation, enforcing uniform bucket-level access, constraining domain-restricted sharing and allowed regions — so the default state is secure.

  2. Rebuild identity around least privilege

    Replace basic roles with predefined and custom roles, use IAM Recommender and policy analysis to strip unused permissions, apply IAM conditions, and eliminate service account keys in favour of Workload Identity Federation and Workload Identity for GKE.

  3. Design the network

    Shared VPC and subnet design, firewall rule review and tightening, Private Google Access and Private Service Connect, VPC Service Controls perimeters around sensitive data, and Cloud Armor at the edge.

  4. Turn on real visibility

    Security Command Center configured and tuned, organisation-level audit log sinks to a restricted log bucket or BigQuery, log-based alerting for high-signal events, and integration with your SIEM and on-call rotation.

  5. Secure workloads and keep them secure

    GKE hardening, Binary Authorization for trusted images, Artifact Registry controls and vulnerability scanning, CMEK where required, Secret Manager adoption, and Terraform modules plus policy-as-code checks so new projects inherit the baseline.

Expected outcomes

What changes as a result of the engagement.

  • A resource hierarchy and organisation policy set that enforces the baseline
  • Basic roles and unused permissions removed from the IAM model
  • Service account keys replaced with keyless Workload Identity
  • Sensitive data protected by VPC Service Controls perimeters
  • Centralised, retained audit logging with alerting on high-signal events
  • Security Command Center findings owned, triaged and actioned
  • GKE clusters hardened against a documented standard
  • Compliance evidence for SOC 2 and ISO 27001 available on demand

Typical deliverables

Confirmed in the proposal before work starts, and adjusted to scope.

  • Google Cloud security assessment against CIS GCP Benchmark
  • Prioritised remediation roadmap with risk and effort estimates
  • Target-state GCP security architecture and resource hierarchy design
  • Organisation policy constraint set
  • IAM least-privilege model with custom role definitions
  • Workload Identity Federation migration plan
  • VPC, firewall and VPC Service Controls design
  • Logging, monitoring and SCC configuration design
  • GKE security hardening standard
  • Terraform modules implementing the agreed controls
  • Compliance control mapping

What this covers

The specific capabilities available under this service. Engagements usually draw on a subset — we scope to the problem, not the catalogue.

Architecture & policy

  • GCP security architecture review
  • Organisation, folder and project hierarchy design
  • Organisation policy constraints
  • CIS GCP Benchmark assessment
  • Landing zone design
  • Resource labelling and ownership model

Identity & access

  • IAM least-privilege design
  • Custom role engineering
  • IAM conditions and policy analysis
  • Workload Identity Federation
  • Workload Identity for GKE
  • Service account key elimination
  • Cloud Identity and SSO integration
  • Secret Manager and Cloud KMS / CMEK

Network security

  • Shared VPC and subnet design
  • Firewall rule review and hardening
  • VPC Service Controls perimeters
  • Private Google Access / Private Service Connect
  • Cloud Armor and load balancer security
  • Egress control and Cloud NAT

Detection & workloads

  • Security Command Center configuration and tuning
  • Cloud Audit Logs and log sinks
  • Log-based metrics and alerting
  • SIEM integration
  • GKE security hardening
  • Binary Authorization and Artifact Registry
  • Cloud posture management (CSPM)
  • Vertex AI and BigQuery data protection

Who this is for

  • Product and platform teams running workloads on Google Cloud
  • Organisations migrating to GCP or expanding an existing footprint
  • AI and data-heavy teams using Vertex AI, BigQuery and GKE
  • Companies preparing for SOC 2 or ISO 27001 on Google Cloud
  • Teams that need service account keys out of their pipelines

Recognise your situation? A 30-minute discovery call is the fastest way to find out whether this is the right engagement.

Book a security consultation

Common questions

How do we get rid of service account keys without breaking CI?

Incrementally. We inventory every key and its consumer, migrate workloads to Workload Identity Federation or GKE Workload Identity one consumer at a time, monitor for authentication failures, then disable key creation at the organisation policy level once the estate is clean.

Are VPC Service Controls worth the operational cost?

For environments holding regulated or high-value data, usually yes — they are one of the few controls that meaningfully limits data exfiltration. They do need careful perimeter design and a dry-run period, which is exactly what we plan for rather than enabling them blind.

Do you have hands-on GCP production experience?

Yes. Our practice includes ongoing work securing cloud-native platforms on Google Cloud — SecOps, DevSecOps, compliance automation and incident response for a production AI-powered product platform.

These engagements are often scoped together — the underlying risks overlap.

Cloud Security

AWS Security

Secure AWS architecture, least-privilege IAM, detection with GuardDuty and Security Hub, and posture management that keeps multi-account estates defensible as they grow.

Cloud Security

Kubernetes & Containers

Cluster hardening, workload isolation, admission control, image supply-chain integrity and runtime detection for EKS, GKE, AKS and self-managed Kubernetes.

DevSecOps & AppSec

DevSecOps

Build security into the delivery pipeline instead of bolting it on at the end — secure SDLC, CI/CD hardening, IaC scanning, supply-chain controls and guardrails engineers will actually keep.

Discuss your security challenges

Tell us what you are trying to secure and where it hurts. We will tell you what we would do first, whether or not you engage us.