What we deliver
Twara Technologies assesses, designs and implements the security controls that sit on the customer’s side of the cloud. In its shared responsibility model, AWS describes itself as responsible for security of the cloud, while the customer is responsible for security in the cloud, including guest operating systems, applications, data, encryption choices and access permissions. Other providers draw the line in a similar way. Our work makes sure every item on your side of that line is configured well, monitored and owned.
Typical scope
- Account and organisation structure, with separation between production, non-production and security tooling.
- Identity: federation with your directory, multi-factor authentication, role design, privileged access and periodic access reviews.
- Network: segmentation, private connectivity to managed services, controlled internet exposure and web application firewalls.
- Data: encryption, key management, secrets, backup protection and controls against public exposure of storage buckets.
- Workloads: operating system and container hardening, vulnerability scanning and patch status.
- Logging and detection: audit trails, centralised log storage, alerting on high-risk events and integration with your security team’s tools.
- Compliance mapping and evidence collection.
Technologies we work with
- Native security services: AWS Security Hub, GuardDuty and IAM Access Analyzer; Microsoft Defender for Cloud and Azure Policy; Google Security Command Center. These are usually the most efficient starting point because they understand each provider’s services in depth.
- Policy as code: AWS Service Control Policies, Azure Policy and Google Organization Policy for preventive guardrails; Open Policy Agent or Checkov to check infrastructure code before it is deployed.
- Hardening benchmarks: the CIS Benchmarks, consensus-based configuration recommendations covering the major cloud providers and operating systems, are our usual reference for baselines.
- Secrets and keys: provider key management and secrets services, or HashiCorp Vault for multi-cloud estates.
- Scanning: container image and dependency scanners such as Trivy, integrated into pipelines.
How we approach it
- Scope and context. Understand which systems and data matter most, which frameworks you report against and what your threat concerns are.
- Assess. Review configuration with native tools and benchmark checks, then validate the significant findings by hand. Automated scanners produce noise; judgement turns it into a useful list.
- Prioritise. Rank findings by exposure and impact. Publicly reachable weaknesses and over-privileged identities usually come first. Security misconfiguration is ranked second in the OWASP Top 10:2025, a reminder that configuration deserves as much scrutiny as code.
- Remediate. Fix issues through infrastructure as code wherever possible so the fix is permanent, reviewed and repeatable.
- Prevent and detect. Add guardrails that stop the same issue reappearing and alerts that catch what guardrails cannot.
- Sustain. Schedule periodic reviews, keep the control mapping current and rehearse incident response.
Quality and security
- Indian regulatory context. CERT-In’s Directions of 28 April 2022 require covered organisations to report specified cyber incidents within 6 hours of noticing them, keep ICT system logs for a rolling 180 days within Indian jurisdiction and synchronise clocks with NIC or NPL time sources or servers traceable to them. We design logging, retention and response runbooks so that these obligations can be met, and confirm applicability with your advisers.
- Changes through code. Security fixes are applied via reviewed infrastructure code, not one-off console edits that can drift back.
- No standing super-users. Administrative access is time-limited, approved and logged wherever the platform allows.
- Independent verification. We encourage independent testing and audits, and support you through them.
- Honest reporting. Findings are reported plainly, including residual risks you choose to accept, so decisions are recorded.
What we need from you to start
- An overview of your cloud accounts or subscriptions, and which ones hold production and sensitive data.
- Read-only access for the assessment, granted through roles you control.
- The frameworks, customer requirements or regulations you need to demonstrate compliance with.
- A security or IT contact who can make decisions on risk and approve changes.
- Any previous audit reports, penetration test results or known issues.
Engagement options
- Security posture assessment: a fixed-scope review with a prioritised remediation plan.
- Remediation and hardening: Twara Technologies implements the plan, guardrails and logging.
- Compliance readiness: control mapping and evidence collection ahead of an external audit.
- Ongoing security operations: periodic reviews and monitoring as part of managed cloud operations.
Contact us to arrange a review of your cloud security.