Bringing in an outside firm to scan your cloud looks, at first glance, like handing over
the keys. Done properly, it's the opposite — and it's worth seeing why, because it's the
template for every other arrangement:
- They get read-only access, which you created and can delete.
- The findings are about your account, and they arrive in your hands.
- When it's over, you remove the access and nothing of yours went anywhere.
Expert work, delivered, with ownership never moving. That's the shape to look for. If a
vendor's version of the same service requires an administrator key "so we can fix things
for you," you've been offered something different wearing the same name.
Here's one finding such a check-up turns up more than any other, and it costs nothing to
go look for yourself: credentials that outlived the service
they were made for. A contractor's access from a project that ended. A key issued
for a migration two years ago. The service was switched off; the key never was. If you
have a cloud account, ask whoever runs it for a list of credentials sorted by when they
were last used, and ask what the unused ones are still for.