Skip to content
Second Key Security

Security Program Assessment

A two-week review of identity, cloud, and your key SaaS apps, plus a snapshot of shadow IT and AI tools. You get prioritized findings and a plan.

Fixed scope and fixed fee, agreed in writing before we start.

What we review

  • Identity

    Who has access to what across your identity provider, and where it does not match their role.

  • Cloud

    How your cloud accounts are configured, checked against your controls.

  • Key SaaS apps

    Admin access and security settings in the apps your business runs on.

  • Shadow IT and AI snapshot

    The apps and AI tools your team uses that nobody approved.

What you get

  • A two-week review of controls across your identity provider, cloud, and key SaaS apps
  • A shadow IT and AI app snapshot
  • Prioritized findings
  • A recommended plan and services

Access we need

  • A read-only admin role in your identity provider, for example Read-Only Administrator in Okta or Global Reader in Microsoft Entra ID
  • Read-only security audit roles in your cloud accounts, for example the AWS SecurityAudit policy
  • Read-only admin access to your key SaaS apps

Everything is read-only, and you can revoke it the day the review ends.

What we need from you

A person on your team who can create read-only access and approve changes.

How the two weeks run

  1. Step 1: Kickoff and scoping call

    We agree on scope and the systems to include.

  2. Step 2: You create read-only access

    Roles you define, scoped for the review.

  3. Step 3: Review and expert analysis

    Agents run the checks, and an expert analyzes every finding.

  4. Step 4: Findings walkthrough

    We walk you through the findings and the recommended plan.

Book your assessment

Email us to set up the kickoff and scoping call, or book a short intro call first.