JJC SystemsBook a Consultation
Azure · Audit

Cloud workload security review

Twenty checks on an Azure workload holding patient data, covering network, identity, keys and the evidence an auditor will ask for.

Why run this

What this checklist is for

Cloud workloads holding patient data accumulate configuration drift the way any estate does, and the drift is invisible until somebody audits it or exploits it.

Most of the items below are cheap to fix and expensive to have missed. Run this per workload rather than across the estate, so the findings are actionable.

Run it with

CIO or CISO

And with

Cloud architects and security engineers

And with

Privacy officer

0 of 0 complete · 0%
The checklist

20 checks, in the order we would run them

Tick only what you can genuinely evidence today. An item you intend to do is not an item you have done, and scoring yourself generously here only produces a comfortable number and an uncomfortable project.

Section 1

Network exposure

The surface an attacker reaches first.

Section 2

Identity and access

Where most real intrusions progress.

Section 3

Data protection

What determines the severity if something does go wrong.

Section 4

Evidence and monitoring

Whether you could demonstrate any of the above in six months.

What your score means

Read this against the number above

These bands are deliberately blunt. The middle band is where most organizations honestly sit, and it is a perfectly reasonable place to proceed from — provided the gaps are written down with owners rather than carried as optimism.

0–59%Significant gaps

Do not proceed yet. More than four in ten items are unaddressed, and the ones that fail here are usually the foundational ones that make everything after them harder.

60–84%Mostly ready, with known gaps

Proceed on a defined scope, with the outstanding items written into the plan as risks with owners and dates. This is the most common honest position.

85–100%Ready

The remaining gaps are small enough to handle during delivery rather than before it. Confirm the unticked items are genuinely minor rather than simply unexamined.

Your score highlights automatically as you tick items above. Nothing is saved, sent or tracked — refreshing the page clears it.

Closing the gaps

If you could not tick these, start here

The four items below are the ones whose absence causes the most trouble downstream. If your unticked items include any of these, they are worth addressing before the rest.

Public network access enabled

Address this first. It is the highest-severity common finding and usually a configuration change rather than a project.

Stored credentials in configuration

Move to managed identities. This removes a whole class of credential leak and is straightforward for most services.

Diagnostic settings configured manually

Convert to policy. Manual configuration covers what existed on the day somebody did it and nothing created since.

No control mapping

Build it. This is the document that turns a two-week audit scramble into an afternoon.

Want a second opinion on your score?

We will run this review against one workload and produce a prioritised remediation plan mapped to your specific regulatory obligations.

Talk through your result Read the related guides We reply to every message within one business day.
Keep going

Related checklists

defender
healthcareReadiness

Ransomware readiness checklist

Twenty checks framed around the only question that matters in a provider organization: how long can you deliver safe care without systems?

May 23, 2026 · 20 checksOpen
Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.