Fixed-scope cloud health check

Know what your cloud is really costing you, and where it is quietly exposed.

A structured review of your cloud estate across cost, licensing, resilience, access and governance, turned into a clear picture of where money is leaking, where risk sits and what to fix first.

Fixed scope Senior-led Vendor-neutral Delivered in weeks
What this review is

A clear view of your cloud, before you spend more on it.

Most organisations do not have a cloud problem so much as a visibility problem. Spend creeps up, environments sprawl, recovery is assumed rather than tested, and no one has a single, current picture of whether the estate is delivering value.

Not a migration pitch dressed up as a review. This review is designed to give you clarity and control, not to push you into a rebuild or a new platform you do not need.

The Cloud Health Check gives you that picture. We examine usage and spend, Microsoft 365 and Azure licensing, backup and recovery readiness, security and access, and the way the environment is governed day to day.

The aim is to identify where money is being wasted, where exposure sits, what is already working, and what deserves attention first.

It is independent and commercially grounded. The output is not a generic cloud checklist, it is a practical decision view for leaders who need control before more cloud spend. Cloud security is examined here as part of the cloud environment; a broader view across identity, endpoints, email and response readiness is a separate engagement, the Security Posture Review.

What the review covers
01

Spend and licensing

Usage, licences, dormant accounts, duplicated services and avoidable cost signals.

02

Resilience and recovery

Backup coverage, restore confidence, continuity assumptions and recovery priorities.

03

Security and access

Privileged access, user lifecycle, cloud permissions and control visibility.

04

Governance and ownership

Decision ownership, environment structure, reporting clarity and action accountability.

Who it is for

Built for organisations whose cloud has grown faster than their control of it.

This is for teams that need clarity before renewal, leadership scrutiny, budget approval, recovery planning or wider cloud investment.

01

Your cloud bill keeps climbing

Costs have crept up month after month, and no one can fully explain what you are paying for or whether you still need all of it.

02

You inherited a messy estate

Licences, tenants, services and access were set up by different people over time, and the whole thing now needs a clear, current view.

03

A renewal or board question is coming

A contract renewal, audit or leadership question about cloud cost means you need to know where you stand before someone else asks.

A common starting point

When the estate was built by different people at different times.

Nobody sets out to create this. Licences, tenants and access accumulate through reasonable decisions taken by different people, in different roles, at different times — and the whole picture stops being held in any one place.

01

Licences

Subscriptions added for a project or a new starter, never revisited when the need changed.

02

Tenants

More than one tenant, or one created for a reason nobody now remembers, still carrying live services.

03

Services

Platforms and connected apps enabled over time, with no single list of what is running or why.

04

Access

Admin rights granted for good reasons, by and for people who have since moved on, and not reviewed since.

05

Backup and recovery

Backups configured at some point and assumed to work, without anyone testing what a restore would actually involve.

06

Ownership

Responsibility sits across several people and providers, so no one holds the whole picture and decisions wait.

Review process

How the review works.

The review is structured, low-disruption and focused on decisions. The goal is to show where cost, risk and ownership need attention first.

01

Map the estate

We review your cloud platforms, usage, spend, access and recovery setup across Microsoft 365, Azure and connected services. You get one current picture instead of fragments.

02

Assess cost, risk and resilience

We identify waste, exposure, weak recovery and access gaps, then rank them by real business impact. You see what matters, not just what is technically wrong.

03

Deliver the Cloud Control Snapshot

You receive a prioritised action plan showing where to cut cost, where to strengthen resilience, who owns each decision and the practical next steps.

What you receive

A Cloud Control Snapshot, not a cloud bill you still cannot explain.

The review produces a single, clear deliverable that turns technical and commercial findings into decisions: spend reviewed against value, recovery confidence assessed, access and security flagged, and a practical action plan with owners and next steps.

Sample review output

Cloud Control Snapshot

Review type Fixed scope Status Decision ready Focus Cost and control
Cloud indicators Estate view
Spend clarity 68%
Licence fit 74%
Recovery confidence 62%
Open priorities 6 items
Priority findings Action
High
Unused licences still active Review dormant users, duplicated subscriptions and role fit.
Licence review
First priority
Medium
Recovery evidence is incomplete Backup presence does not yet prove recovery confidence.
Recovery check
Next cycle
High
Privileged cloud access needs review Confirm admin roles, access lifecycle and ownership.
Access review
First priority
Senior review note Decision view
Cloud health check

Focus next on licence waste, recovery evidence and privileged access before expanding services or committing to a migration.

Spend view Prioritised

Cloud costs grouped by value, waste signals and practical reduction opportunities.

Recovery focus Actionable

Backup, restore confidence and continuity assumptions reviewed clearly.

Action plan Next steps
01 Confirm licence usage and dormant accounts Priority
02 Validate backup and recovery evidence Next
03 Review privileged access and ownership Next
04 Define cloud cost and control rhythm Planned
Scope boundaries

What this health check is not.

Being clear about the edges makes the engagement more useful. If what you need is one of the things below, we will say so and point you to the right route.

PT

Not a penetration test

We do not attempt to exploit systems or applications. The health check examines how the environment is configured, owned and governed, not whether it can be broken into.

AU

Not a formal or accredited audit

SoftExponent is not an audit body, and this is not an audit carried out under an accreditation scheme.

AZ

Not an Azure certification assessment

It does not assess your environment against a certification standard and it does not produce a certification result.

MS

Not a Microsoft-affiliated assessment

This is an independent SoftExponent engagement. It is not endorsed by, certified by, or delivered on behalf of Microsoft.

GS

Not a guaranteed-savings exercise

It shows where spend may not be matching value. It does not promise a reduction, and any saving depends on the decisions you take afterwards.

Scope and pricing

Fixed scope. Clear price. No open-ended engagement.

The Cloud Health Check is designed to give you a clear starting point without committing to a migration, remediation project or larger cloud programme before you know what matters.

Fixed-scope engagement
From £1,250

Suitable for most organisations up to around 50 users or a single-tenant estate. Larger, multi-tenant or multi-platform environments are scoped after a short conversation.

We examine spend, licensing, backup, recovery, access and governance across the current cloud estate.

You receive a Cloud Control Snapshot with cost signals, priority findings and practical next steps.

The walkthrough translates cloud findings into plain English so leadership can see what to cut, strengthen or review first.

i

Cloud consumption, third-party licences, remediation and migration work are quoted separately where needed.

Buyer questions

Questions buyers ask before a cloud health check.

The review is intended to be clear before it starts: what happens, what access is needed, and what you receive at the end.

The fixed-scope review covers most estates up to around 50 users or a single tenant. Larger or multi-tenant environments are scoped after a short conversation, with a clear price before any work starts.

No. The review runs alongside normal operations using appropriate read-only access wherever possible. Nothing is changed or reconfigured without your agreement.

Most reviews are completed within two to three weeks of starting, depending on the size and complexity of the estate and how quickly access and information can be provided.

You decide. The action plan is yours to act on however you choose: internally, with SoftExponent, or with another provider. There is no obligation to continue.

Often, but it is not a savings guarantee and we will not present it as one. The health check shows where spend and licensing may not be matching value, so those decisions can be made on evidence rather than assumption. What the findings are worth depends on which of them you act on.

Security and access is one of the four lenses, alongside spend and licensing, resilience and recovery, and governance and ownership. It looks at how the cloud environment is secured and who can get into it. For a broader picture across identity, endpoints, email, cloud security and response readiness, that is a separate engagement: the Security Posture Review.

We work with appropriate read-only access wherever possible, and we tell you exactly what is needed before anything starts. Nothing in your environment is changed or reconfigured without your agreement.

The starting point is whatever estate you already have. Microsoft 365 and Azure are the most common, and the health check also covers AWS, Google Cloud and connected platforms where they form part of the estate. Tell us what you run and scope is confirmed before any work starts.

Next step

Start with a clear picture, not a bigger invoice.

Before you renew a contract, add more licences or commit to a migration, get an independent, senior-led picture of what your cloud actually costs and where it is exposed.

← Explore all cloud capabilities

Configure your Cloud Health Check

Answer a few straightforward questions and we'll help shape the right review. You don't need to know all the technical details.

I'm not sure what I need — Request scope review

What cloud services does your business use?

If you're not sure, choose "Not sure" and we'll help.

Does your cloud environment have specialist regulatory, compliance or assurance requirements?

This means requirements beyond an ordinary small or medium business - for example where an external body expects a deeper specialist assessment. If none of that applies, or you're not sure, just say so and we'll pick it up together.

Would you like any deeper reviews?

All optional. The core review is complete on its own.

Need help? Request scope review