package/gcp-architecture-security-review
GCP Architecture & Security Review
An independent read of what you actually have, ranked by what would hurt most, with working Terraform for the fixes at the top of the list.
~$18,000
Starts with Discovery & Scoping
Floors reflect typical engagements. Larger, regulated, or multi-region estates are scoped and quoted after Discovery.
Where this usually starts
Something prompted this. A penetration test came back worse than expected. An enterprise customer sent a security questionnaire with forty questions your team cannot answer in writing. A new CISO asked who has project owner, and nobody knew until they ran the query.
The underlying condition is usually the same. The estate grew one project at a time, each one provisioned by whoever needed it, and no single person now holds the whole picture. Security Command Center is switched on and reporting thousands of findings that nobody triages, because triaging them would take a month and there is no month available.
What makes this hard to fix internally is not skill. It is that the people who built the estate cannot see it fresh, and the people who could see it fresh do not have the context. An external review is worth paying for precisely because the reviewer has no attachment to the decisions being reviewed.
What gets assessed
The review works against the Google Cloud architecture framework, but the output is not a framework score. It is a list of specific things in your estate, each one with a project, a resource, and a fix.
- IAM and organization policy. Who holds primitive roles, where service accounts have been granted more than they use, which org policy constraints are unset, and where a folder-level binding is quietly granting production access to a sandbox group.
- Network topology and VPC Service Controls. Shared VPC structure, peering, egress paths, and whether service perimeters exist around the data that would matter in a breach. Perimeters in dry-run mode that were never enforced are a common finding.
- KMS and secrets. Key rotation, separation between key admin and key user, and whether secrets sit in Secret Manager, in environment variables, or in a repository.
- Security Command Center. Existing findings triaged into a ranked list rather than an export. Most estates have a large volume of low-value findings obscuring a small number that matter.
- Workload Identity. Where workloads still authenticate with downloaded service account keys, and what it would take to remove them.
- External exposure. Public buckets, unauthenticated endpoints, load balancers without Cloud Armor, and any resource reachable from the internet that nobody remembers creating.
- AI workload security. Where Vertex AI endpoints sit in the network, how they authenticate, and whether Model Armor policies filter prompts and responses on the paths that carry customer data.
What you get at the end
Three artefacts. A findings report where every item carries a severity, an affected resource, and an explanation of the actual exposure rather than a generic control description. A remediation plan sequenced by risk reduction per unit of effort, because the order matters more than the list. And Terraform for the fixes at the top — not pseudocode, not a recommendation to write Terraform.
The report is written to be read by two audiences without being written twice. The findings are technical enough for the engineer who has to act on them. The summary is direct enough to forward to a board without translation.
Where this review stops
This package assesses. It does not build. That boundary is deliberate: a reviewer who is also bidding to implement every finding has an incentive problem, and you should be suspicious of one who does not name it.
Remediation beyond the top-fix Terraform is a separate engagement, quoted separately, and you are free to have your own team do it or hire someone else. Application-layer security — code review, dependency analysis, business logic — is out of scope; this is an infrastructure review. Compliance certification is out of scope entirely. The findings support a SOC 2 or ISO audit, but Sumech is not an auditor and does not issue attestations.
Deliverable. Severity-ranked findings report, remediation plan, and Terraform for the top fixes.
How the engagement runs
- Week 0 Discovery & Scoping Three to five days establishing estate size, project count, and which parts are in scope. Produces the fixed quote for the review itself.
- Week 1 Read-only access and inventory Organization-level viewer and security reviewer roles. Automated inventory across projects, then a first pass at org policy and IAM. No changes are made to your estate at any point in this engagement.
- Week 2 Depth passes Network topology and perimeters, KMS and secrets, Workload Identity, external exposure. Interviews with the engineers who built the parts that look unusual, because unusual is often deliberate and the reason matters.
- Week 3 Triage and ranking Security Command Center findings triaged against what the inventory showed. Severity assigned on real exposure in your topology, not on the default score.
- Week 4 Report, Terraform, walkthrough Findings report and remediation plan delivered, Terraform for the top fixes handed over, and a working session with your engineers to walk the list. Questions after handover are answered; that is not billed.
These figures are starting points, not quotes. Final pricing depends on the size and complexity of your estate and is fixed in writing at the end of Discovery & Scoping.
What this engagement does not cover
Named here rather than discovered later. This is the list that makes the fixed price hold when scope starts moving.
- remediation implementation
- application-layer security
- compliance certification
What this is based on
- Google Cloud Professional Security Engineer and Professional Network Engineer, two of five Professional-tier Google Cloud certifications held.
- Estates reviewed at the scale of a national logistics operator running 2,000+ VMs across multiple regions.
- Remediation Terraform written against the same module patterns used to deliver enterprise landing zones.
What buyers ask
Do you need write access to our production environment?
No. The review runs entirely on read-only roles — organization viewer, security reviewer, and folder-level viewer where the org is segmented. Nothing in your estate is modified. If a finding needs a proof of exposure, it is described rather than demonstrated against production.
We already run Security Command Center. What does this add?
Security Command Center tells you what is wrong. It does not tell you which four things to fix this quarter, and it has no view of your architecture, so it cannot tell you that a medium-severity finding in one project is actually critical because that project holds the shared VPC.
The review is mostly the work of ranking. Most estates come in with a large backlog of open findings; what comes out is an ordered list where the top items are the ones that reduce real exposure.
Can you fix what you find?
Terraform for the top fixes is included. Everything beyond that is a separate engagement, scoped and quoted after the review, and you are under no obligation to buy it. Many clients hand the remediation plan to their own team and use it as a quarter of platform roadmap.
If you do want the remediation delivered, the Landing Zone and Automation packages are usually where it lands, depending on whether the finding is structural or delivery-process.
How much of our engineers’ time does this take?
Roughly four to six hours total across the engagement, concentrated in week two. One kickoff, two or three short interviews with whoever built the unusual parts, and one walkthrough at the end. The inventory and analysis work does not need your team present.
Does the Model Armor review mean you build AI platforms?
No. It means AI workloads are assessed the same way anything else in the estate is assessed: where the endpoints sit, how they authenticate, what reaches them, and whether prompt and response filtering is configured on the paths that carry sensitive data. That is a security review of infrastructure that already exists. Building AI or agent platforms is not something Sumech sells.
Questions about pricing, terms, and ownership across every engagement are on the FAQ.
Start with Discovery & Scoping
$4,500 fixed, 3–5 days. A current-state review, a gap analysis, a written scope, and a fixed quote for this engagement. Half the fee is credited against the work if you proceed within 60 days.