This guide is general information and does not replace a scoped technical, security, legal, financial, or compliance assessment.
What to examine
- Who can access critical systems and how is access reviewed?
- Is multi-factor authentication enforced?
- Which resources are internet-accessible and why?
- How are data and secrets encrypted?
- Are logs collected, retained, and monitored?
- How are vulnerabilities and configuration drift addressed?
- Can backups be altered by compromised production credentials?
- When was recovery last tested?
What to do next
Good security questions create ownership and evidence. Avoid absolute claims; ask how controls are designed, monitored, tested, and improved.
Recommended next step
Run a structured discovery and cloud readiness assessment before selecting target services or committing to a migration schedule.