Advice on thinking from a red team perspective

Currently working with a company on their IT system. Their system is comprised mostly of chained-together APIs from various SaaS/PaaS providers, and this system operates almost the entire company. The company does own and operate workstations for the employees, mostly Mac machines, but the company does not operate any in-house servers and relies instead on the cloud providers. I'd like to consider where the company should harden their operations. Any thoughts on where to start? Or where would Red team start?
Was this page helpful?