Cloud penetration testing.
Your provider secures the cloud. You are responsible for what is in it. We test identity, exposure and blast radius across AWS, Azure and GCP, and we do it against your actual configuration rather than a checklist.
At a glance
- Typical duration
- 1 to 2 weeks per platform
- Platforms
- AWS, Azure, GCP
- Approach
- Configuration review plus authenticated exploitation
- Also covers
- Kubernetes and containers on request
- Retest
- Included
What we look for.
Cloud breaches rarely involve a provider vulnerability. They involve a role that can assume another role, a storage bucket that was public for one afternoon, or a build pipeline with permissions nobody audited. We map the identity graph and show you the paths through it.
What we test.
What you receive.
Risk posture in plain language for leadership and the board, with the two or three things that actually matter.
Severity, proof-of-concept evidence, reproduction steps and specific remediation, written for the engineer who has to fix it.
Findings mapped to SOC 2, ISO 27001, PCI DSS and HIPAA controls so your auditor can use the report directly.
A shareable letter confirming scope, dates and outcome, reissued free after we verify your fixes.
Who needs this.
- Teams that grew their cloud estate faster than their governance
- Anyone preparing for SOC 2 or ISO 27001 with cloud-hosted production
- Businesses handling regulated data in managed services
- Organisations after a cloud migration or a major re-architecture
- Companies with multiple accounts, subscriptions or projects and no central review
Frequently asked.
Do you need production access?
We need read-level access for configuration review and a scoped role for exploitation testing. We define exactly which permissions we need at scoping, and the role is time-limited and revoked at the end of the engagement.
Is this the same as a cloud security posture scan?
No. A posture scan tells you a policy is over-permissive. We show you the chain: this role can assume that role, which can read that bucket, which contains those credentials. Impact is the difference.
Do we need permission from AWS, Azure or GCP?
The major providers permit testing of your own resources under their published policies, with some exceptions such as denial-of-service. We confirm the current rules for your services during scoping.
Can you test our CI/CD pipeline?
Yes, and we recommend it. Build systems typically hold the most powerful credentials in the estate and receive the least scrutiny.
Related services.
The perimeter is one phishing email deep. We test what an attacker reaches from outside, and separately what they achieve once they are already inside.
SVC 02API TestingYour mobile app and your single-page front end are just API clients. The API is the real target, and it is usually tested least. We test REST, GraphQL and the authorisation logic underneath both.
CMP 04FedRAMPThe authorisation US federal agencies require before they can use your cloud service. It is the most demanding programme we support, and we will tell you honestly whether the market opportunity justifies it.
Ready to find out what an attacker would find?
Tell us about your environment and we will come back with a scoped quote and a start date. No discovery-call marathon, no obligation.