SECOMPSSECOMPS
SVC 05

Cloud penetration testing.

Your provider secures the cloud. You are responsible for what is in it. We test identity, exposure and blast radius across AWS, Azure and GCP, and we do it against your actual configuration rather than a checklist.

At a glance

Typical duration
1 to 2 weeks per platform
Platforms
AWS, Azure, GCP
Approach
Configuration review plus authenticated exploitation
Also covers
Kubernetes and containers on request
Retest
Included
01Overview

What we look for.

Cloud breaches rarely involve a provider vulnerability. They involve a role that can assume another role, a storage bucket that was public for one afternoon, or a build pipeline with permissions nobody audited. We map the identity graph and show you the paths through it.

02Coverage

What we test.

Identity and access managementOver-permissive roles and policies, privilege escalation paths, trust relationships, unused credentials and long-lived keys.
Public exposureStorage buckets and blobs, snapshots and machine images, managed databases, load balancers and public endpoints.
Network architectureSecurity group and firewall rules, peering and transit relationships, private endpoint usage, egress control.
Secrets managementSecrets in environment variables, task definitions, build configuration and source repositories.
Serverless and containersFunction permissions and event-source trust, container escape surface, registry exposure and image provenance.
KubernetesRBAC configuration, service account token exposure, pod security, network policy and control-plane access.
Logging and detectionWhether audit logging is on, immutable and actually monitored, and whether our activity generated anything.
Data protectionEncryption at rest and in transit, key management practice, backup exposure and cross-region replication.
03Deliverables

What you receive.

01Executive summary

Risk posture in plain language for leadership and the board, with the two or three things that actually matter.

02Technical findings

Severity, proof-of-concept evidence, reproduction steps and specific remediation, written for the engineer who has to fix it.

03Compliance annex

Findings mapped to SOC 2, ISO 27001, PCI DSS and HIPAA controls so your auditor can use the report directly.

04Attestation letter

A shareable letter confirming scope, dates and outcome, reissued free after we verify your fixes.

04Fit

Who needs this.

  • Teams that grew their cloud estate faster than their governance
  • Anyone preparing for SOC 2 or ISO 27001 with cloud-hosted production
  • Businesses handling regulated data in managed services
  • Organisations after a cloud migration or a major re-architecture
  • Companies with multiple accounts, subscriptions or projects and no central review
05Questions

Frequently asked.

Do you need production access?

We need read-level access for configuration review and a scoped role for exploitation testing. We define exactly which permissions we need at scoping, and the role is time-limited and revoked at the end of the engagement.

Is this the same as a cloud security posture scan?

No. A posture scan tells you a policy is over-permissive. We show you the chain: this role can assume that role, which can read that bucket, which contains those credentials. Impact is the difference.

Do we need permission from AWS, Azure or GCP?

The major providers permit testing of your own resources under their published policies, with some exceptions such as denial-of-service. We confirm the current rules for your services during scoping.

Can you test our CI/CD pipeline?

Yes, and we recommend it. Build systems typically hold the most powerful credentials in the estate and receive the least scrutiny.

Ready to find out what an attacker would find?

Tell us about your environment and we will come back with a scoped quote and a start date. No discovery-call marathon, no obligation.