04 · Security Testing
Cloud Security Assessment
Find the misconfiguration before a scanner on the internet does.
A configuration and architecture review of your cloud estate, identity and access, network boundaries, storage and secrets, logging and detection, container and serverless workloads, benchmarked against CIS and provider best practice, then prioritized by exploitability.
The context
Why this matters
Cloud breaches are rarely exotic. They are an over-permissive role, a storage bucket that drifted public, a secret in an environment variable, a management port open to the internet, or logging that was never enabled on the account that mattered.
We review the estate as an attacker would map it: what is reachable from outside, what an initial foothold escalates into, and what a compromised CI pipeline or developer laptop could reach. That is a different exercise from running a CSPM scan and exporting the findings list.
The output is a prioritized remediation plan with infrastructure-as-code changes where we can express them that way, so fixes land in your repository rather than as manual console clicks that drift back within a quarter.
Platform coverage
Every platform, assessed for what actually breaks on it.
The failure modes differ by provider. So does our checklist.
Amazon Web Services
The deepest surface we test. IAM is where AWS environments quietly go wrong, and it is almost never a single bad policy. It is a chain.
Full AWS assessment guideWhat we find most often
A CI role assumable from an unrestricted GitHub OIDC condition, chaining into production admin.
Assessed surfaces
- IAM roles, policies, trust relationships & privilege escalation paths
- S3 bucket policies, ACLs, Block Public Access & pre-signed URL handling
- VPC design, security groups, NACLs & internet-facing exposure
- KMS key policies, Secrets Manager, SSM Parameter Store
- CloudTrail coverage, GuardDuty, log integrity & retention
- EKS RBAC, ECS task roles, Lambda execution permissions
- CodeBuild / CodePipeline permissions & OIDC trust from CI
What is covered
Scope of the engagement
- 01
Identity & access management
Role and policy review, privilege escalation paths, cross-account trust, federation and SSO configuration, service account sprawl, and unused credentials.
- 02
Network exposure
Internet-facing surface, security group and firewall rules, VPC and subnet design, load balancer and WAF configuration, private connectivity, and management-plane access.
- 03
Data protection
Storage permissions and public access controls, encryption at rest and in transit, key management and rotation, secrets handling, backup integrity and restore testing.
- 04
Logging & detection
Audit trail coverage and retention, log integrity, alerting on high-risk actions, and whether anyone would actually notice a compromise in progress.
- 05
Workload security
Container images and registries, Kubernetes RBAC and network policy, serverless permissions and runtime configuration, and host-level hardening.
- 06
CI/CD & supply chain
Pipeline permissions, build-time secret exposure, artifact integrity, dependency and base-image hygiene, and who can push to production.
What you receive
Deliverables
Everything below is included in the fixed price. Nothing here is an upsell discovered halfway through.
- Prioritized findings report with cloud-native reproduction detail
- Attack-path analysis showing what a foothold escalates into
- CIS Benchmark and provider best-practice conformance summary
- Infrastructure-as-code remediation snippets where applicable
- Logging and detection coverage gap assessment
- Architecture recommendations for the next stage of growth
Questions
Cloud Security Assessment FAQ
We work from read-only audit access, a scoped role with security-audit permissions in AWS, Reader plus Security Reader in Azure, or the equivalent in GCP. No write access, no changes made by us. Where policy prohibits third-party access we can run our collection scripts with your engineer driving.
A CSPM tool tells you a control is non-conforming. It does not tell you that this particular role, combined with that particular trust relationship, lets a compromised build runner assume an admin role in the production account. We do the chaining, the prioritization and the architecture judgement a tool cannot.
No. We assess AWS, Azure and GCP, and we specifically look at the seams between them, federated identity, cross-cloud data flows, and inconsistent controls where one provider's defaults quietly differ from another's.
Often paired with
ISO 27001 Certification
End-to-end ISO 27001 implementation: gap analysis, ISMS build, evidence and audit support, right through Stage 2.
Read more02SOC 2 Readiness
Type I and Type II readiness: control design, evidence discipline and auditor coordination, without the busywork.
Read more03Penetration Testing
Manual testing of web apps, APIs, mobile clients and authentication flows, with a report your engineers can act on.
Read moreKnow exactly what an auditor, and an attacker, would find.
Tell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.
No sales sequence. A scoping call and a written proposal cost nothing.