Service · Cloud · SVC-04

Cloud Penetration Testing.

AWS, Azure and GCP environment audits - IAM, networking, workloads and CI/CD pipelines. Identity-first, because that is where modern breaches start.

2–3 weeks Fixed quote Manual-first methodology
AWS · Azure · GCP
All three hyperscalers
IAM-first
Privilege-boundary focus
14 days
Typical delivery
Methodology

Three approaches. One uncompromising standard.

Choose the depth of engagement that matches your risk profile and reporting needs.

Configuration

Configuration review

A read-only audit of your cloud environment against the CIS Foundations Benchmark and vendor best-practice baselines. No active exploitation.

  • CIS Foundations Benchmark coverage
  • Misconfiguration & public exposure
  • IAM policy & SCP review
  • Logging & monitoring coverage
Threat-led

Threat-led assessment

Live testing simulating an adversary with low-privilege access. We chain misconfigurations into privilege escalation and lateral movement.

  • Initial access & recon
  • Privilege escalation paths
  • Lateral movement across accounts
  • Data exfiltration validation
White Box

White-box review

Architecture-aware deep dive with full diagrams, IaC, and IAM policies available. Best coverage and signal-to-noise on remediation.

  • Architecture & trust-boundary review
  • IaC (Terraform/CDK) security review
  • CI/CD pipeline hardening
  • Secrets management review
What we cover

The full surface - tested manually.

01IAM & privilege boundary review
02Misconfiguration & public exposure
03Network & VPC segmentation
04Kubernetes & container security
05Secrets management & KMS
06CI/CD pipeline hardening
Engagement variants

Four ways to scope this service.

AWS

AWS Environment Audit

Multi-account AWS reviews - Organizations, SCPs, IAM, networking and managed services.

  • Organizations & SCP review
  • IAM & AssumeRole chains
  • S3, KMS & data-store exposure
Azure

Azure Environment Audit

Azure subscriptions and tenancy review - Entra ID, RBAC, and resource-group hardening.

  • Entra ID & conditional access
  • RBAC & subscription boundaries
  • Storage & Key Vault exposure
GCP

GCP Environment Audit

Google Cloud project reviews - organisation policies, IAM and workload identity.

  • Organisation & folder policies
  • IAM & service-account hygiene
  • GCS & Secret Manager review
K8s

Kubernetes & Container Security

EKS/AKS/GKE clusters, RBAC, admission control and supply-chain coverage.

  • RBAC & PSA enforcement
  • Image & supply-chain review
  • Network policy & ingress audit
The process

Six clearly-defined phases.

From scoping call to remediated environment - each step has a deliverable, a check-in and a documented owner.

01
Define Scope

Goals, asset inventory, RoE and success criteria.

02
Information Gathering

Recon, fingerprinting and threat modelling.

03
Identification

Vulnerability discovery and validation.

04
Attack & Penetration

Manual exploitation & chain analysis.

05
Reporting

Executive & technical deliverables.

06
Remediation Support

Fix guidance & debrief session.

Why it matters

Outcomes you can measure.

Multi-cloud capability

Same standard across AWS, Azure, GCP.

IAM-first approach

Most cloud breaches start with identity.

Workload-level review

Containers, serverless, managed services.

Architecture-aware

Findings tied to the controls your auditors care about.

What you receive

Deliverables.

Executive summary

Board-ready overview - risk posture, business impact, recommended priorities.

Technical report

Every finding with reproduction steps, evidence, CVSS & business-impact scores.

Remediation tracker

Jira / Linear-ready issue list with severity, owner and acceptance criteria.

Frequently asked

About cloud penetration testing.

Do you need full admin access?
Read-only access is sufficient for most reviews. Some exploitation paths require scoped privileges, agreed in scoping.
Will testing impact running workloads?
No. Cloud reviews are largely read-only; any active testing happens against non-production resources or in pre-agreed windows.
Can you assess CSP Foundations Benchmarks?
Yes - AWS Foundations, Azure Foundations and GCP CIS Foundations are part of our baseline coverage.
Do you test Terraform / IaC?
Yes. White-box engagements include IaC review with policy-as-code checks against your applicable benchmarks.
What about hybrid (on-prem + cloud) environments?
Fully supported. We scope the boundary between the two and test trust paths between identity providers.
SVC-04

Let's scope your cloud penetration testing.

A 30-minute call. A fixed quote within two business days.