Cloud security assessments for AWS, Azure and Google Cloud
A review of how your cloud is configured, and a test of what an attacker could do with it. We look for the small misconfigurations that turn one leaked key into access to everything.
Cloud breaches are rarely clever
Cloud breaches rarely involve breaking anything. They involve a storage bucket left public, an access key committed to a code repository, or an identity with far more permission than it needs. Each is a small mistake. Together they make an attack path.
Configuration scanners list hundreds of issues and call most of them urgent. We combine a configuration review with hands-on testing, so you learn which issues really chain into a breach and which can wait.
What we test
Identity and access
IAM roles and policies, privilege escalation paths, unused and long-lived keys, cross-account trust and federation.
Storage and data
Public or over-shared buckets and blobs, snapshots, backups and database exposure.
Network controls
Security groups, firewall rules, public endpoints and private connectivity.
Workloads
Virtual machines, containers, Kubernetes and serverless functions, including metadata service abuse and secrets in environment variables.
Logging and detection
Whether the activity an attacker would generate is recorded, and whether anyone would be alerted.
Microsoft 365 and Entra ID
Conditional access, MFA coverage, guest access, application consents and privileged roles.
How the engagement runs
Read-only access
You grant a read-only audit role in each account, subscription or project. We never need standing write access.
Configuration review
We review configuration against CIS Benchmarks and provider guidance, and map identities and trust relationships.
Attack path testing
From agreed starting points, such as a leaked key or a compromised workload, we test how far an attacker could get.
Report and retest
Prioritised findings with the policy or setting to change, the report within five working days, then a retest.
What you get
- Attack paths drawn from a realistic starting point to your most sensitive data.
- Configuration findings by service, each with the exact setting to change.
- A short list of fixes that remove the most risk.
When to commission it
- After migrating workloads to the cloud or adding a new provider.
- When infrastructure is built by several teams or suppliers, each with their own accounts.
- After an incident involving leaked keys or credentials.
- Yearly, with internet-facing cloud assets watched continuously on the platform.
Questions we get asked
Is this a configuration review or a penetration test?
Do we need permission from AWS, Microsoft or Google?
Which platforms do you cover?
What access do you need?
Related
Infrastructure and networks
External and internal network penetration testing, including Active Directory. See how far an attacker could get from the internet or inside your network.
Read more →Attack surface management
Continuous external attack surface management. Discover every internet-facing asset, including shadow IT, and get alerted to new exposures as they appear.
Read more →Web applications and APIs
Manual web application and API penetration testing. We find the authentication, access control and business logic flaws that automated scanners miss.
Read more →SavountEnhancing Cloud Security: A Multi-Layered Approach
How attackers exploit cloud storage, web applications and deployments, and a layered approach to securing them, from zero trust to data security.
Read the article →