Cloud penetration testing

We review the configuration of your cloud accounts and test them hands-on.

Testing covers IAM privilege escalation, exposed storage, and paths from a compromised workload to your control plane.

What we test

  • IAM policies, roles, and privilege escalation paths
  • Public exposure of storage, snapshots, databases, and functions
  • Instance metadata, workload identity, and credential exposure
  • Kubernetes and container security (EKS, AKS, GKE)
  • Network controls: security groups, VPC and VNet design, and private endpoints
  • Logging and detection coverage: AWS CloudTrail and GuardDuty; Azure Monitor activity logs and Microsoft Defender for Cloud; and Google Cloud Audit Logs and Security Command Center
  • Secrets management and encryption key handling
  • Microsoft Entra ID and Google Workspace tenant configuration

Why it matters

  • Google Cloud Threat Horizons H1 2026: identity issues gave attackers initial access in 83% of Mandiant-handled cloud/SaaS incidents (H2 2025).Source: Google Cloud, Cloud Threat Horizons Report H1 2026 (2026)

    Covers cloud and SaaS incidents Mandiant handled in the second half of 2025, not all cloud incidents.

How we approach it

We start with a read-only audit role to review configuration at scale, then test from an assumed-breach position inside one of your workloads to show which misconfigurations an attacker can actually use. We follow each provider’s penetration testing rules and file any advance notice they require.

Standards and references: CIS Benchmarks, MITRE ATT&CK Cloud Matrix, AWS Well-Architected Security Pillar, Microsoft cloud security benchmark

Included in every penetration test

  • Manual testing by our own US-based testers, backed by tooling.
  • Critical findings are reported within 24 hours of confirmation, not held for the report.
  • Executive summary and technical findings with severity ratings, evidence, and reproduction steps.
  • Final report delivered within 5 business days after testing ends.
  • A walkthrough call with your team after the report.
  • An attestation letter you can share with customers, auditors, and insurers.
  • One retest of reported findings within 90 days of the final report, included in the price.
  • Every engagement is a fixed fee after a free scoping call.

Engagement commitments apply to work under a signed HackNow proposal.

When to use it

  • SaaS companies preparing for SOC 2 or ISO 27001
  • Migrations to a new cloud provider or account structure
  • Adopting Kubernetes or serverless
  • After a cloud security incident or near miss

What we’ll need from you

  • The AWS account, Azure subscription, or Google Cloud project IDs in scope
  • A read-only audit role we can use for the configuration review
  • For assumed-breach testing: a workload or identity to start from
  • Kubernetes clusters in scope, if any
  • Regions, services, or accounts that are off limits

See the full scoping checklist

Questions about cloud testing

How much does it cost?

Prices start at $10,000 per environment for the smallest scope. An environment is one AWS account, Azure subscription, or Google Cloud project. Your price depends on the number of accounts, subscriptions, or projects and the Kubernetes clusters and identity providers in scope, and it’s a fixed fee set after a free scoping call.

Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.

How long does it take, and when do we get results?

Testing can usually start within 5 business days of signing. Testing typically takes one to two weeks per environment. Critical findings are reported within 24 hours of confirmation, not held for the report. Final report delivered within 5 business days after testing ends.

Will testing disrupt our systems?

Testing is planned to avoid disruption. We agree on testing windows, source IP addresses, and emergency contacts before we start. Denial-of-service and destructive testing are never performed without written approval, and you can pause testing at any time with one message.

Is a retest included?

Yes. One retest of reported findings within 90 days of the final report is included in the price. We verify each fix and issue an updated report and attestation letter.

Do we need permission from AWS, Azure, or Google Cloud?

Usually not. AWS, Microsoft Azure, and Google Cloud let customers test their own resources without prior approval, as long as testing follows each provider’s rules. We follow those rules and file any advance notice a provider requires.

Last reviewed October 2026

Ready to scope a cloud pen test?

We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.