Cloud penetration testing
We review the configuration of your cloud accounts and test them hands-on.
- Reply within one business day
- NDA on request
Testing covers IAM privilege escalation, exposed storage, and paths from a compromised workload to your control plane.
What we test
- IAM policies, roles, and privilege escalation paths
- Public exposure of storage, snapshots, databases, and functions
- Instance metadata, workload identity, and credential exposure
- Kubernetes and container security (EKS, AKS, GKE)
- Network controls: security groups, VPC and VNet design, and private endpoints
- Logging and detection coverage: AWS CloudTrail and GuardDuty; Azure Monitor activity logs and Microsoft Defender for Cloud; and Google Cloud Audit Logs and Security Command Center
- Secrets management and encryption key handling
- Microsoft Entra ID and Google Workspace tenant configuration
Why it matters
-
Google Cloud Threat Horizons H1 2026: identity issues gave attackers initial access in 83% of Mandiant-handled cloud/SaaS incidents (H2 2025).Source: Google Cloud, Cloud Threat Horizons Report H1 2026 (2026)
Covers cloud and SaaS incidents Mandiant handled in the second half of 2025, not all cloud incidents.
How we approach it
We start with a read-only audit role to review configuration at scale, then test from an assumed-breach position inside one of your workloads to show which misconfigurations an attacker can actually use. We follow each provider’s penetration testing rules and file any advance notice they require.
Standards and references: CIS Benchmarks, MITRE ATT&CK Cloud Matrix, AWS Well-Architected Security Pillar, Microsoft cloud security benchmark
Included in every penetration test
- Manual testing by our own US-based testers, backed by tooling.
- Critical findings are reported within 24 hours of confirmation, not held for the report.
- Executive summary and technical findings with severity ratings, evidence, and reproduction steps.
- Final report delivered within 5 business days after testing ends.
- A walkthrough call with your team after the report.
- An attestation letter you can share with customers, auditors, and insurers.
- One retest of reported findings within 90 days of the final report, included in the price.
- Every engagement is a fixed fee after a free scoping call.
Engagement commitments apply to work under a signed HackNow proposal.
When to use it
- SaaS companies preparing for SOC 2 or ISO 27001
- Migrations to a new cloud provider or account structure
- Adopting Kubernetes or serverless
- After a cloud security incident or near miss
Can support:
What we’ll need from you
- The AWS account, Azure subscription, or Google Cloud project IDs in scope
- A read-only audit role we can use for the configuration review
- For assumed-breach testing: a workload or identity to start from
- Kubernetes clusters in scope, if any
- Regions, services, or accounts that are off limits
Questions about cloud testing
How much does it cost?
Prices start at $10,000 per environment for the smallest scope. An environment is one AWS account, Azure subscription, or Google Cloud project. Your price depends on the number of accounts, subscriptions, or projects and the Kubernetes clusters and identity providers in scope, and it’s a fixed fee set after a free scoping call.
Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.
How long does it take, and when do we get results?
Testing can usually start within 5 business days of signing. Testing typically takes one to two weeks per environment. Critical findings are reported within 24 hours of confirmation, not held for the report. Final report delivered within 5 business days after testing ends.
Will testing disrupt our systems?
Testing is planned to avoid disruption. We agree on testing windows, source IP addresses, and emergency contacts before we start. Denial-of-service and destructive testing are never performed without written approval, and you can pause testing at any time with one message.
Is a retest included?
Yes. One retest of reported findings within 90 days of the final report is included in the price. We verify each fix and issue an updated report and attestation letter.
Do we need permission from AWS, Azure, or Google Cloud?
Usually not. AWS, Microsoft Azure, and Google Cloud let customers test their own resources without prior approval, as long as testing follows each provider’s rules. We follow those rules and file any advance notice a provider requires.
Last reviewed October 2026
Often paired with
- Network penetration testing External perimeter, internal network, Active Directory, and on-site wireless testing.
- Web application penetration testing Authenticated, manual testing of your web apps, from the login page to business logic.
- Secure code review and threat modeling Design reviews and manual source code review that find security flaws before they ship.
Ready to scope a cloud pen test?
We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.