1. Home
  2. Services
  3. Penetration testing

Cloud penetration testing and configuration review

Cloud breaches rarely need a zero-day. Misconfigurations and stolen credentials are usually enough. We review the configuration of your accounts and test them hands-on: IAM privilege escalation, exposed storage, and paths from a compromised workload to your control plane.

What we test

  • IAM policies, roles, and privilege escalation paths
  • Public exposure of storage, snapshots, databases, and functions
  • Instance metadata, workload identity, and credential exposure
  • Kubernetes and container security (EKS, AKS, GKE)
  • Network controls: security groups, VPC design, and private endpoints
  • Logging and detection coverage: CloudTrail, Microsoft Defender for Cloud, and Security Command Center
  • Secrets management and encryption key handling
  • Microsoft Entra ID and Google Workspace tenant configuration

How we approach it

We start with a read-only audit role to review configuration at scale, then test from an assumed-breach position inside one of your workloads to show which misconfigurations an attacker can actually use.

What you get

  • Executive summary written for leadership and customers
  • Technical findings with CVSS scores, evidence, and reproduction steps
  • Specific remediation guidance for each finding
  • One retest of reported findings within 90 days, with an updated report
  • Attestation letter you can share with customers and auditors

Typical use cases

  • SaaS companies preparing for SOC 2 or ISO 27001
  • Migrations to a new cloud provider or account structure
  • Adopting Kubernetes or serverless
  • After a cloud security incident or near miss

Tell us what you need tested.

Send a few details and we'll set up a short scoping call, then follow up with a fixed-fee proposal.

Request a quote