Skip to content

Cloud security · AWS, Azure, GCP

Most cloud breaches are a permission, not an exploit.

We start from the actual state of your accounts and map the paths that let one identity assume its way to administrator. Then we show you the chain, not just the flag.

Recon · Why it matters

Nobody exploits your cloud. They log into it.

The incidents that hurt in cloud environments rarely involve a novel vulnerability. They involve a role with more permission than anyone intended, storage reachable from somewhere it should not be, or a key that outlived the person who created it. Those are configuration problems, and configuration is what we read.

Coverage · What we test

What is in scope.

01

Identity and access

Roles, trust policies, federation, and the paths that let one identity assume its way to administrator.

02

Network and exposure

What is reachable from the internet, what is reachable between accounts, and whether segmentation matches the diagram.

03

Data and secrets

Storage permissions, encryption in practice rather than on paper, key rotation, and secrets living where they should not.

04

Architecture review

Multi-account structure, landing zone design, and logging that would actually support an investigation.

Execution · How we work

How the engagement runs.

Step 01

Read the configuration

We start from the real state of your accounts, not from a questionnaire about them.

Step 02

Find paths, not just flags

A single over-permissioned role matters only when something can reach it. We show the chain from entry point to impact.

Step 03

Prove what we claim

Where you allow it, we demonstrate the path is real rather than theoretical.

Step 04

Prioritise by blast radius

Fix order is driven by what an attacker gains, not by how many findings share a label.

Debrief · What you get

What lands on your desk.

Every engagement ends with something your engineers can act on and your auditors can accept.

  • Privilege escalation paths mapped from entry point to administrator, with the exact policy at fault
  • Exposure inventory of everything reachable from outside, and from where
  • Prioritised fixes ordered by blast radius, with the policy changes written out
  • Logging review covering whether you could reconstruct an incident from what you keep today

Questions · Straight answers

Common questions.

Which providers do you cover?

AWS, Azure and GCP, including hybrid setups where identity spans more than one.

Do you need administrator access?

Read-only access is enough for the review itself. Anything we want to prove by testing is agreed with you first.

Need this scoped? Let's talk.

Tell us what you need tested and when. A senior tester reads every request and replies within an hour with scope, timing and price.

Request a quote

Reply within an hour · NDA on request · Scoped by a senior tester, not sales