The challenge behind the engagement.
Cloud penetration testing looks at your cloud environment, whether one provider or several, the way an attacker who has landed in the account would, inside each provider’s rules. Most engagements are credentialed, starting from a scoped role so we can trace real privilege-escalation paths; an outside-in scope is also possible. We review identities and permissions for over-permissive roles, overly broad policies, and trust between accounts that an attacker can ride. We check exposed cloud storage, and probe the serverless and container services running your workloads. We hunt for secrets left in the environment, requests that reach internal cloud services they should not, and gaps in logging and monitoring. You receive an identity attack-path diagram, findings with provider-specific fixes and severity ratings, and a retest after you remediate.
For cloud and platform teams running workloads on one or more providers who want attacker-driven testing, not just a configuration score. Common after a migration, ahead of a customer security review, or when identity sprawl has outgrown governance.
What we do.
What you can use.
Scope accounts and access
We confirm which accounts, subscriptions, or projects are in scope, that they are yours to test, and whether the engagement is credentialed with a scoped read-only role or fully outside-in. We note that some providers require advance notice for certain simulated attacks and that denial-of-service testing is off the table under every provider’s rules.
Attack identity and services
We trace privilege escalation through identities and permissions: over-permissive roles, overly broad policies, and trust between accounts an attacker can ride. We test exposed cloud storage, the serverless and container services running your workloads, secrets left in the environment, and requests that reach internal cloud services they should not.
Diagram paths and retest
You receive an identity attack-path diagram, findings rated for severity with provider-specific remediation, and an executive summary. We retest remediated findings, package evidence for auditors and customers, and issue a shareable attestation letter for the account owner.
Who it’s for.
When you need it.
- Cloud and platform teams running production workloads on one or more cloud providers
- Organizations where identity and role sprawl has outgrown its original governance
- Teams that want attacker-driven testing rather than only a configuration score
- Businesses with sensitive data reachable through cloud identities, storage, or serverless services
- A cloud migration or new landing zone recently changed the account structure
- A customer security review asks how cloud identity and data exposure are tested
- Rapid growth left assumable roles, wildcard policies, or exposed storage unreviewed
- A configuration review flagged risks that need validation of real attack paths
What the scope can include.
- 01
Review identities and permissions for privilege escalation and trust between accounts
- 02
Check exposure of cloud storage across the environment
- 03
Probe the serverless and container services running your workloads
- 04
Hunt for exposed secrets and requests that reach internal cloud services
- 05
Assess network exposure and logging and detection gaps per account
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.
One cloud account with a handful of services and one production workload
About 24–40 hoursTwo to five cloud accounts running production apps, containers, or serverless code
About 48–72 hoursMore than five accounts or more than one cloud provider, with shared sign-in across them
About 80–120 hours- Number of cloud accounts, subscriptions, or projects
- Number of users, roles, and trust links between accounts
- Container and serverless services in use
- One cloud provider or several
Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Identity attack-path diagram across the in-scope accounts and roles
- Findings with severity ratings and provider-specific remediation
- Executive summary plus a retest of remediated cloud findings with evidence
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Do you need a role in our account, or is this black-box?
Both models work. Most value comes from a credentialed test that starts from a scoped, often read-only role, because that lets us trace privilege-escalation paths an outside scan never sees. A black-box scope models an attacker with no access. We confirm in writing that the accounts are yours and apply each provider’s testing rules.
How is this different from a configuration review?
A configuration review scores your settings against a benchmark. Cloud penetration testing is attacker-driven: we chain a weak permission into a wider role, reach a secret, and pivot to real data, showing the path rather than a list of misconfigurations. If you want setting-by-setting coverage instead, that belongs in a cloud security assessment.
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
- OWASP Web Security Testing Guide
- OWASP Top 10 API Security Risks – 2023
- Common Vulnerability Scoring System version 4.0: Specification Document
- NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security
- Penetration Testing - Amazon Web Services (AWS)
