Cloud security review
Most cloud incidents are not zero-days. They are a public bucket, an over-privileged role, a key in a repo, and no logging when it matters. We review the configuration an attacker would actually use.
What this engagement is
Australian organisations moved to AWS, Azure and Google Cloud faster than they moved the control model that used to live in a datacentre. Identity is the new perimeter. Storage is a URL. A single wildcard IAM statement can undo a year of network diagrams.
A cloud security review is a structured, authorised assessment of identity, network exposure, storage permissions, secrets handling and logging. It is not a pentest of every workload, and we will not pretend it is. It is the engagement that catches the misconfiguration class that dominates cloud breach reports.
We map findings to CIS Benchmarks and vendor best practice, and we write them so an engineer can change the Terraform, not just nod at a screenshot of the console.
What we actually look for
Identity and access
IAM, Entra ID, service principals, unused keys, privilege paths, assume-role chains.
Public exposure
S3/Blob/GCS, snapshots, AMIs, load balancers, security groups that mean 'the internet'.
Secrets
Keys in user-data, pipelines, Parameter Store left world-readable, CI logs.
Network paths
Peering, PrivateLink, jump boxes that are not, and metadata services reachable from a foothold.
Logging and detection
CloudTrail/Activity Logs/Audit Logs coverage, retention, and the gaps that make an incident unreconstructable.
Guardrails
SCPs, Azure Policy, org-level constraints that exist on a slide and not in the tenant.
Questions buyers ask before they sign
Do you need admin on the account?
Read-only at org or subscription level is enough for a review. We do not need to deploy attackers into production. If you want an assumed-breach exercise, that is a different, explicit scope.
One cloud or three?
We quote per platform. A company on AWS plus a bit of Azure is two surfaces, not one.
Is this a pentest?
It is a configuration and architecture review with exploit-minded eyes. We will prove impact where it is safe (a public object, an over-permissive role). We will not ransomware your tenancy to make a point.
Often scoped alongside
Web application penetration testing
Your web app is the front door to customer data, payments and admin. We test it logged in, role-aware, reading the JavaScript and probing th…
Learn more > [api]API penetration testing
Your SPA is a skin. The API is the product. We test REST, GraphQL and internal service APIs for the authorisation bugs that turn one user's …
Learn more > [mob]Mobile app penetration testing
The store listing is not the threat model. We assess the iOS and Android clients and the APIs they call, on-device and on the wire, mapped t…
Learn more >Scope this test
Send the target, the roles and the deadline. You will get a fixed quote in AUD, usually within two business days.