// Cloud

Cloud security review

Most cloud incidents are not zero-days. They are a public bucket, an over-privileged role, a key in a repo, and no logging when it matters. We review the configuration an attacker would actually use.

Earth from orbit at night

What this engagement is

Australian organisations moved to AWS, Azure and Google Cloud faster than they moved the control model that used to live in a datacentre. Identity is the new perimeter. Storage is a URL. A single wildcard IAM statement can undo a year of network diagrams.

A cloud security review is a structured, authorised assessment of identity, network exposure, storage permissions, secrets handling and logging. It is not a pentest of every workload, and we will not pretend it is. It is the engagement that catches the misconfiguration class that dominates cloud breach reports.

We map findings to CIS Benchmarks and vendor best practice, and we write them so an engineer can change the Terraform, not just nod at a screenshot of the console.

// Coverage

What we actually look for

[cld]

Identity and access

IAM, Entra ID, service principals, unused keys, privilege paths, assume-role chains.

[cld]

Public exposure

S3/Blob/GCS, snapshots, AMIs, load balancers, security groups that mean 'the internet'.

[cld]

Secrets

Keys in user-data, pipelines, Parameter Store left world-readable, CI logs.

[cld]

Network paths

Peering, PrivateLink, jump boxes that are not, and metadata services reachable from a foothold.

[cld]

Logging and detection

CloudTrail/Activity Logs/Audit Logs coverage, retention, and the gaps that make an incident unreconstructable.

[cld]

Guardrails

SCPs, Azure Policy, org-level constraints that exist on a slide and not in the tenant.

// FAQ

Questions buyers ask before they sign

Do you need admin on the account?

Read-only at org or subscription level is enough for a review. We do not need to deploy attackers into production. If you want an assumed-breach exercise, that is a different, explicit scope.

One cloud or three?

We quote per platform. A company on AWS plus a bit of Azure is two surfaces, not one.

Is this a pentest?

It is a configuration and architecture review with exploit-minded eyes. We will prove impact where it is safe (a public object, an over-permissive role). We will not ransomware your tenancy to make a point.

Scope this test

Send the target, the roles and the deadline. You will get a fixed quote in AUD, usually within two business days.

Get a fixed quote