Skip to main content
  • Enterprise IT & cloud

Cloud Security

Your cloud accounts and subscriptions, and the build and automation estate that deploys into them: workloads, storage, networks, the identity layer above them, and the monitoring and backups that decide what happens when something does go wrong.

Why we test it this way

A posture tool reads configuration and returns a list. What it cannot tell you is which of those findings someone could actually use, because that depends on which identity can reach the resource, from where, and what that identity can do next. We collect the same data automatically and treat it as coverage rather than as findings. The time goes on the part that needs context: checking which of them is real in your environment, then chaining what is real into a path.

Three assessment types over the same review areas. The scan is automated and broad, the pentest is scoped and manual, and the maturity assessment adds the operation around the estate. Operational resilience is out of scope for the scoped review, which is a boundary worth knowing before you buy rather than after.

What each depth covers
ScanPentestMaturity

Resources

Workloads: instances, functions, containers, hardening Scan covered Pentest covered Maturity covered
Storage: buckets, volumes, secrets, policy misconfiguration Scan covered Pentest covered Maturity covered
Network: firewalls, load balancers, exposure and remote access Scan covered Pentest covered Maturity covered

Identity and access

Access rules, credential management, authentication Scan covered Pentest covered Maturity covered
Privileged identities, least-privilege violations, overprivileged accounts Scan not covered Pentest covered Maturity covered
Role design and privileged account management Scan not covered Pentest covered Maturity covered

Operational resilience

Native logging, alerting and response capability Scan not covered Pentest not covered Maturity covered
Backups, resilience features, native security tooling Scan not covered Pentest not covered Maturity covered
Integration: hybrid directory, external identities, third-party apps, devices Scan not covered Pentest not covered Maturity covered

Processes and people

Detection coverage and response process Scan not covered Pentest not covered Maturity covered
Change and lifecycle management, patching, periodic review Scan not covered Pentest not covered Maturity covered

A full-scope review covers all of these. It is not a claim that these are all of cloud security.

A public bucket in a sandbox and a public bucket holding customer records are the same finding to a scanner and different problems to you. The difference is not in the configuration, it is in what sits around it, which is why the review reads resources and identity together rather than one after the other.

Identity is where a cloud estate is usually won. Permission assignments that were correct when granted, roles that accumulated, service principals nobody owns any more, and the hybrid join between the directory on premises and the one in the tenant: these are ordinary administrative debt, and they are also the shortest path from one foothold to the whole subscription.

Where engagements usually start

Cloud security scan

Automated collection across every account, and the issues that do not need a person to find.

  • Every subscription or account enumerated, rather than a sample
  • Automated checks across workload, storage and network configuration
  • Identity data collected in the same pass, so a finding can be read against who can reach it
  • Run with our own tooling and open source: our forks of ScoutSuite and GCPHound, Prowler, and our collection scripts

Cloud security pentest

A scoped review that follows the findings into the paths they actually make possible.

  • Scoped to named projects, subscriptions or accounts
  • Resources and identity read together, human and non-human alike: hardening and exposure against permission assignments and role design, including the service accounts, CI runners and agent workloads that hold standing access
  • Findings validated against your architecture, so what is theoretical is set aside with the reasoning kept
  • What survives is chained into attack paths, which is the part a severity list cannot produce
  • Operational resilience is out of scope at this depth

Cloud maturity assessment

The full scope, including the monitoring, the backups and the people running them.

  • Everything in the scoped review, across the whole estate rather than a subset
  • Operational resilience: native logging and alerting, backup and recovery, the security tooling your platform already includes
  • Integration: hybrid directory and external identities, collaboration platforms, third-party applications, device management
  • Processes and people: detection coverage, response process, change and lifecycle management, patching

Also available: identity review on its own, where the directory rather than the tenant is the subject. The build and automation estate as its own subject, covering artifact repositories and package caches, CI runners, agent sandboxes, the service accounts they hold and the egress each of them has — which identities can write, what each can reach if something else were driving, and whether an alert fires when one of them writes somewhere it should not. Cloud application testing, when the risk is in what you built rather than in what you configured. Red teaming, when the question is whether anyone would notice.

How we work

We agree first which accounts hold the things that would hurt to lose, because a review scoped to everything is a review weighted by nothing. Automated collection then runs across the whole scope, and it is there for coverage rather than for its findings: it tells us what exists, so the manual work can be aimed instead of sampled. What comes back is validated against your architecture, and what survives that is chained into paths and tested. Results are presented in a session rather than sent as a file, because a high-severity finding needs its proof of concept shown, and an attack path needs someone to walk through it with the people who own each step.

Send us the problem

Tell us what you are building and what you need looked at. You will get an answer from the people who would run the engagement, and if another firm is the better fit for what you are asking, we will name one.

Get in touch

Security Research Labs is a member of the Allurity family. Learn more(opens in a new tab)