Skip to content

Home » Penetration testing » Cloud penetration testing

Cloud penetration testing

Book a call

What is cloud penetration testing?

Cloud penetration testing reviews how your AWS, Microsoft Azure or Google Cloud environment is configured and tests what an attacker could do with a foothold in it. Incursion tests cloud environments for UK organisations, combining configuration review against the provider’s own security benchmarks with hands-on testing of identity, permissions and workloads, delivered by named consultants with UK Cyber Security Council professional titles.

What we test

Identity and access: users, roles, service principals and the permissions they actually have, including privilege escalation paths.

Storage: buckets, blobs, databases and backups that are public, over-shared or unencrypted.

Network: security groups, firewall rules, exposed management interfaces and routes between environments.

Workloads: virtual machines, containers, serverless functions and the secrets they hold.

Logging and monitoring: whether you would know if any of the above were being abused.

Configuration review against the CIS Benchmarks for the provider, plus hands-on testing from a defined starting point.

Why it matters

Cloud breaches are rarely about the provider and almost always about configuration: a role with more permissions than anyone remembers granting, a storage bucket that was public for a migration and never closed, a secret in an environment variable. The provider secures the cloud; you secure what you put in it, and that is what we test.

How we run it

01

Scoping. Your account manager and an active penetration tester work with you to agree the scope of your test on a scoping call. The quote is fixed to it.

02

Testing. A named, suitably qualified consultant does the work, and you get a direct line to them before, during and after the engagement. Critical and high-risk issues are verified and reported immediately.

03

Reporting. Easily digestible summaries sum up the whole engagement and support detailed technical findings, written so your team can replicate and fix them. Delivered within 5 working days.

04

Free retesting. One day of free retesting for every five days of consultancy, taken within 90 days of report delivery, so you can be sure the fixes worked.

Scoping notes

We need read-only access to the environment for the configuration review and, for hands-on testing, a defined starting point such as a low-privilege user or a compromised workload. We cover AWS, Azure and Google Cloud. Multi-cloud estates are scoped per provider.

What you get

A named consultant with a UK Cyber Security Council professional title, who scoped the work and delivers it.

A report within 5 working days: executive summary, technical summary, and observation, impact and remediation for every finding.

Immediate notification of critical and high-risk issues, once we have verified them.

Free retesting: one day for every five days of consultancy, within 90 days of the report.

A walkthrough call with the consultant for your team, on request, at no extra cost.

Frequently asked questions

Which cloud providers do you cover?

AWS, Microsoft Azure and Google Cloud.

Is this a configuration review or a penetration test?

Both, and you can have either. The review compares your configuration to the provider’s benchmarks; the test starts from a foothold and tries to escalate. The review finds more items; the test proves which ones matter.

Do we need to tell the cloud provider?

For AWS, Azure and Google Cloud, customer-initiated testing of your own resources within their policies does not need prior approval. We confirm the current policy at scoping and stay within it.

Ready to scope a test?

Book a call. Our sales team will set it up and handle the proposal; an active penetration tester agrees the scope with you. No obligation.