Skip to content

Cloud

Cloud Security
Assessment

AWS, Azure, and GCP configuration and IAM review

Configuration review from $4,200, exploitation from $6,800, fixed scope, free retest. See all pricing →

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When you need a cloud security assessment

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • An enterprise customer or a cyber insurer asked for evidence that your cloud is configured safely, and a provider dashboard score did not satisfy them.
  • You moved to AWS, Azure, or GCP and no outsider has ever reviewed the identity model, the network exposure, or the data stores.
  • A security questionnaire asks how your cloud is secured, and you need an independent posture and IAM review to answer it.
  • Your cloud sits inside your SOC 2 or ISO 27001 scope and the auditor expects more than a configuration checklist.
  • You want to know where the gaps are before committing to a full cloud penetration test that proves them end to end.

Definition

What is a cloud security assessment?

A cloud security assessment, sometimes called a cloud security audit or posture review, is a read-only evaluation of how one cloud account is configured and what it exposes. It covers the identity model, the network exposure, the storage and data stores, and the logging and key management, benchmarked against the CIS Foundations for your provider and verified by hand rather than exported from a dashboard score. Access is read-only, so nothing in the account is changed while we assess it.

The assessment covers a single AWS account, Azure subscription, or GCP project from $4,200, the same starting price as our Microsoft 365 configuration review. When you also need the misconfigurations proven end to end, our cloud penetration testing chains them into a real attack path from $6,800.

What we look for

What a cloud security assessment finds

In the cloud, the weaknesses attackers use are usually misconfigurations and over-privileged identities rather than zero-days. An assessment reads the account the way an attacker would enumerate it, and reports the exposures that a benchmark score alone would miss.

Identity and access management

The identities and policies that decide who can reach what, and the grants that quietly let a small foothold become account-wide access.

We test for

  • Over-permissive and wildcard policies
  • Privilege-escalation paths through roles and trust
  • Unused, stale, and never-rotated credentials
  • Federated identity and cross-account or cross-tenant trust
  • Standing administrator and root or Global Administrator access

Network exposure

The services and endpoints reachable from the internet, and the rules that were opened for a reason nobody remembers.

We test for

  • Open security groups, firewall rules, and NACLs
  • Public databases, caches, and management interfaces
  • Exposed storage and object endpoints
  • Peering, transit, and VPN paths that widen the boundary
  • Staging and preview environments left public

Storage and data stores

Where the data lives, and whether any of it is reachable by someone it should not be.

We test for

  • Public buckets, blobs, and containers
  • Snapshots, backups, and images left readable
  • Encryption at rest across storage and databases
  • Object ACLs and bucket policies
  • Sensitive data in logs and metadata

Logging, monitoring, and keys

Whether the account would even record an attack, and whether the secrets that unlock it are protected.

We test for

  • CloudTrail, Azure activity, or GCP audit-log coverage and retention
  • Alerting on risky sign-ins, key use, and policy changes
  • Key-management scope, rotation, and access
  • Secrets in environment, metadata, and configuration
  • Metadata-service exposure (IMDSv1 versus IMDSv2)

Benchmark and posture

The account measured against the recognized baseline, so the report shows both the deviations and the exposures that matter most.

We test for

  • CIS Foundations Benchmark deviations for AWS, Azure, or GCP
  • Configuration drift from the documented baseline
  • Shared-responsibility gaps left to the customer
  • Region and service sprawl outside the intended footprint
  • The findings ranked by real exposure, not raw score

Approach

Assessment or penetration test

The assessment answers whether the account is configured safely. The penetration test proves how far a real attacker gets. Most first engagements start with the assessment.

Cloud security assessment

Question it answers
Is the account configured safely, and what does it expose?
Method
Read-only review of identity, exposure, storage, and logging, benchmarked against CIS.
Output
A prioritized posture report with the deviations and the exposures that matter.
Starting price
From $4,200

Cloud penetration test

Question it answers
How far does a real attacker get from a small foothold?
Method
A leaked key or read-only identity chained through the misconfigurations into a proven path.
Output
The attack chain proven end to end, with fixes ranked by which link breaks the most paths.
Starting price
From $6,800

Both cover AWS, Azure, and GCP, both include a free retest, and both can be scoped together so the assessment feeds the test. See the cloud testing price tiers for what moves the number.

Providers

AWS, Azure, and GCP, each reviewed on its own terms

The identity model and the exposure surface differ by provider, so the review does too, with the same depth on all three.

Amazon Web Services

IAM users, roles, and policies; S3 public access and bucket policies; security groups and VPC exposure; CloudTrail and GuardDuty coverage; KMS and Secrets Manager scope. Granted through a scoped read-only role such as the AWS SecurityAudit policy.

Microsoft Azure

Entra ID roles and app registrations; Azure RBAC and subscription scope; storage-account and blob exposure; network security groups; Key Vault access; activity-log coverage. Granted through a read-only role such as Reader or Security Reader.

Google Cloud

IAM bindings and service accounts; Cloud Storage permissions; VPC firewall rules and default networks; audit-log coverage; Secret Manager and KMS access; organization policy. Granted through a role such as Security Reviewer. Our GCP penetration testing guide covers the exploitation side.

The Microsoft 365 or Google Workspace tenant is a separate Microsoft 365 security assessment. Kubernetes clusters are covered by Kubernetes penetration testing.

Shared responsibility

What the provider secures, and what you do

Every major provider runs a shared-responsibility model. AWS describes it as security "of the cloud" versus security "in the cloud": the provider protects the infrastructure that runs its services, and the customer is responsible for their own data, identity and access management, network and firewall configuration, and the operating systems and applications they run. Azure and Google Cloud publish shared-responsibility models of their own that divide the work along similar lines.

Public storage, over-granted identities, open network rules, and missing logs all sit on the customer side of that line. A cloud security assessment reviews exactly that side, so the report is about the decisions you can actually change, not the data-center controls the provider already runs. For a first pass of your own before we start, our cloud security checklist lists the controls we check.

Methodology

Cloud security assessment methodology

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your cloud security assessment runs through.

  1. 01

    Scope & read-only access

    One account, subscription, or project, a scoped read-only identity, and the fixed price agreed in writing. Nothing in the environment is changed.

  2. 02

    Inventory & benchmark

    Identities, storage, network rules, logging, and keys enumerated and benchmarked against the CIS Foundations for your provider.

  3. 03

    Exposure & identity review

    The network exposure and the identity model reviewed by hand for the paths a benchmark score does not surface.

  4. 04

    Prioritize

    Findings ranked by real exposure, with the quick wins separated from the projects and the shared-responsibility gaps named.

  5. 05

    Report & retest

    A benchmarked report, an attestation letter, and a free retest once your fixes ship.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope & kickoff

    Targets, roles, and rules of engagement defined in writing, with a fixed scope and timeline.

  2. 02

    Testing goes live

    Findings post to your live platform dashboard the moment our testers confirm them.

  3. 03

    Track remediation

    Follow every finding from open to fixed, with severity, evidence, and status in one place.

  4. 04

    Report & retest

    Executive and technical reports land, then request a free retest in one click.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping cloud security assessment.

Still have questions? 
01What is a cloud security assessment?

It is a read-only review of how one cloud account is configured and what it exposes: the identity model, the network exposure, the storage and data stores, and the logging and key management, benchmarked against the CIS Foundations Benchmark for AWS, Azure, or GCP and verified by hand. It answers whether the account is set up safely and where the gaps are, before an attacker finds them. It covers a single account, subscription, or project from $4,200.

02What is the difference between a cloud security assessment and a cloud penetration test?

The assessment reads the account against a benchmark and reports the misconfigurations and exposures, read-only, from $4,200. The penetration test takes a leaked key or a read-only identity and chains those misconfigurations into a proven attack path, from $6,800. The assessment tells you where the gaps are; the test proves what an attacker does with them. Most first engagements are the assessment, and the two can be scoped together.

03What access do you need, and is it read-only?

A scoped read-only identity for the account: the AWS SecurityAudit policy or an equivalent role on AWS, a Reader or Security Reader role on Azure, or a Security Reviewer role on Google Cloud. It lets us enumerate identities, policies, storage, network rules, logging, and keys without changing anything. We agree the exact role during scoping.

04Which providers do you assess?

AWS, Azure, and Google Cloud, with the same depth on each. The identity model and exposure surface differ by provider, so the review is provider-specific: IAM and S3 on AWS, Entra ID and storage accounts on Azure, IAM bindings and Cloud Storage on Google Cloud. Multi-cloud estates are assessed account by account and quoted from the scope.

05Do you need AWS, Azure, or Google approval to assess our account?

A configuration review only reads settings through a role you grant, so it stays within your own account and each provider’s customer-testing rules. You do not need to request approval to review your own environment on AWS, Azure, or Google Cloud, provided the work stays inside your resources and their acceptable-use policies. We confirm the current policy for your provider during scoping.

06How much does a cloud security assessment cost?

A configuration and IAM review of one AWS account, Azure subscription, or GCP project is $4,200, fixed before work begins, with a free retest. Adding exploitation, where an attack path is proven end to end, is a cloud penetration test from $6,800. Several accounts or a multi-cloud estate are quoted from the scope. Starting prices for every service are on our pricing page.

07Does an assessment satisfy SOC 2 or an auditor who asked for a pentest?

The assessment evidences the configuration and access-management side of SOC 2, ISO 27001, HIPAA, and NYDFS, and answers a customer questionnaire or insurer application about how the cloud is secured. It does not replace a penetration test where an auditor specifically asked for one; that is the cloud penetration test, which proves the attack paths. We often scope the assessment first and the test where the framework requires it.

Ready to test your defenses?

Talk to our team about scoping cloud security assessment.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.