Cloud Security Assessment
Misconfigurations — not zero-days — are the leading cause of cloud breaches. We audit your AWS, Azure and GCP estates against provider-specific CIS Benchmarks and exercise real attack paths through IAM, storage, secrets management, serverless and Kubernetes.
Why Generic Penetration Testing Misses Cloud Risk
Cloud breaches almost never follow the on-premises playbook. There is no perimeter to breach; there is an over-permissive IAM role, a public storage bucket, a Lambda execution role with iam:PassRole *, or a Kubernetes service account that can list secrets cluster-wide. Generic pen testing tools surface a fraction of these because they don't understand the provider control plane.
A CDSEC cloud assessment combines configuration audit against the relevant CIS Benchmark (AWS Foundations, Azure Foundations, or GCP Foundations) with an active exploitation phase that chains misconfigurations into realistic privilege-escalation paths. We use the same techniques documented by Rhino Security Labs (Pacu), Microsoft's offensive teams, and the Cloud Security Alliance's research into provider-specific attack patterns.
What We Test Per Provider
AWS
- IAM role chaining, AssumeRole abuse, permission boundary bypasses
- S3 bucket ACL, policy and Block Public Access regression
- KMS key policy review, cross-account exposure
- Lambda execution roles, environment variable secrets
- EC2 IMDSv1 metadata service exposure, SSRF chains
- EKS RBAC, pod service accounts, IRSA
- CloudTrail / GuardDuty / Config coverage validation
Azure
- Entra ID (Azure AD) role assignments, Privileged Identity Management gaps
- Conditional Access policy bypass paths
- Managed Identity misuse, Storage account SAS leakage
- Key Vault access policy / RBAC exposure
- Service Principal credential hygiene
- AKS RBAC, pod identity, network policies
- Sentinel / Defender for Cloud detection coverage
GCP
- IAM binding sprawl, primitive role usage, service account impersonation
- Cloud Storage bucket IAM and ACL review
- Workload Identity Federation misuse
- Secret Manager access and rotation
- Cloud Function and Cloud Run execution identities
- GKE RBAC, Workload Identity, binary authorisation
- Security Command Center / Audit Logs gaps
Methodology
- Read-only enumeration. We start with a least-privilege audit role and enumerate the estate against the relevant CIS Benchmark. Findings here cover the long tail of misconfiguration debt.
- Attack path mapping. We build the IAM graph and identify privilege-escalation paths — service accounts that can impersonate others, roles with
iam:PassRole *, storage objects with sensitive content, key policies that trust untrusted principals. - Authenticated exploitation. With permission, we exercise the highest-impact paths end-to-end and confirm what an attacker who reaches that initial principal can achieve. This is where ad-hoc cloud reviews fall short — discovering a finding is one thing, proving its business impact is another.
- Detection validation. We test whether your CloudTrail / Azure Activity Log / GCP Audit Log telemetry actually surfaces the attack actions to your SIEM, and whether your SOC playbooks trigger on the expected event types.
- IaC remediation. Where you operate via Terraform, CloudFormation or Bicep, we propose remediations as code-diffs rather than console screenshots — same fix, lower friction.
Frameworks & Standards
- CIS Benchmarks — AWS Foundations 3.x, Microsoft Azure Foundations 2.x, GCP Foundations 3.x.
- CSA Cloud Controls Matrix (CCM) v4 — for multi-cloud governance and compliance mapping.
- NIST SP 800-204 series — for microservice and serverless security.
- OWASP Top 10 for Kubernetes and the NSA / CISA Kubernetes Hardening Guide.
- MITRE ATT&CK for Cloud — for mapping observed attack paths to defender vocabulary.
When to Run a Cloud Security Assessment
Annually is the minimum cadence for a production cloud estate, but the event-driven triggers tend to drive value: post-migration after lifting workloads from on-prem; post-acquisition when inheriting another company's estate; after major IaC repository changes; before SOC 2 / ISO 27001 audits; and when adopting a new provider for the first time.
If your stack is multi-tenant SaaS sitting on top of one of the three providers, a cloud security assessment combined with a focused web application penetration test and API security test covers the realistic attack surface.
Related Services
- Infrastructure Security Testing — for hybrid estates with on-prem components.
- API Security Testing — for the APIs exposed by your cloud workloads.
- Red Team Exercises — adversary emulation that includes cloud as one of many entry points.
- All Penetration Testing Services — the full CDSEC service catalogue.
Get Your Cloud Estate Assessed
Most cloud assessments scope and price within 24 hours of an initial call. Send a high-level description of your estate (provider, account / subscription / project count, rough headcount) and we'll come back with a structured proposal.
Request a ProposalGet In Touch
Ready to secure your business? Contact our team of certified experts today for a consultation.
Contact Us
Get in touch for questions about our services
Phone
+44131 460 4180
Speak directly with our security experts
Our Global Offices
Local expertise with global reach across three continents