← All services
Penetration testing service
Cloud Configuration Review
AWS, Azure or GCP configuration reviewed against the provider benchmark and against how the environment is actually used.
What the test covers
- Identity and access management: over-permissioned roles, unused credentials, privilege escalation paths
- Storage exposure and encryption at rest
- Network configuration, security groups and public exposure
- Logging, monitoring and alerting coverage
- Secrets management across the pipeline
- Benchmark comparison against CIS controls for the platform
Deliverables
- Executive summary
- Findings mapped to the relevant CIS benchmark controls
- Prioritised remediation roadmap
- One retest round with a signed closure letter
Out of scope
- Provider infrastructure itself
- Cost optimisation