Skip to content

Home Expertise / Penetration testing

PEN / PEN-07

Cloud and IAM penetration testing

Controlled testing of abuse scenarios in a cloud environment, beyond configuration review alone.

WHEN IT HELPS

A focused response
to a defined need.

CTO or cloud owner; sensitive storage, multiple cloud accounts or highly privileged service identities.

AT A GLANCE

Family
Penetration testing

Engagement
Testing

Reference
PEN-07

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Authorised accounts and services
  • privilege paths
  • storage and secret access with strict controls on costs and data

Deliverables

  • Validated scenarios
  • affected permissions and dependencies
  • IAM and architecture recommendations

Acceptance evidence

Observed scenarios remain within the authorised tenant; costs, evidence and cleanup are tracked.

DELIVERY

How the work is structured.

Approach

Obtain authorisation and rules of engagement; prepare accounts and backups; perform controlled tests; debrief, clean up and arrange retesting.

Prerequisites & responsibilities

Customer: written authorisation, asset ownership, third-party permission, stop contacts and scope. Provider: bounded testing, minimal evidence and critical-finding notification.

Scope factors

Applications, roles, APIs, networks, business complexity, supplied access, depth and authorised windows. Black/grey/white box and retesting affect effort; price after scoping.

Questions to clarify

Which accounts and regions? What does the provider permit? Which budgets and services are excluded?

IMPORTANT BOUNDARIES

Provider testing rules apply in addition to customer authorisation; a cloud review does not automatically include these tests.

No denial of service, destruction, real exfiltration or social engineering without explicit authorisation. Third parties are not tested merely at a customer’s request. Untested scope remains unassessed.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A SaaS application on AWS has overly broad storage access. Project: test access using synthetic objects. Target outcome: reduce permissions to required resources and verify application regression tests.

Scenario 02

A multicloud company shares a deployment identity across test and production. Project: assess boundaries. Target outcome: separate accounts and rotated secrets; actions outside the approved scope remain prohibited.

Technology and reference context

Cloud IAM, object storage and in-scope services; provider documentation.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.