Skip to content

04 · Security Testing

Cloud Security Assessment

Find the misconfiguration before a scanner on the internet does.

A configuration and architecture review of your cloud estate, identity and access, network boundaries, storage and secrets, logging and detection, container and serverless workloads, benchmarked against CIS and provider best practice, then prioritized by exploitability.

  • Azure

The context

Why this matters

Cloud breaches are rarely exotic. They are an over-permissive role, a storage bucket that drifted public, a secret in an environment variable, a management port open to the internet, or logging that was never enabled on the account that mattered.

We review the estate as an attacker would map it: what is reachable from outside, what an initial foothold escalates into, and what a compromised CI pipeline or developer laptop could reach. That is a different exercise from running a CSPM scan and exporting the findings list.

The output is a prioritized remediation plan with infrastructure-as-code changes where we can express them that way, so fixes land in your repository rather than as manual console clicks that drift back within a quarter.

Platform coverage

Every platform, assessed for what actually breaks on it.

The failure modes differ by provider. So does our checklist.

Amazon Web Services

The deepest surface we test. IAM is where AWS environments quietly go wrong, and it is almost never a single bad policy. It is a chain.

Full AWS assessment guide

What we find most often

A CI role assumable from an unrestricted GitHub OIDC condition, chaining into production admin.

Assessed surfaces

  • IAM roles, policies, trust relationships & privilege escalation paths
  • S3 bucket policies, ACLs, Block Public Access & pre-signed URL handling
  • VPC design, security groups, NACLs & internet-facing exposure
  • KMS key policies, Secrets Manager, SSM Parameter Store
  • CloudTrail coverage, GuardDuty, log integrity & retention
  • EKS RBAC, ECS task roles, Lambda execution permissions
  • CodeBuild / CodePipeline permissions & OIDC trust from CI

What is covered

Scope of the engagement

  1. 01

    Identity & access management

    Role and policy review, privilege escalation paths, cross-account trust, federation and SSO configuration, service account sprawl, and unused credentials.

  2. 02

    Network exposure

    Internet-facing surface, security group and firewall rules, VPC and subnet design, load balancer and WAF configuration, private connectivity, and management-plane access.

  3. 03

    Data protection

    Storage permissions and public access controls, encryption at rest and in transit, key management and rotation, secrets handling, backup integrity and restore testing.

  4. 04

    Logging & detection

    Audit trail coverage and retention, log integrity, alerting on high-risk actions, and whether anyone would actually notice a compromise in progress.

  5. 05

    Workload security

    Container images and registries, Kubernetes RBAC and network policy, serverless permissions and runtime configuration, and host-level hardening.

  6. 06

    CI/CD & supply chain

    Pipeline permissions, build-time secret exposure, artifact integrity, dependency and base-image hygiene, and who can push to production.

What you receive

Deliverables

Everything below is included in the fixed price. Nothing here is an upsell discovered halfway through.

  • Prioritized findings report with cloud-native reproduction detail
  • Attack-path analysis showing what a foothold escalates into
  • CIS Benchmark and provider best-practice conformance summary
  • Infrastructure-as-code remediation snippets where applicable
  • Logging and detection coverage gap assessment
  • Architecture recommendations for the next stage of growth

Questions

Cloud Security Assessment FAQ

We work from read-only audit access, a scoped role with security-audit permissions in AWS, Reader plus Security Reader in Azure, or the equivalent in GCP. No write access, no changes made by us. Where policy prohibits third-party access we can run our collection scripts with your engineer driving.

A CSPM tool tells you a control is non-conforming. It does not tell you that this particular role, combined with that particular trust relationship, lets a compromised build runner assume an admin role in the production account. We do the chaining, the prioritization and the architecture judgement a tool cannot.

No. We assess AWS, Azure and GCP, and we specifically look at the seams between them, federated identity, cross-cloud data flows, and inconsistent controls where one provider's defaults quietly differ from another's.

Know exactly what an auditor, and an attacker, would find.

Tell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.

Book a scoping callsecurity@innsecs.com

No sales sequence. A scoping call and a written proposal cost nothing.