Service
Cloud Security Posture Assessments
AWS, Azure, GCP and Kubernetes, reviewed the way an attacker reads them: not as a list of misconfigurations, but as a set of paths from wherever they land to whatever you care about.
Questions we get asked
We already run a CSPM tool. What does this add?
Your CSPM tells you a bucket is public and a role is over-permissioned. It does not tell you that the over-permissioned role is assumable by the CI runner that builds pull requests from forks, which is the sentence that actually matters. Posture tools list conditions; we chain them into paths and tell you which chain reaches your production data.
Do you need production access?
A read-only role is enough for the posture review, and we prefer it: SecurityAudit and ViewOnlyAccess in AWS, Reader plus a directory read in Azure, roles/viewer with IAM read in GCP. If you also want the exploitation half proved rather than argued, that needs a scoped, written-down escalation of access, or a copy of the environment.
Which do we need, a posture assessment or a cloud penetration test?
Posture assessment if the question is "how is this configured and what is wrong with it". Penetration test if the question is "can somebody get from the internet into our data". They overlap, and most clients want the review first because it is cheaper and it usually surfaces enough to keep the team busy for a quarter.
Does the cloud provider need to approve testing?
For AWS, Azure and GCP, testing your own resources within their published rules no longer needs an approval form for common service categories, though some activities still do and simulated denial of service always does. We check the current policy for whatever we are touching and keep the confirmation with the engagement record.
Do you cover Kubernetes?
Yes, and it is often the most productive part. RBAC that grants pod creation is effectively node-level access, service accounts get mounted into pods that have no business holding a token, and the boundary between namespaces is thinner than most teams assume. We look at the cluster and at what a compromised pod can reach in the cloud account underneath it.
Also from us
Related services
Penetration Testing
Network, web app, API, mobile and internal testing done by hand. You get the attack path, the proof, and a retest once it is fixed.
Vulnerability Assessments
Full-estate scanning, then a human pass to strip the noise and rank what is left by real reachability instead of raw CVSS.
Endpoint Security
CrowdStrike Falcon rollouts, policy tuning and legacy AV migrations, run by people who break into endpoints for a living.
Compliance Readiness
Gap assessment first, then the recurring scanning and pentest evidence your SOC 2, HIPAA, PCI DSS or CMMC auditor asks for.
Know what an attacker would reach first.
Tell us what you run and what worries you. We will come back with a scope, a fixed price and the earliest week we can start.