Network and cloud security

External and internal infrastructure tests, plus AWS, Google Cloud and Azure configuration reviews, following PTES, NIST SP 800-115 and the CIS Benchmarks.

We start at the edge and keep going until we reach something that matters.

What we test

Out of scope stays out. We ask first.

  • External perimeter

    Internet-facing hosts and services, VPNs and remote access.

  • Internal network

    Segmentation, directory services, management interfaces, paths between zones.

  • Cloud identity

    IAM roles, policies, access keys and trust between accounts.

  • Cloud data

    Storage access, encryption, snapshots and backups.

  • Cloud networking

    Security groups, firewall rules, public endpoints and peering.

  • Logging and detection

    Would anyone notice an attacker, and would the logs show it?

How we test

  1. Scoping

    Ranges, accounts, rules, testing hours, and a read-only role for the cloud review.

  2. Discovery

    Nmap and passive sources map hosts, services and versions.

  3. Configuration review

    Prowler and ScoutSuite against CIS, then IAM and network rules by hand.

  4. Testing

    Every exposure confirmed inside the agreed rules, without disrupting your services.

  5. Attack paths

    How small issues chain, and what they add up to.

  6. Report and retest

    Prioritised fixes, a walkthrough and a free retest.

A report your engineers can act on

  • Severity, evidence, affected assets and a fix for every finding.
  • Configuration findings mapped to the relevant CIS Benchmark.
  • Attack-path notes showing how issues chain.
  • A free retest of fixed findings in an agreed window.

How a finding reads

V-033ExampleSeverity: Critical

Backup storage readable without signing in

Weakness
CWE-732
Where
Cloud storage bucket holding nightly database backups
Impact
Anyone who found the bucket name could download full copies of the database.
Fix
Block public access at the account level, encrypt backups and alert on policy changes.
Fixed · retested

Standards and tools

Findings mapped to
  • PTES
  • NIST SP 800-115
  • CIS Benchmarks
Tools we use
  • Nmap
  • Prowler
  • ScoutSuite
  • Burp Suite
Is it safe to test production infrastructure?

We plan for it. No denial-of-service testing unless you ask, hours agreed in writing, and a contact who can pause us at any time.

What access do you need for a cloud review?

A read-only audit role, such as AWS SecurityAudit with ViewOnlyAccess, or the viewer roles in Google Cloud and Azure. Never write access.

Can you run an internal test remotely?

Yes. A VPN account, or a small test machine you place inside the network for the test.

Do we need permission from our cloud provider?

AWS, Google Cloud and Azure don’t require approval for most testing of your own resources, but each publishes rules. We stay inside them.

Tell us about your infrastructure

Send the scope and your deadline, and we’ll set up a call.