Skip to content
Safestorm
Menu

Core service

Cloud Security Assessments

Risk-led assessment of cloud identity, configuration, data exposure and paths to control-plane compromise.

A cloud security assessment evaluates how identities, resources and trust relationships are configured across the agreed cloud estate. Rather than producing a configuration checklist alone, Safestorm investigates how weaknesses could be combined to access sensitive data, escalate privileges, establish persistence or reduce defensive visibility.

Founder-led technical delivery

Why Safestorm for this assessment

Felix applies offensive-security and enterprise identity experience to cloud control planes, where a small IAM or trust mistake can have broad consequences. The assessment follows permissions and relationships to realistic outcomes instead of treating every configuration deviation as equally important.

  • More than six years’ offensive-security experience
  • OSCP and OSEP certified
  • Red teaming, adversary simulation and control validation
  • Published IPv6 research presented at BSides London

Felix’s prior experience includes identifying high-impact weaknesses in healthcare environments. Client identities and engagement details remain confidential.

What the assessment covers

Final coverage is agreed during scoping and reflects your technologies, user roles, threat model and operational constraints.

  • Cloud inventory, organisation or tenant structure and externally exposed resources
  • IAM roles, policies, service principals, managed identities and privilege boundaries
  • Federation, SSO, cross-account or cross-subscription trust and conditional access
  • Public and unintended access to storage, databases, snapshots and secrets
  • Network controls, private endpoints, security groups and management-plane exposure
  • Compute, serverless, container and managed-service configuration within scope
  • Key management, secret handling, metadata services and deployment credentials
  • Logging, alerting, security-service coverage and opportunities for defence evasion

Common risks identified

Testing is not limited to this list. These examples illustrate the types of material risk the assessment is designed to uncover.

  • Over-permissive identities enabling direct or chained privilege escalation
  • Public or cross-tenant exposure of sensitive cloud data
  • Long-lived keys and deployment secrets providing persistent access
  • Unsafe federation or resource policies extending trust beyond intended boundaries
  • Incomplete logging preventing investigation of control-plane activity

A controlled process

How the engagement works

  1. Step 1

    Define providers, accounts, subscriptions, projects and assessment objectives

  2. Step 2

    Agree least-privilege review access and safe-testing constraints

  3. Step 3

    Inventory identities, resources, exposure and trust relationships

  4. Step 4

    Analyse IAM, configuration, data access and escalation opportunities

  5. Step 5

    Validate material attack paths without disrupting cloud workloads

  6. Step 6

    Report, debrief cloud owners and retest priority remediation

Who this service is suitable for

  • AWS, Microsoft Azure and Google Cloud environments
  • Cloud estates following migration, acquisition or major architecture changes
  • Organisations wanting deeper assurance than a native configuration scan
  • Teams validating IAM design, external exposure and security monitoring

Not sure whether this is the right assessment? Safestorm can help define the assurance question before recommending a scope.

Methodology and industry references

Testing is risk-led and tailored rather than reduced to a checklist. Relevant, recognised guidance helps structure coverage and communicate results.

Referencing a framework does not represent certification against it or guarantee compliance with every control.

Frequently asked questions

Is this a cloud configuration review or a penetration test?

It can include elements of both. The exact engagement may combine configuration and IAM analysis with controlled validation of exploitable paths. The proposal states clearly which accounts, resources and testing activities are included.

What access is required?

A least-privilege read-only or security-review role is normally used first. Any active validation requiring additional permissions is agreed separately and recorded in the rules of engagement.

Does the assessment certify compliance with CIS or CSA guidance?

No. Relevant controls may inform coverage and recommendations, but the assessment is not a certification or guarantee of compliance with an entire framework.

Define the right scope

Tell us what you need to assess, your timescale and the assurance outcome you need. We will propose a proportionate scope and clear rules of engagement.

Discuss your requirements