CLOUD PENETRATION TESTING

Secure your AWS, Azure and GCP, for real.

In the cloud, the perimeter is not your firewall, it is who can assume which role. Most cloud breaches are not a single exploit but a chain: an exposed bucket, a leaked key, an over-permissioned role, a hop into the next account. We attack that chain by hand, across AWS, Azure and GCP, and prove which one actually reaches your data.

How a cloud pentest works
87%
of our clients renew annually
150+
organisations across multiple European countries
7/10
confirm findings their previous provider did not find
Want to know what your cloud actually exposes? Share your main concern and your email.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Trusted by cloud and security teams in highly regulated environments

Identify how an attacker moves through your cloud.

Public exposure
buckets · APIs · IPs
Secrets & repos
git · CI · images
IAM & policies
roles · trust · SCP
Compute
Lambda · EKS · K8s
STS & sessions
AssumeRole · ext-id
Object storage
S3 · Blob · GCS
Databases
RDS · SQL · snapshots
Keys · KMS
decrypt · grants
Data plane reached · S3 list+get · RDS snapshot exfiltration · KMS decrypt · organisation administrator role within reach

Your cloud does not live in one place. It lives in APIs, permissions, configurations, secrets scattered across hundreds of services. An attacker who gets in through a single door can reach all the others if the permissions are badly thought out. We test from the position of an attacker with minimal access: what they can do in your cloud with nothing, what side doors sit between services, where credentials and forgotten keys are left behind. The cloud attack surface is almost always bigger than you think.

WHAT WE TEST
  • Identity and access: roles, trust policies and SCPs
  • Privilege escalation: a limited role turned administrator
  • Public exposure: buckets, instances and open APIs
  • Secrets left in repos, CI/CD pipelines and images
  • Cross-account and cross-project pivots
  • Containers and serverless: Kubernetes, Lambda, functions
  • The data itself: object storage, databases and KMS keys
  • Detection blind spots: what your logging never sees

Why a CTO, CISO or cloud lead books a cloud pentest.

It is rarely routine. A landing-zone rollout, a new account structure, a migration, a CSPM alert that will not close, or a customer’s security questionnaire forces the question.

TAP A SITUATION
Compliance & audit ISO 27001 audit window

An auditor does not accept a marketing PDF, and a cloud handling card or personal data raises the bar.

With PCI DSS, ISO 27001, ENS or SOC 2 on the line, the report has to survive scrutiny: traceable scope, a methodology mapped to recognised cloud standards, signed retest and an execution certificate.

  • Methodology mapped to the CIS Benchmarks, MITRE ATT&CK Cloud, PTES and NIST SP 800‑115
  • Segmentation and cardholder-data reachability tested and documented
  • Execution certificate ready for the auditor folder
  • Retest evidence with timestamps and signoff
Board & customer Enterprise customer security questionnaire

Someone with authority asked, and ‘we’re fine’ isn’t an answer.

When the ask is for assurance, you need an external, expert-led pentest and a deliverable that turns what a single exposure reaches into business impact, in language a non-technical stakeholder can read.

  • Executive summary that lands without translation
  • Findings ranked by business impact and audit exposure
  • Blast radius stated plainly: how far one exposure actually reaches
  • Independence: external and expert-led throughout
Change / migration Landing-zone rollout

You are changing the cloud. Verify the change landed.

Every federation, SSO or cross-account trust change moves who can assume which role. We enumerate with a read-only role first, then attempt the escalation and the hop, and retest after the fix.

  • Scope tuned to the change being shipped
  • Roles, trust policies and guardrails tested by attempting the escalation
  • Cross-account and cross-project hops attempted, not inferred from the diagram
  • Retest gates closure, not just the report
Incident-driven Anomalous IAM activity in the logs

Something looked off. You need to know what is still exposed.

The question is not ‘do we have findings’ but ‘which of them actually reaches our data’. We attempt the suspected path by hand across AWS, Azure and GCP, and map the adjacent routes a real attacker would take.

  • Targeted scope around the suspected identity or exposure path
  • Adjacent paths mapped: roles and trust policies, escalation, cross-account hops, secrets
  • Posture findings triaged by whether they are actually reachable and exploitable
  • Detection blind spots reported next to the path, so your responders see the gap
Business event Newly acquired cloud estate

A transaction handed you accounts you did not build.

We enumerate the accounts, the roles and the trust between them, then prove which single exposure reaches production data or the control plane, so what you are taking on is evidence rather than an assurance.

  • Scope agreed against the accounts as they are, not as the diagram describes them
  • Trust between accounts and projects tested by attempting the hop
  • Findings ranked by business impact, in language a non-technical reader follows
  • Retest to closure, so the integration starts with the gaps closed

Ready to see what your cloud opens to?

Book a call
Thirty minutes with an experienced pentester.

A seven-phase method, for your cloud security pentesting.

Seven phases, the way we actually run them across AWS, Azure and GCP. The short version is below; the full step-by-step lives on its own page.

What you actually get, and why it is different.

Most cloud reviews hand back a CSPM export. Here is where we go further.

Chains, not a checklist

A scanner lists hundreds of misconfigurations and cannot say which ones connect. We prove the chain that reaches your data, so you fix the path, not the noise.

Every major cloud, tested the way it breaks

AWS, Azure and GCP each break in their own way. We test yours on its own terms, Kubernetes and serverless included, not one checklist stretched across three.

Read-only by default, safe on production

We enumerate with a read-only role and exploit only within agreed rules, so you get an attacker’s view of your live environment without risking it.

Closed, not just reported

Findings arrive live in our platform, and a free retest confirms each fix against the original proof.

Want to see what your next cloud pentest with us would look like?

We at Etnia highly value our collaboration with Asperis Security.
Sergi Leno, Systems Manager · ETNIA Barcelona

Loved by engineering and security teams.

Names, roles and companies on the record.

We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
Sergi Leno, Systems Manager
ETNIA Barcelona
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
Jordi Bondia, IT Director
SALVI
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
Sergi Laencina Verdaguer, CISO
NPAW
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Juan Valer Tecedor, Software Engineer
GNOSS
READY WHEN YOU ARE

Want a real Cloud Pentesting scope?

An experienced consultant will reply.

Questions that come up before signing.

Cloud penetration testing is a manual security assessment of your AWS, Azure or GCP environment, focused on how an attacker would move through it, from public exposure and leaked secrets, through over-permissioned identities, to your data and control plane. It goes beyond listing misconfigurations to prove which ones chain together into a real path to compromise. The deliverable is a short set of proven attack chains, ranked by business impact, each with a reproducible proof of concept.

No. A CSPM or config review lists misconfigurations against a benchmark; it cannot tell you which of them actually connect into a breach. A cloud pentest is a person proving the chain: this public bucket holds this key, which unlocks this role, which reaches this database. A CSPM is excellent for continuous hygiene; a pentest tells you where you are genuinely exposed right now. Most mature teams run both, and we often start from your CSPM output to focus the engagement.

Yes, all three, plus the Kubernetes and serverless layers on top of them. Each provider has its own identity and service model, so a flaw pattern in AWS often looks different in Azure or GCP; we test each on its own terms rather than applying one generic checklist. If you run a multi-cloud or hybrid estate, we scope across it and pay particular attention to the trust relationships between environments.

No. Our default posture is read-only enumeration using a role you provide, and controlled exploitation only within agreed Rules of Engagement. We do not run destructive tests, and any action that could affect availability or trigger a real incident response requires explicit written approval with your team on standby. You get an attacker’s view of your live environment without risking it.

A single-account, single-provider environment typically takes one to two weeks of active testing; larger multi-account, multi-region or multi-cloud estates, or those with heavy Kubernetes use, run two to four weeks. Scoping happens beforehand and the retest follows your fixes. We confirm the timeline in the proposal, delivered within 48 hours of the first call.

Price follows scope: the number of accounts and providers, the size of the estate, and whether Kubernetes and serverless are included. We quote a fixed price with no hidden fees and no obligation to renew. A single-account assessment sits at the bottom of the range; large multi-cloud estates scale from there. The retest that confirms your fixes is always included.

For the most efficient engagement, a read-only role in the accounts in scope (we provide the exact policy), an architecture overview and one technical contact for questions. We can also test purely from the outside with no access, mirroring a real attacker, but a read-only role lets us cover far more ground in the same time. You decide the model on the introductory meeting.

The senior specialist you meet on the first call runs it end to end. Our team holds OSCP, OSCE³, OSWE and OSEP credentials, adds cloud-specific expertise (AWS, Azure and GCP security certifications, plus Terraform and Kubernetes familiarity), and we are NASA Bug Bounty verified contributors. The same person scopes, executes and retests. You work with that specialist at every stage of the engagement.

Ready to prove your cloud is secured?

Start with a no-obligation introductory meeting. We will review your providers, your account structure and your sensitive data, and define the right cloud pentest before the project begins.

Request a cloud pentest proposal.
An experienced cloud pentester replies within one business day. You talk to the person who runs the test.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Or email [email protected] directly.

OUR CLIENTS HAVE ALREADY DONE IT

We at Etnia highly value our collaboration with Asperis Security.

Sergi Leno, Systems Manager
ETNIA Barcelona

ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.

Jordi Bondia, IT Director
SALVI

At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.

Sergi Laencina Verdaguer, CISO
NPAW

With Asperis you don’t hire a service. You hire a partner.