Home / Continuous / Cloud
Cloud
Cloud configuration drifts constantly, and a permission added to unblock a release on Friday is still there in March. This module watches for that.
What it covers
- Storage exposure: public buckets and containers, and objects reachable without authentication
- IAM permissions, over-permissive roles and privilege escalation paths between them
- Network exposure created by cloud configuration rather than by a host
- Key material and secrets in metadata, environment configuration and build settings
- Logging and audit configuration, to the extent it affects your ability to see an incident
How the work is carried out
A consultant directs this module and does the work that needs judgement, with automation carrying the continuous load between their passes. Your intervals are set during onboarding and recorded in the service agreement, because a schedule that suits one application would be wrong for a large, sprawling estate. What is fixed is the shape: a scheduled layer that runs the same checks on fixed intervals so change is visible, and an exploratory layer that a consultant directs based on what turns up. Reporting is monthly.
What the tooling handles
- Keeps configuration review running across every account and subscription in scope
- Flags change on IAM policy and storage exposure as it happens
- Enumerates non-destructively only, using read-only access
What our consultants do
- Work through the configuration and permission model directly, account by account
- Trace privilege escalation paths and decide which are materially exploitable
- Validate escalation by attempting it where it is safe and authorised to do so
- Confirm every finding before it is reported
Every finding in this module is reproduced or confirmed by a consultant before it reaches you.
What you receive
- Validated findings, each reproduced or confirmed by a consultant
- A monthly written report, including what changed since the last one
- Critical and high findings notified within one business day of validation
- A record of configuration change across the period
- Verification of fixes once you have applied them
What is out of scope
- The cloud provider's own infrastructure, which is not yours or ours to test
- Application-layer testing of workloads, which is the Access module
- Denial-of-service testing, which is blocked by default
- Cost optimisation and architecture consulting, which is not a security service
Prerequisites
Nothing runs until these are in place. We pause rather than proceed against an unconfirmed register.
- A read-only audit role in each account, subscription or project in scope
- An inventory of accounts, subscriptions or projects
- Signed authorisation from someone entitled to grant that access
- A confirmed asset register