Cloud penetration testing

Can a small cloud foothold become broad access?

Controlled attack-path testing across cloud identities, workloads and data access.

From A$6,000 ex GST for one AWS, Azure or GCP account.

Manually verified findings.

  • OSCP-certified testers
  • Written testing boundaries
  • Actionable remediation
What we test

A scope with a purpose.

Identity escalation

Role assumptions and excessive permissions that expand a controlled foothold.

Workload and data access

Exposed services, secrets, storage permissions and control-plane paths.

Account boundaries

Cross-account trust, network paths and separation of sensitive environments.

Before testing

What we need from you

  • Provider, accounts or subscriptions, and critical workloads.
  • Starting access and written authority.
  • Provider-policy constraints and a safe test-data plan.
Use the scoping checklist
After testing

What you can act on

  • Evidence of reachable attack paths.
  • The identities and resources involved.
  • Least-privilege or network fixes, plus paths we could not safely validate.

Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.

Limits matter

What this test does not cover

  • Testing the cloud provider or another customer.
  • Destructive actions.
  • Baseline configuration review. That is a separate deliverable.
The deliverable

See what you will receive

A 19-page illustrative report built from synthetic findings, not a client report. It shows scope, evidence, severity rationale and the retest record.

See sample report

Questions before you book

Practical answers.

Do we need a configuration review instead?

A configuration review checks settings against a baseline. A penetration test validates exploitable paths and impact. If you need the inventory of policy gaps first, start with the review.

What does a penetration test cost?

From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.

How long will it take?

Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.

Ready to price your test?

The sample report is illustrative, built from synthetic findings. It is not a client report.

Get instant quote

Last reviewed: