Cloud security assessment is the testing and review of cloud services and SaaS (Software-as-a-Service) which play an increasing role in the provision of services to business and customers.
Activities include assessing configurations, procedures and workloads to identify vulnerabilities and understand how issues could be exploited in practice
By assessing environments organisations can improve the security posture of cloud services which are critical to business operation and customer services.
By identifying and addressing weaknesses in procedures and technical controls, organisations can reduce the likelihood of successful attacks, limit business disruption, and protect users.
Cloud security testing initiates with threat modelling gaining an understanding of the cloud, DevOps, and SaaS environments in scope. This includes reviewing architecture, services in use, and workloads to identify areas of risk and inform testing priorities.
Testing involves security configuration reviews and targeted penetration testing, guided by vendor best practice, industry guidance such as CIS benchmarks, and our experience.
Assessments can include public cloud platforms such as AWS, Azure, Oracle Cloud and Google Cloud, commonly used SaaS platforms, such as M365 and Google Workspace, DevOps platforms including GitHub, GitLab and Container orchestration such as Kubernetes and OpenShift.
No, not strictly. This service focuses on assessing configuration, access controls, and security posture rather than exploitation, although risk is evaluated from a threat-led perspective.
However, cloud and SaaS are often within the scope of Adversary Simulation and Scenario testing.
No. The service provides assessment and reporting only. Reports include clear, risk-based mitigation recommendations, but implementation is not included.
Yes. Assessments consider how data is stored, accessed, and protected within SaaS platforms, including configuration and access controls.
Yes. Identity and access configuration is a core focus, including roles, permissions, and privilege management across cloud and SaaS platforms.
Assessments are non-intrusive and based on review and analysis of configuration and controls.
Common triggers include initial adoption, major configuration changes, onboarding new SaaS platforms, or periodic assurance reviews
The shared responsibility model defines how security responsibilities are split between the cloud or SaaS provider and the customer.