Cloud & devices

Cloud configuration review

A configuration-led review of your cloud tenants — identity, exposure, data and logging — that finds the privilege escalation paths and quiet public exposures a checklist tool reports as green.

8
areas covered
5
stages, scoping to retest
In-house
testers, never subcontracted
portal.cyberlysecure.com/acme-health/coverage
Acme Health — Test coverage4 practices · 15 services · one team
In-house
Web app
API
SaaS
Mobile
Client-side
External
Internal
Segment test
Wireless
Cloud config
Hardware & IoT
AI & LLM
Social eng.
Physical
Red team
ApplicationsNetworkCloud & devicesPeople & premises
6 in scope · one team · one report
In-house testers 0 subcontracted
Every surface one team
What this is

What the test covers.

Cloud breaches are rarely exploits. They are permissions: a role that can assume another role, a key with no expiry, a storage bucket that was public for one migration and never changed back.

We review your configuration with read access, map how identity actually flows, and show which chains would let a low-privilege principal end up owning the tenant.

CIS Benchmarks Cloud provider security best-practice guidance NIST SP 800-53 control families

What we test

  • Identity and access: roles, policies, trust relationships and privilege escalation paths
  • Over-permissive service accounts, long-lived keys and unused credentials
  • Public and over-shared storage, databases, snapshots and images
  • Network exposure: security groups, firewall rules and public endpoints
  • Key and secret management, encryption at rest and in transit
  • Logging, monitoring and detection coverage — whether an incident would be reconstructable
  • Backup, recovery and deletion protection
  • Microsoft 365 and Entra ID: conditional access, legacy authentication, guest access and sharing
How it runs

From scoping call to retest, here’s what happens.

Typically one to two weeks, depending on the number of accounts and services.

1

Scope and access

We agree which tenants and subscriptions are in scope and receive time-boxed read-only access.

2

Collect the configuration

We gather identity, network, data and logging configuration across the estate.

3

Map the paths

We work out which principals can become which other principals, and where that ends.

4

Prove what matters

Where you authorize it, we validate the highest-impact paths rather than only describing them.

5

Report, readout and retest

Findings are ranked by what they would let an attacker do, with a readout and a retest after remediation.

What it surfaces

The kind of thing this test tends to find.

Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.

A path from a low-privilege role to tenant-wide administration

Access keys years old, still valid, belonging to people who have left

Storage or snapshots readable by anyone who knows the address

Conditional access policies with exclusions that swallow the rule

Logging switched off, short-retention or never delivered anywhere anyone looks

Getting started

What you get, and what we need from you.

What you get

  • Technical report — Every finding, the evidence behind it and clear guidance your engineers can act on.
  • Executive summary — Your risk explained in plain language for leadership and the board.
  • Attestation letter — Signed confirmation of testing to hand your auditors.
  • Readout call — A walkthrough with the people who tested your systems.
  • Retest — Confirmation your fixes worked, documented for whoever needs to see it.

What we need from you

  • Read-only access to each tenant, subscription or project in scope
  • A list of the accounts and environments you consider production
  • Any compliance framework you are being measured against
  • One named contact for the duration of the review

Missing something on this list? Bring it to the call — we scope around what you have.

Free attack-surface snapshot

Give us a domain. See what an attacker sees.

Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.

  • Internet-facing hosts
  • Exposed services
  • Leaked credentials
  • TLS certificate hygiene

Request your snapshot

Free. No obligation.

We only ever test assets you own, with your written authorization.