Cloud & Identity Security Review

One leaked credential should not empty your tenant. We trace the attack paths an intruder would actually take — then help you close them.

Why this matters: The Snowflake-era breaches settled the argument: attackers stopped breaking cloud platforms and started logging into them. One unrotated CI key, one identity without MFA, one over-privileged service account — our cloud case-study series traces how a single credential emptied tenant after tenant. Identity is the perimeter now; we review it that way.

What we cover

  • AWS, Azure, and GCP IAM: privilege paths and escalation routes
  • Federation and SSO configuration — Keycloak, Entra ID, Okta
  • Secrets management: sprawl, rotation, CI/CD key exposure
  • MFA coverage and phishing-resistant methods
  • Token lifetimes, consent grants, and stale credentials
  • Network segmentation, storage exposure, and blast radius
  • Logging and detection coverage — what would you actually see?

How we test

1Read-only configuration review

We start from read-only access: users, roles, policies, grants, and trust relationships across your tenant(s).

2Attack-path simulation

From realistic starting points — one leaked key, one phished admin — we trace how far an intruder could actually reach.

3Identity abuse testing

Agreed, controlled tests of token handling, consent, and federation edge cases within the rules of engagement.

4Prioritized roadmap

Findings sorted by real attack path, not checklist severity, with a sequenced remediation plan and a verification pass.

What you get

  • Config findings with attack paths, not just checklists
  • Identity perimeter scorecard for leadership
  • Zero-trust gap analysis with a sequenced rollout plan
  • Verification pass after remediation

The engagement at a glance

📞 Free scoping call

A short conversation about your environment. You receive a written scope, timeline, and fixed quote — no obligation.

✍️ Signed authorization

Testing begins only with your written permission and agreed rules of engagement. Always.

⏱️ Time-boxed delivery

A calendar agreed before we start, with an agreed communication plan while testing runs.

🔁 Retest included

A verification pass over everything you fix — included in the price, not an add-on.

See the full engagement process → and how pricing is scoped in our public pricing guide.

Related research from Hmmnm

Common questions

Do you need write access to our cloud?

No. The core review is read-only. Any active testing happens only with explicit written authorization and tightly scoped, time-limited test identities.

We run multiple clouds — can you cover all of them?

Yes. Multi-cloud identity sprawl is exactly where attack paths hide — shared credentials, mirrored misconfigurations, and federation trust between platforms.

Can findings support ISO 27001 or SOC 2 evidence?

The report is structured to slot into audit evidence for access-control and monitoring controls, though we are not the certification body itself.

Authorization first, always. Testing happens only with your written permission and agreed rules of engagement — the same ethics that govern responsible disclosure on this site.

Want this assessed for your environment?

A short scoping conversation is enough to get a fixed quote. No obligation — a researcher replies.

Start the conversation →