Bug’s Life — Field Guide to Vulnerabilities
← Field Guide Index
SPC-04CLOUD

Cloud Security

Classification
CLOUD
Method
By hand
Standards
OWASP · PTES
Duration
1–4 weeks
01 · Field Notes
Overview

What this engagement covers

Most cloud breaches come down to misconfiguration, not exotic exploits. We review your cloud accounts against provider and industry best practice — identity, network, storage, logging and more — and show you the handful of changes that most reduce your risk.

02 · Test Coverage
What we test
Identity & access (IAM)
  • Over-privileged users, roles and service accounts
  • Unused credentials, stale access keys and missing MFA
  • Privilege-escalation paths and risky cross-account trust
Network exposure
  • Open security groups / NSGs and public IPs
  • Exposed management ports and services
  • Weak segmentation between workloads and environments
Storage & data
  • Public or world-readable buckets, blobs and disks
  • Encryption at rest and in transit
  • Key management (KMS) and secret handling
Logging, detection & workloads
  • CloudTrail / activity logging and monitoring gaps
  • Insecure defaults and unpatched compute
  • Container / Kubernetes and serverless posture (as scoped)
Providers
  • AWS, Azure and GCP — single or multi-cloud
  • Benchmarked against CIS and provider best practice
03 · Specimen Range
Scope of work
  • a.AWS, Azure and GCP configuration and posture review
  • b.Identity and access management (IAM) and privilege review
  • c.Network exposure, storage and encryption checks
  • d.Logging, monitoring and detection gaps
  • e.Benchmarked against CIS and provider best practice
04 · Field Method
How we work
01

Scope & rules of engagement

We agree targets, timing, depth and constraints in writing before anything starts — so testing is safe, authorized and focused on what matters to you.

02

Manual testing

Certified testers work by hand — following recognised methodologies like OWASP and PTES, not just automated scanners — chaining findings the way a real attacker would to prove genuine impact.

03

Reporting

You get a prioritized report with clear proof-of-concept, business impact and step-by-step remediation your engineers can act on immediately.

04

Retest

After you fix, we re-test the findings to confirm they are resolved and issue an updated report you can share with customers or auditors.

05 · What you keep
Deliverables
  • A prioritized list of misconfigurations and risks
  • Concrete, least-privilege remediation steps
  • Quick wins that cut exposure fast
  • Guidance to keep your posture strong as you grow
06 · Field Q&A
Common questions
Which providers do you cover?

Amazon Web Services, Microsoft Azure and Google Cloud Platform — individually or across a multi-cloud estate.

Do you need admin access?

A read-only, scoped role is usually enough for a posture review. We will tell you exactly what access we need and why before we begin.

Specimen request

Ready to get started with Cloud Security?