Skip to content
Penetration testing
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
All services on one page
Industries How we work About Blog
1300 AURIAN Contact
Menu
Penetration testing
  • Penetration testing services
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Security assurance and compliance services
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Managed security services
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
  • All services
  • Industries
  • How we work
  • About
  • Blog
Call 1300 AURIAN Contact
  1. Services
  2. Penetration testing
  3. Cloud security assessment

Penetration testing

Cloud security assessment

We review your cloud configuration against the benchmarks and then test the attack paths that configuration alone will not reveal.

Scope a test Call 1300 AURIAN

Who this is for

  • You have moved workloads to the cloud

    Cloud shifts the risk from patching servers to configuring identity and access, and the defaults are rarely the safe choice.

  • Identity is now your perimeter

    In Microsoft 365 and Entra ID, a single over-privileged account or a gap in Conditional Access is the way in.

  • You need to show the cloud is configured to a standard

    Auditors, customers and insurers ask whether your cloud meets a recognised benchmark, and you want an independent answer.

What our cloud security assessment covers

Internet Web application API Perimeter Cloud tenancy Email Office network Workstation Identity Wireless Crown jewels Servers INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. PERIMETER: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. CLOUD TENANCY: CHECKS INCLUDE CIS Benchmark configuration review Public exposure of storage, services and secrets Logging, monitoring and landing zone design Network paths between workloads and to the internet EMAIL: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. OFFICE NETWORK: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WORKSTATION: NOT IN SCOPE HERE Covered by essential Eight assessment. Click to open that service. IDENTITY: CHECKS INCLUDE Entra ID and Conditional Access policy Privilege escalation through roles and service principals MFA coverage and legacy authentication WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. CROWN JEWELS: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. SERVERS: NOT IN SCOPE HERE Covered by configuration review and benchmarking. Click to open that service. Internet Web application Perimeter API Email Cloud tenancy Office network Workstation Wireless Identity Crown jewels Servers INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. PERIMETER: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. EMAIL: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. CLOUD TENANCY: CHECKS INCLUDE CIS Benchmark configuration review Public exposure of storage, services and secrets Logging, monitoring and landing zone design Network paths between workloads and to the internet OFFICE NETWORK: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WORKSTATION: NOT IN SCOPE HERE Covered by essential Eight assessment. Click to open that service. WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. IDENTITY: CHECKS INCLUDE Entra ID and Conditional Access policy Privilege escalation through roles and service principals MFA coverage and legacy authentication CROWN JEWELS: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. SERVERS: NOT IN SCOPE HERE Covered by configuration review and benchmarking. Click to open that service.

We assess your cloud tenancy against the CIS Benchmarks and then test the identity and exposure attack paths, because configuration and exploitation each find what the other misses.

  • Identity and access management, including roles, permissions and privilege escalation paths
  • Conditional Access, multi-factor authentication and legacy authentication in Entra ID
  • Publicly exposed storage, databases, functions and management interfaces
  • Secrets management, and secrets found in code, pipelines and configuration
  • Network configuration, including security groups, peering and private endpoints
  • Logging and monitoring coverage, and the gaps an attacker would exploit
  • Landing zone and account structure against the platform's own guidance
  • Microsoft 365 hardening, covering mail flow, sharing and administrative roles

How we test it

Moving to the cloud does not remove risk so much as move it, from patching servers to configuring identity, access and exposure. The platforms are secure by design and insecure by default, and the difference between the two is configuration that is easy to get subtly wrong across hundreds of resources. Aurian’s cloud security assessment combines a configuration review against the CIS Benchmarks with attack-path testing, because each finds what the other misses.

The configuration review is evidence-based and read-only. Using an auditor role, we gather the actual state of your tenancy and measure it against the CIS Benchmarks and the platform’s own baselines, across identity, storage, network, logging and the account structure itself. That produces a clear picture of where you differ from the standard. On its own, though, a list of deviations does not tell you which ones matter, and a long report of low-severity settings can bury the one that lets an ordinary account take over the tenancy.

So we also test the attack paths. A consultant maps who can reach what, follows the routes by which a standard identity could escalate, and tests the public exposure in practice, safely and within agreed limits. In Microsoft 365 and Entra ID, where identity is the perimeter, that means Conditional Access, legacy authentication and administrative roles get particular attention. The report maps every finding to the benchmark and ranks it by what an attacker could actually do, and we retest the findings rated high or above once you have remediated.

Standards CIS Benchmarks, ASD Blueprint for Secure Cloud, Microsoft and AWS security baselines

  1. 01 Configuration review

    We assess the tenancy against the CIS Benchmarks and the platform's own baselines, using read-only access to gather evidence.

  2. 02 Identity analysis

    We map who can reach what, and the paths by which an ordinary account could escalate to control of the tenancy.

  3. 03 Attack-path testing

    We test the exposure and escalation paths in practice, safely, to show which findings are theoretical and which are reachable.

  4. 04 Reporting and retest

    You receive findings ranked by severity and mapped to the benchmark. Once you have remediated, a retest of the findings rated high or above confirms what is closed and the report is updated. Retesting is quoted with the test or booked afterwards.

What you receive

Every finding in an Aurian report looks like this: what we found, the evidence, what it means for you, and what to change.

Catastrophic AUR-2026-014 Sample finding, fictional environment

Public storage bucket exposes database backups

Affected asset
s3://example-prod-backups (ap-southeast-2)
Rating
Catastrophic Almost certain 5 × Critical 6 = 30

Description

A storage bucket holding nightly database backups is configured for public read access. Anyone who knows or guesses the name can download the full backups, which include customer records and password hashes, without any credentials.

Evidence

$ aws s3 ls s3://example-prod-backups --no-sign-request
2026-09-05 02:00  4.2 GiB  prod-db-2026-09-05.sql.gz
2026-09-04 02:00  4.2 GiB  prod-db-2026-09-04.sql.gz
# --no-sign-request means no credentials were used

The backups were listed and downloadable with no credentials, using an unauthenticated request.

Impact

A full copy of the production database, including customer personal information and password hashes, is downloadable by anyone on the internet. A breach on this scale is what the Notifiable Data Breaches scheme exists for, and backups are a favoured target precisely because they hold everything in one place.

Remediation

Block public access at the account and bucket level, and confirm no other bucket is public. Encrypt backups, restrict access to a named role, and enable access logging. Rotate any credentials contained in the exposed data, and assess whether the exposure is already notifiable.

References

  • CIS Amazon Web Services Foundations Benchmark
  • ASD, Blueprint for Secure Cloud
  • Executive summary written for the board and the insurer, in plain language
  • Technical findings ranked by severity and mapped to the CIS Benchmark
  • The identity attack paths drawn out, from ordinary account to tenancy control
  • Remediation guidance your own engineers can apply without calling us

Common findings

What this kind of engagement typically surfaces, so you can recognise your own environment.

  • Over-privileged identities

    Users, roles and service principals with far more access than they use, and paths by which one can escalate to administrator.

  • Public exposure

    Storage, databases, functions and management ports open to the internet, often left from a test that was never locked down.

  • Gaps in Conditional Access

    Legacy authentication still enabled, multi-factor authentication not enforced for all users, or exclusions that swallow the policy.

  • Secrets in code and pipelines

    Keys and credentials committed to repositories or baked into build pipelines, granting access to whoever finds them.

  • Insufficient logging

    Audit logging disabled or short-lived, so an attacker's actions leave no trace and an incident cannot be reconstructed.

  • Weak landing zone design

    Flat account structures and shared administrative access that let a problem in one workload reach the others.

Frequently asked questions

Is this a configuration review or a penetration test?

Both, and that is the point. A configuration review against the CIS Benchmarks tells you where you differ from the standard. Attack-path testing tells you which of those differences an attacker could actually use. Run together, they separate the urgent from the merely non-compliant.

Which platforms do you assess?

AWS, Microsoft Azure, Microsoft 365 and Google Cloud. Many clients run more than one, and we assess the identity that spans them, because that is often where the weakest link sits.

What access do you need?

Read-only access is enough for most of the work: a security-auditor role in the cloud platform and a reader role in the tenancy. For attack-path testing we agree in advance exactly what we will attempt and against which resources.

Will the assessment affect production?

The configuration review is read-only and cannot. Attack-path testing is scoped carefully and agreed in writing, and we avoid anything that would affect availability.

How long does it take?

It depends on the number of accounts, subscriptions and services: typically five to ten days of assessment, with the report following. We confirm the timeframe after scoping.

Related services

Configuration review and benchmarking

Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

API penetration testing

API penetration testing for REST, GraphQL and SOAP against the OWASP API Security Top 10: authorisation, rate limiting and undocumented endpoints.

Internal network penetration testing

Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

Penetration testing services

Scope a test with a senior consultant

Tell us what you need to know about your environment. We reply within one business day.

Scope a test Call 1300 AURIAN

Aurian Security is an Australian penetration testing and security assurance firm. Senior consultants perform every engagement, for clients across the country.

Penetration testing

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation

Assurance and managed

  • Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
  • Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring

Company

  • About Aurian
  • How we work
  • Industries
  • Blog
  • Contact
  • Privacy policy
526/368 Sussex St, Sydney NSW 2000 1300 AURIAN (1300 287 426) sales@aurian.com.au

© 2026 Aurian Security Pty Ltd. ACN 639 930 528.

This site is static, loads no third-party trackers, and publishes a security.txt.