IAM & Access Control
Details
Roles, policies, and service accounts for over-permissions. Cross-account access, least-privilege principle, MFA enforcement for privileged identities, and permission boundaries.
Cloud Security
AWS. Azure. GCP. Misconfigurations are attack vector #1 in the cloud. We audit IAM policies, container security, and network isolation - documented against MITRE ATT&CK Cloud.
Trusted by these organizations
Platforms
We also assess hybrid and multi-cloud environments - including the transitions between on-premises and cloud.
Amazon Web Services
EC2 · S3 · RDS · Lambda · IAM · VPC · KMS · CloudTrail · EKS
IAM policies, bucket permissions, VPC configuration, CloudTrail logging, and EKS cluster security against CIS AWS Foundations Benchmark.
Microsoft Azure
VMs · Blob Storage · App Service · Key Vault · RBAC · NSGs · AKS
Azure RBAC, network security groups, Key Vault access, Defender for Cloud configuration, and AKS cluster security against CIS Azure Benchmark.
Google Cloud Platform
Compute Engine · Cloud Storage · IAM · KMS · VPC · GKE
GCP IAM roles, org policies, Cloud Audit Logs, VPC firewall rules, and GKE cluster hardening against CIS GCP Benchmark.
Assessment Areas
Six critical areas - from access control to monitoring. Each area can serve as an entry point for attackers.
Details
Roles, policies, and service accounts for over-permissions. Cross-account access, least-privilege principle, MFA enforcement for privileged identities, and permission boundaries.
Details
Security groups, NACLs, VPC peering, and private endpoints for unintended exposure. Firewall rules, ingress/egress filters, and network topology for lateral movement opportunities.
Details
S3/Blob/GCS bucket policies for public exposure, encryption at rest and in transit, access logs, and lifecycle policies. Databases for network isolation and backup security.
Details
Container image security, pod security standards, RBAC configuration, network policies, and secrets management in EKS, AKS, and GKE. Admission controllers and runtime security.
Details
Lambda/Functions execution roles for over-permissions, event source injection via S3, API Gateway, or SNS, dependency analysis in deployment packages, and secrets in environment variables.
Details
CloudTrail/Azure Monitor/Cloud Audit Logs for complete coverage across all regions and services. Alerting gaps for security-critical events and SIEM integration weaknesses.
Methodology
Two complementary approaches - combined, they deliver the most complete picture of your cloud security posture.
Configuration Review
Automated and manual review of configuration against CIS Benchmarks and CSA Cloud Controls Matrix. Non-invasive, read-only. No risk to production operations.
Cloud Pentest
Active exploitation of vulnerabilities: privilege escalation in the cloud, service-to-service attacks, and simulated data exfiltration - under controlled conditions.
1 day
Joint definition of assessment scope: which accounts, regions, services, and applications. Setup of read-only access via IAM roles or service accounts. Definition of rules of engagement and prohibited test targets.
2-3 days
Automated review with ScoutSuite (multi-cloud) and Prowler (AWS) against CIS Benchmarks, SOC 2, PCI DSS, and ISO 27001 controls. Generates a complete baseline of all misconfigurations with severity ratings.
ScoutSuite · Prowler · CIS Benchmarks
3-5 days
Deep analysis of IAM policy structure for privilege escalation paths, network topology for unintended transitions, architectural vulnerabilities, and logical access problems that no scanner can detect.
Manual Analysis · Policy Simulator
3-7 days
Active exploitation of discovered vulnerabilities: privilege escalation via over-privileged roles, database access via compromised service accounts, cross-service attacks, and data exfiltration simulation.
Pacu · CloudFox · Custom Scripts
2-3 days
Technical report with CVSS scores, cloud-specific remediation steps, and architectural recommendations. Management summary with risk overview. On request: compliance mapping to TISAX, SOC 2, ISO 27001, or NIS-2.
Shared Responsibility
Cloud security is not solely the provider's responsibility. The Shared Responsibility Model clearly defines who must secure what.
Cloud provider secures
YOU secure
Customer-side misconfigurations are among the most common causes of cloud security incidents according to industry analyses - not provider vulnerabilities. This is exactly where we come in.
Fixed Prices
No hourly rates. No additional charges. Binding quote within 24 hours.
Cloud Configuration Review
from 6,000 EUR
5-8 business days - non-invasive, read-only
Recommended
Cloud Pentest (1 Provider)
from 10,000 EUR
8-12 business days - active testing
Multi-Cloud + Container
from 18,000 EUR
15-25 business days - AWS + Azure + GCP + Kubernetes
Compliance
Our report is structured so it can be used directly as evidence for auditors and authorities.
TISAX
TISAX assessments require evidence that cloud environments are adequately secured. Our report directly covers the relevant TISAX requirement categories.
ISO 27001
ISO 27001:2022 Annex A explicitly addresses cloud service usage (A.5.23). Our assessment maps all findings to the relevant controls for your certification or audit.
SOC 2
For SOC 2 Type II audits, cloud controls must be evidenced over 6-12 months. We identify gaps early and support remediation prior to the audit.
NIS-2
NIS-2 Article 21 requires organizations to regularly review their cloud infrastructure as critical supply chain. Our assessment documents compliance with technical security measures.
You will receive a binding fixed-price quote within 24 hours. No hourly rate. No surprises.
Qualifications
OSCP
Offensive Security Certified Professional
AWS Security
AWS Certified Security - Specialty
AZ-500
Microsoft Azure Security Engineer
ISO 27001 LA
Lead Auditor
CKS
Certified Kubernetes Security Specialist
CCSP
Certified Cloud Security Professional
Why AWARE7 for Your Cloud Pentest
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.
Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.
From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.
More on digital sovereigntyWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.
References
These case studies are available in German.
Everything you need to know before your initial consultation about cloud penetration tests, scope, and pricing.
Related Services
Complementary security services for comprehensive protection.
OWASP Top 10, API Security, Business Logic. Also for cloud-native applications.
Active Directory, firewall bypass, lateral movement. For hybrid cloud environments.
ISMS implementation and certification support. Cloud usage is explicitly addressed in Annex A.
Aus dem Blog
Our certified cloud penetration testers assess AWS, Azure, and GCP for misconfigurations, IAM vulnerabilities, and container security - with a fixed-price commitment from EUR 6,000.
Free · 30 minutes · No obligation
Arturs Nikitins
Initial consultation & needs analysis
Looking for personal advice?
No obligation · Reply within 24h on business days