Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

Cloud Security

Cloud Security Audit & Penetration Test Your cloud. Our offensive.

AWS. Azure. GCP. Misconfigurations are attack vector #1 in the cloud. We audit IAM policies, container security, and network isolation - documented against MITRE ATT&CK Cloud.

AWS / Azure / GCP ISO 27001 Certified OSCP-Certified

Trusted by these organizations

500+
Pentests completed
AWS · Azure · GCP
all hyperscalers from one partner
24h
fixed-price quote committed
0
false positives in final report

Platforms

All major cloud platforms. One point of contact.

We also assess hybrid and multi-cloud environments - including the transitions between on-premises and cloud.

Amazon Web Services

AWS

EC2 · S3 · RDS · Lambda · IAM · VPC · KMS · CloudTrail · EKS

IAM policies, bucket permissions, VPC configuration, CloudTrail logging, and EKS cluster security against CIS AWS Foundations Benchmark.

Microsoft Azure

Azure

VMs · Blob Storage · App Service · Key Vault · RBAC · NSGs · AKS

Azure RBAC, network security groups, Key Vault access, Defender for Cloud configuration, and AKS cluster security against CIS Azure Benchmark.

Google Cloud Platform

GCP

Compute Engine · Cloud Storage · IAM · KMS · VPC · GKE

GCP IAM roles, org policies, Cloud Audit Logs, VPC firewall rules, and GKE cluster hardening against CIS GCP Benchmark.

Assessment Areas

What we assess

Six critical areas - from access control to monitoring. Each area can serve as an entry point for attackers.

01

IAM & Access Control

Details

Roles, policies, and service accounts for over-permissions. Cross-account access, least-privilege principle, MFA enforcement for privileged identities, and permission boundaries.

02

Network Security

Details

Security groups, NACLs, VPC peering, and private endpoints for unintended exposure. Firewall rules, ingress/egress filters, and network topology for lateral movement opportunities.

03

Data Storage

Details

S3/Blob/GCS bucket policies for public exposure, encryption at rest and in transit, access logs, and lifecycle policies. Databases for network isolation and backup security.

04

Containers & Kubernetes

Details

Container image security, pod security standards, RBAC configuration, network policies, and secrets management in EKS, AKS, and GKE. Admission controllers and runtime security.

05

Serverless

Details

Lambda/Functions execution roles for over-permissions, event source injection via S3, API Gateway, or SNS, dependency analysis in deployment packages, and secrets in environment variables.

06

Logging & Monitoring

Details

CloudTrail/Azure Monitor/Cloud Audit Logs for complete coverage across all regions and services. Alerting gaps for security-critical events and SIEM integration weaknesses.

Methodology

Configuration Review + Active Testing

Two complementary approaches - combined, they deliver the most complete picture of your cloud security posture.

Configuration Review

Automated and manual review of configuration against CIS Benchmarks and CSA Cloud Controls Matrix. Non-invasive, read-only. No risk to production operations.

Cloud Pentest

Active exploitation of vulnerabilities: privilege escalation in the cloud, service-to-service attacks, and simulated data exfiltration - under controlled conditions.

1 day

Scoping - Cloud Account Identification

Joint definition of assessment scope: which accounts, regions, services, and applications. Setup of read-only access via IAM roles or service accounts. Definition of rules of engagement and prohibited test targets.

2-3 days

Automated Scanning - CIS Benchmark Checks

Automated review with ScoutSuite (multi-cloud) and Prowler (AWS) against CIS Benchmarks, SOC 2, PCI DSS, and ISO 27001 controls. Generates a complete baseline of all misconfigurations with severity ratings.

ScoutSuite · Prowler · CIS Benchmarks

3-5 days

Manual Analysis - IAM, Network, Architecture

Deep analysis of IAM policy structure for privilege escalation paths, network topology for unintended transitions, architectural vulnerabilities, and logical access problems that no scanner can detect.

Manual Analysis · Policy Simulator

3-7 days

Exploitation - Privilege Escalation, Cross-Service

Active exploitation of discovered vulnerabilities: privilege escalation via over-privileged roles, database access via compromised service accounts, cross-service attacks, and data exfiltration simulation.

Pacu · CloudFox · Custom Scripts

2-3 days

Reporting - Risk-Prioritized Findings

Technical report with CVSS scores, cloud-specific remediation steps, and architectural recommendations. Management summary with risk overview. On request: compliance mapping to TISAX, SOC 2, ISO 27001, or NIS-2.

Shared Responsibility

Your part of the responsibility

Cloud security is not solely the provider's responsibility. The Shared Responsibility Model clearly defines who must secure what.

Cloud provider secures

Cloud provider secures

  • Physical infrastructure and data centers
  • Hypervisor and virtualization layer
  • Network backbone and global infrastructure
  • Hardware and firmware of host systems
  • Availability and reliability of core services

YOU secure

YOU secure

  • IAM configuration, roles, and access rights
  • Network rules, security groups, and firewall policies
  • Data encryption and key management
  • Application security and code quality
  • Operating system hardening and patch management
  • Logging, monitoring, and incident response

Customer-side misconfigurations are among the most common causes of cloud security incidents according to industry analyses - not provider vulnerabilities. This is exactly where we come in.

Fixed Prices

Transparent Fixed Prices

No hourly rates. No additional charges. Binding quote within 24 hours.

Cloud Configuration Review

from 6,000 EUR

5-8 business days - non-invasive, read-only

  • CIS Benchmark Checks (AWS/Azure/GCP)
  • Automated scanning with ScoutSuite/Prowler
  • Manual IAM policy analysis
  • Network and data storage review
  • Risk-prioritized final report
  • Compliance mapping (TISAX, ISO 27001)
  • No impact on production operations

Recommended

Cloud Pentest (1 Provider)

from 10,000 EUR

8-12 business days - active testing

  • Everything from the Configuration Review
  • Active privilege escalation testing
  • Cross-service attacks simulated
  • Container & Kubernetes security
  • Serverless function testing
  • Proof-of-concept exploits included

Multi-Cloud + Container

from 18,000 EUR

15-25 business days - AWS + Azure + GCP + Kubernetes

  • Full assessment of all three hyperscalers
  • Hybrid cloud transitions assessed
  • Multi-cloud identity federation
  • Cross-provider data flow analysis
  • Consolidated overall risk report
  • Dedicated senior consultant
  • Management presentation included

Compliance

Your Cloud Security Assessment as Compliance Evidence

Our report is structured so it can be used directly as evidence for auditors and authorities.

TISAX

Automotive Cloud Usage

TISAX assessments require evidence that cloud environments are adequately secured. Our report directly covers the relevant TISAX requirement categories.

ISO 27001

Annex A Control Mapping

ISO 27001:2022 Annex A explicitly addresses cloud service usage (A.5.23). Our assessment maps all findings to the relevant controls for your certification or audit.

SOC 2

Type II Audit Preparation

For SOC 2 Type II audits, cloud controls must be evidenced over 6-12 months. We identify gaps early and support remediation prior to the audit.

NIS-2

Critical Supply Chain

NIS-2 Article 21 requires organizations to regularly review their cloud infrastructure as critical supply chain. Our assessment documents compliance with technical security measures.

Expose your cloud attack surface: IAM, container escape paths, and network isolation - fully documented.

You will receive a binding fixed-price quote within 24 hours. No hourly rate. No surprises.

Qualifications

Certifications & Qualifications of Our Cloud Testers

OSCP

Offensive Security Certified Professional

AWS Security

AWS Certified Security - Specialty

AZ-500

Microsoft Azure Security Engineer

ISO 27001 LA

Lead Auditor

CKS

Certified Kubernetes Security Specialist

CCSP

Certified Cloud Security Professional

Why AWARE7 for Your Cloud Pentest

What sets us apart from other providers

Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.

Research and teaching as our foundation

20 %

Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.

Digital sovereignty: no compromises

100 %

From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.

More on digital sovereignty

Fixed price within 24h: predictable project timelines

24 h

Within 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.

Your dedicated contact

1:1

A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.

Peer-reviewed publications

First page of the paper: Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

ACM AsiaCCS 2025

Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: A Platform for Physiological and Behavioral Security

A Platform for Physiological and Behavioral Security

NSPW 2025

Jan Hörnemann

First page of the paper: Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

IEEE/IFIP DSN 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: Understanding Regional Filter Lists: Efficacy and Impact

Understanding Regional Filter Lists: Efficacy and Impact

PoPETS 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

Who is AWARE7 the right partner for?

Mid-sized companies with 50-2,000 employees

Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.

IT managers & CISOs

Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.

Regulated industries

Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.

Frequently Asked Questions about Cloud Security Assessments

Everything you need to know before your initial consultation about cloud penetration tests, scope, and pricing.

A Cloud Security Assessment is a structured security review of your cloud infrastructure carried out by certified experts. We analyze IAM configurations, network architecture, data storage, container environments, and logging configurations against established benchmarks such as CIS Controls and CSA CCM. You receive a detailed report with verified findings, CVSS scores, and prioritized recommendations - tailored specifically to your cloud environment.
A Cloud Configuration Review is non-invasive: we receive read-only access to your cloud accounts and check all configurations against CIS Benchmarks and best practices - without active attacks. A Cloud Penetration Test goes further: we actively exploit found vulnerabilities, attempt privilege escalation, lateral movement between services, and simulate real data exfiltration. For a comprehensive security assessment, we recommend combining both approaches.
We assess all three major hyperscalers: Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). We also test hybrid cloud environments with on-premises connectivity and multi-cloud setups. Our testers specialize in the native services of each platform - from AWS IAM and EKS, to Azure RBAC and AKS, to GCP IAM and GKE. For specialized platforms such as Alibaba Cloud or Oracle Cloud, please contact us.
For the Configuration Review, we require a read-only IAM user or service account - we set this up together with you and ensure no write permissions are granted. For active penetration testing, we work with a dedicated test account or a time-limited test access with defined permissions. All access is immediately revoked after testing is complete. We do not process production data on our systems.
A Configuration Review typically takes 5-10 business days, and a Cloud Penetration Test takes 7-15 business days. For multi-cloud assessments across AWS, Azure, and GCP, plan for 15-25 business days. The exact duration depends on the complexity of your environment - number of accounts, regions, service types, and whether containers and Kubernetes are in scope. In a free initial consultation, you will receive a binding fixed-price quote within 24 hours.
The Configuration Review is completely non-invasive and has no impact on your operations. During a Cloud Penetration Test, we conduct active tests in accordance with agreed Rules of Engagement - we never perform destructive actions such as deleting resources or denial-of-service attacks. On request, we test exclusively in dedicated test environments or carry out critical tests outside business hours.
Yes. Container and Kubernetes security is a separate assessment area in every Cloud Assessment. We analyze container image security (vulnerabilities in base images, secrets in layers), Kubernetes RBAC configuration, network policies, pod security standards, secrets management, container runtime security, and admission controllers. For managed Kubernetes services (EKS, AKS, GKE), we additionally review the cloud-specific configurations.
Yes. Serverless security is a frequently overlooked attack vector. We review Lambda/Azure Functions/Cloud Run for over-privileged execution roles, event source injection (e.g., via S3 events or API Gateway), dependency vulnerabilities in deployment packages, environment variables containing secrets, and timeout and memory configurations. Serverless environments often have a fragmented attack surface - we analyze the entire function chain.
Our Cloud Assessment provides mapping to BSI C5 (Cloud Computing Compliance Criteria Catalogue), TISAX for automotive suppliers, ISO 27001 Annex A controls, SOC 2 Type II criteria, and NIS-2 Article 21 requirements for critical infrastructure. We also assess against CIS Benchmarks for AWS, Azure, and GCP, as well as the CSA Cloud Controls Matrix (CCM). You receive a report that can be used directly as evidence for auditors.
Recommendation: at least once a year for a full assessment. Cloud environments change rapidly - new services, new teams, new configurations continuously increase the attack surface. A follow-up assessment should occur immediately after major architectural changes, cloud migrations, or security incidents. Organizations subject to NIS-2 are required to regularly review their cloud infrastructure as critical supply chain. Many clients use our retainer model for bi-annual reviews.

Related Services

Complementary security services for comprehensive protection.

01

Web Application Pentest

OWASP Top 10, API Security, Business Logic. Also for cloud-native applications.

02

Network & Infrastructure

Active Directory, firewall bypass, lateral movement. For hybrid cloud environments.

03

ISO 27001 Consulting

ISMS implementation and certification support. Cloud usage is explicitly addressed in Annex A.

How secure is your cloud infrastructure, really?

Our certified cloud penetration testers assess AWS, Azure, and GCP for misconfigurations, IAM vulnerabilities, and container security - with a fixed-price commitment from EUR 6,000.

Free · 30 minutes · No obligation

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen