Opulence.
Cybersecurity

Network & Cloud Security Assessment

External and internal network tests and AWS, Azure and Google Cloud configuration reviews.

The perimeter is now an internet-facing estate plus a cloud console. We test both: external and internal network penetration testing to find the paths into and across your infrastructure, and cloud configuration reviews to find the identity, storage and network settings that attackers rely on.

The output is an attack-path map and a prioritised hardening plan, so fixes go where they cut the most risk.

How we're different
  • We chain findings into attack paths so you see how an intrusion would actually unfold.
  • Cloud reviews go beyond benchmark checklists to the misconfigurations attackers use.
  • Our IT consultants can implement the hardening plan if your team is stretched.
Who this is for
  • A bank or airline with a large on-premises estate, several cloud accounts and one identity provider tying them together.
  • A manufacturer or logistics group whose operational sites connect to the corporate network.
  • A company that has just completed a cloud migration and has never had the result tested.
Signals you need this now
  • Nobody has a full list of internet-facing hosts.
  • Cloud accounts were created by project teams outside central control.
  • Privileged accounts exist without multi-factor authentication.
  • Active Directory has grown for years without a review of paths to domain admin.
Scope of work

What is included.

  1. 01

    External network testing

    Internet-facing hosts and services enumerated and tested for exploitable weaknesses.

  2. 02

    Internal network testing

    Assumed-breach testing from inside, including Active Directory and lateral movement.

  3. 03

    Cloud configuration review

    IAM, storage, networking, logging and workload settings reviewed against benchmarks and real attack paths.

  4. 04

    Microsoft 365 and identity review

    Tenant configuration, conditional access, MFA coverage and privileged accounts.

  5. 05

    Hardening plan

    Prioritised fixes with effort and impact, reviewed with your team.

Method

Four steps, no surprises.

  1. 01

    Scope

    Ranges, accounts, tenants and rules of engagement agreed.

  2. 02

    Map

    Enumeration of hosts, services, identities and cloud resources.

  3. 03

    Attack

    Exploitation and privilege escalation within agreed limits.

  4. 04

    Harden

    Attack-path report, hardening plan and retest.

How the engagement runs

From first meeting to steady state.

  1. 01Week 1

    Scope and map

    Ranges, accounts, tenants and rules agreed, then enumeration of hosts, services, identities and cloud resources.

  2. 02Weeks 2 to 3

    Attack

    External and assumed-breach internal testing with exploitation and privilege escalation within agreed limits.

  3. 03Weeks 4 to 5

    Report and harden

    Attack-path map, prioritised hardening plan and a review with your team, followed by retest.

What we measure
  • Attack paths to critical assets closed, tracked to retest.
  • Misconfigurations by severity across cloud accounts and tenants.
  • Privileged accounts brought under multi-factor and conditional access.
  • Internet-facing services reduced to those with a known owner.
Who is on the engagement
  • Lead infrastructure tester
  • Cloud security consultant
  • Identity and directory specialist
  • Engagement manager
Deliverables
  • Attack-path map.
  • Misconfiguration and vulnerability list with severity.
  • Cloud and identity review report.
  • Prioritised hardening plan.
  • Retest confirmation.
Engagement terms

Assessments are fixed scope based on the number of hosts, accounts and tenants. External tests typically take one week, internal tests one to two weeks and cloud reviews one to two weeks, with reporting following. Quarterly external testing is available on a retainer.

FAQ

Network & Cloud Security Assessment, in plain terms.

We start from the position of an attacker who already has a foothold, such as a phished user, and see how far they can get. It is the most realistic view of internal risk.

Yes. AWS, Azure and Google Cloud, plus the identity provider that ties them together.

Testing is planned to avoid disruption, with agreed windows and exclusions. Anything with outage risk is discussed before it is attempted.

External testing at least annually and after significant change. Cloud reviews annually or whenever the architecture changes materially.

Next step

Ready to talk about network & cloud security assessment?