Is a cloud configuration assessment a fit for your business?

Cloud Configuration Assessment

A cloud configuration assessment maps out misconfigurations and security risks in your cloud environment. We systematically check how your environment is set up for deviations from recognized security standards, before they're exploited by a malicious actor.

  • Thorough analysis of IAM permissions, network configuration and storage
  • Assessed against recognized standards such as the CIS Benchmarks
  • Practical report with concrete, prioritizable improvements

[ 01 ]What we check

What do we check?

Cloud environments are constantly changing: new services, users and integrations get added. A misconfiguration creeps in easily, and an overly broad permission setting or an accidentally public storage location can have major consequences. Click through examples of common vulnerabilities uncovered during cloud configuration assessments. We describe the risk level and impact, just as we do in our independent pentest report.

Identity & Access Management

Overly broad permissions, missing MFA on sensitive accounts, or orphaned user accounts often give an attacker who gets in far more capabilities than necessary, think least privilege as the starting point.

Risk levelKritiek

We assess your environment against recognized standards such as the CIS Benchmarks and the cloud provider's own best practices.

Certifications

Our ethical hackers are broadly certified

From OffSec to Hack The Box: the Tozetta team sets the bar high with internationally recognized, hands-on certifications. We put that in-depth expertise to work in every pentest, so organizations can count on thorough, high-quality security research.

OSCP

OSCP

Offensive Security Certified Professional

OSWE

OSWE

Offensive Security Web Expert

OSEP

OSEP

Offensive Security Experienced Penetration Tester

OSED

OSED

Offensive Security Exploit Developer

OSCE3

OSCE3

Offensive Security Certified Expert 3

CPTS

CPTS

HTB Certified Penetration Testing Specialist

CWEE

CWEE

HTB Certified Web Exploitation Expert

CWES

CWES

HTB Certified Web Exploitation Specialist

AED

AED

Android Exploit Developer

APIsec

APIsec

API Penetration Testing

eWPT

eWPT

Web Application Penetration Tester

BED

BED

Browser Exploit Design

Corelan

Corelan

Windows Expert-Level Stack Exploit Dev

OSCP

OSCP

Offensive Security Certified Professional

OSWE

OSWE

Offensive Security Web Expert

OSEP

OSEP

Offensive Security Experienced Penetration Tester

OSED

OSED

Offensive Security Exploit Developer

OSCE3

OSCE3

Offensive Security Certified Expert 3

CPTS

CPTS

HTB Certified Penetration Testing Specialist

CWEE

CWEE

HTB Certified Web Exploitation Expert

CWES

CWES

HTB Certified Web Exploitation Specialist

AED

AED

Android Exploit Developer

APIsec

APIsec

API Penetration Testing

eWPT

eWPT

Web Application Penetration Tester

BED

BED

Browser Exploit Design

Corelan

Corelan

Windows Expert-Level Stack Exploit Dev

Kevin van den Eshof

โ€œCloud environments change weekly: new services, new users, new integrations. That's exactly why a misconfiguration creeps in so easily, and often goes unnoticed until it's too late.โ€

Kevin van den Eshof

Co-founder & Private Investigator, Tozetta

[ 02 ]Why Tozetta

Why a cloud configuration assessment with Tozetta?

Cloud environments change constantly, and that's exactly why a misconfiguration creeps in so easily. We assess your environment systematically, so risks don't sit unresolved until it's too late.

  • Thorough, systematic assessment of IAM, network, storage and logging
  • Assessed against recognized standards such as the CIS Benchmarks
  • Practical report with concrete, prioritizable improvements in Tozetta Reports
  • Direct contact with the specialist carrying out the work
  • Certified ethical hackers
  • Affordable & fast delivery
Contact Tozetta
Tozetta ethical hackers discussing a cloud configuration assessment
Ian van der Wurff, ethical hacker

โ€œA misconfigured S3 bucket or an overly broad IAM policy is often easy to find, but in practice gets overlooked until it's too late. We assess your cloud environment systematically, so these kinds of risks don't sit unresolved.โ€

OSCP
OSED
OSWE
OSEP
OSCE3

[ 03 ]Our process

How does a cloud configuration assessment work?

No jargon, just a clear process. Click a step or sit back and relax.

Introduction & Scope

A no-obligation conversation or an interactive questionnaire, in which we determine together which cloud environment and platforms we examine.

Engagement progress25%

Schedule an introduction

Curious what a cloud configuration assessment can mean for your environment? Schedule a no-obligation introduction, and we'll discuss the possibilities.

Frequently asked cloud configuration assessment questions

What is a cloud configuration assessment?
A cloud configuration assessment is a thorough check of how your cloud environment is set up, looking for misconfigurations and security risks. Think overly broad permissions, publicly accessible storage or missing logging. We assess the configuration against recognized security standards and deliver a report with concrete improvements.
What is the difference with a pentest?
A pentest simulates an attack to see what an attacker can actually exploit. A cloud configuration assessment focuses specifically on how the cloud environment itself is set up and systematically assesses it against best practices, including points a pentest might not cover.
Which cloud platforms does this apply to?
We run cloud configuration assessments for the major cloud platforms, including Microsoft Azure, Amazon Web Services (AWS), Google Cloud Platform and Microsoft 365.
Who is a cloud configuration assessment valuable for?
For any organization that hosts (business-critical) systems or data in the cloud. Cloud environments change constantly, so misconfigurations creep in easily. A periodic assessment helps catch this in time, especially during growth or under compliance requirements.

Ready for a cloud configuration assessment?

Get in touch without obligation or schedule an introduction directly.