Scoping by account, subscription, or project
Cloud tests are scoped on the accounts, subscriptions, or projects in play, the workloads inside them (compute, containers, serverless, managed databases), and the identity model connecting them. We agree whether the test is external-only, assumed-breach from a low-privilege identity, or both. Assumed-breach is where most real findings come from and is our default recommendation.
- Typical effort: 5 to 10 testing days for a single production account or subscription with a handful of workloads; multi-account organisations are phased.
- Access we need: a read-only auditor role for configuration review plus one deliberately low-privilege identity for the assumed-breach path, and provider-specific authorisation where required.
- Provider rules: we work within AWS, Azure, and Google Cloud penetration-testing policies, so no denial-of-service and no testing of provider-owned infrastructure.