Our agency will perform cloud penetration testing for AWS azure and gcp

CREST accredited security testing for high trust organisations
Vetted by Fiverr Pro
REDSECLABS was selected by the Fiverr Pro team for their expertise.
Vetted for
Cybersecurity
About this Gig
Vetted Pro
RedSecLabs is a UK CREST accredited, SWIFT, PCI QSA accredited cybersecurity firm delivering penetration testing, PCI DSS, SOC 2, ISO 27001 readiness, incident response and security advisory services.
We deliver cloud penetration testing and configuration review across AWS, Azure and GCP for regulated sectors including financial services, SaaS, healthcare and payments.
WHAT WE TEST
- IAM misconfiguration and privilege escalation paths
- Identity federation and SSO (Entra ID, Okta, AWS SSO)
- Network segmentation (VPC, NSG, firewall rules)
- Public exposure (S3, blob, GCS)
- Workload security (EC2, ECS, EKS, AKS, GKE, Lambda, Functions)
- Secrets management and encryption
- Logging, monitoring and detection coverage
FRAMEWORK ALIGNMENT
- CIS Benchmarks (AWS, Azure, GCP)
- NIST 800-53 and NIST CSF
- ISO 27001 and ISO 27017
- PCI DSS v4.0.1 cloud requirements
- SOC 2 Common Criteria
If your cloud environment supports a regulated workload, contact us to scope. NDA
available.
Expertise:
Audit
•
Gap analysis
•
Risk assessment
Technology:
Cloud - IaaS
•
CRM
•
ERP
•
Firewalls
•
Networking
Clients We’ve worked with
Bykea
Mobile App Development
Provided cyber security consulting for Bykea to strengthen their overall security posture. Developed a Cyber Security Framework specifically for developers, integrated DevSecOps practices, and significantly improved their Vulnerability Disclosure.
Feb 2023
Portfolio
Other Cybersecurity Services we Offer
FAQ
Do you test all three providers in one engagement?
Standard covers one provider. Premium can cover multi-cloud if you operate hybrid environments.
Will findings be exploited or only identified?
Both. We chain misconfigurations into demonstrable attack paths that is what distinguishes a pentest from an automated CSPM scan.
Do you cover Kubernetes (EKS, AKS, GKE)?
Yes. Including pod security, RBAC, network policies and supply chain controls.
Can you review Infrastructure as Code (Terraform, Bicep, Pulumi)?
Yes. IaC review is included in Premium and available as an add-on to Standard.
Will the report support SOC 2 and PCI cloud scope evidence?
Yes. Reports are produced in a format suitable for audit submission.
Is provider pre-approval required?
AWS and GCP do not require pre-approval for most testing. Azure has a published policy we comply with. We handle provider notifications.

