Cloud and Virtualisation Security Testing

Cloud and virtualisation security testing reviews the boundaries between hosted workloads, management services and the people who administer them. ProCheckUp helps identify weaknesses in the customer's configuration and use of these environments.

Cloud and virtualisation boundaries

  • Virtual machines, hypervisors and management interfaces
  • Administrative access, tenant separation and network boundaries
  • Cloud services and integrations included in the engagement

Cloud and Virtualisation Testing

Embracing the cloud revolution brings a myriad of benefits: cost-efficiency, impressive scalability, and the assurance of up-time. Businesses are rapidly transitioning to cloud-based IT infrastructures to leverage these advantages.

However, a prevailing myth is that cloud service providers bear the sole responsibility for data protection. Contrary to this belief, the onus is primarily on the cloud customers to ensure robust security for their cloud-based IT infrastructure.

Cloud and Virtualisation Testing

Cloud Testing Process
When undertaking cloud testing for renowned platforms, whether it's Microsoft, Amazon, Google, or Oracle, clients typically provide us with access permissions. This allows us to set up a 'jump box' or to utilize an existing predefined image for manual penetration testing. Beyond that, our meticulous approach includes auditing cloud service configurations. We also employ Open Source Intelligence (OSINT) tools to uncover any publicly exposed data and detect common configuration oversights.

For those utilizing prominent cloud platforms such as Office 365, Azure, AWS, Google Cloud, or SaaS platforms like Salesforce, ProCheckUp provides comprehensive cloud security assessments. Our goal? To ensure your cloud-based IT infrastructure stands as a bastion against potential threats.

Preparing for the engagement

Provide an architecture diagram and identify which controls belong to the organisation and which belong to a provider. Agree access and any restrictions on testing shared infrastructure.

Outcomes and next steps

The findings should connect configuration weaknesses to the resources they could expose. For platform-specific attack-path testing, see the AWS and Azure penetration testing services.

ProCheckUp case study

ProCheckUp examined an Azure application estate and connected identity and development services, reporting twenty findings and three validated attack chains within the agreed scope.

Read the azure cloud penetration testing case study.

Related services

Discuss your requirements

Contact ProCheckUp with the environment, objectives and timing you have in mind. We can discuss the appropriate scope and next steps.

Need Help?

If you have any questions about cyber security or would like a free consultation, don't hesitate to give us a call!

Our Services

Keep up to date!


For More Information Please Contact Us

Smiling Person

ACCREDITATIONS