Skip to content
8bytes

Find what your
CSPM tool missed.

AWS, Azure, and GCP. Architecture review, misconfiguration audits, IAM analysis, Kubernetes and container security — the findings your posture tooling missed.

Coverage

What we audit.

Cloud security testing across the three major hyperscalers plus the container layer that sits on top of all of them. Multi-cloud estates handled in a single engagement.

AWS

IAM, S3, KMS, VPC and security groups, Lambda and serverless, ECS and EKS, organisation and account boundaries.

Azure

Entra ID, RBAC and PIM, subscription and management-group structure, Key Vault, Functions, AKS.

GCP

IAM and service accounts, project hierarchy, VPC and firewall rules, GKE, Cloud Functions, secret management.

Kubernetes & containers

RBAC, network policies, admission controllers, container image hygiene, runtime workload identity, service mesh.

Methodology

How we work.

01

Architecture review

Workshop with your platform team. Understand intent, boundaries, and historical decisions before we touch the environment.

02

IAM & identity analysis

Enumerate every identity, every permission, every assumable role. Identify excessive privilege and privilege-escalation paths.

03

Configuration audit

CIS-mapped misconfiguration sweep, plus the issues your CSPM tool does not have rules for.

04

Attack-path modelling

Combine identity, configuration, and network findings into real attack paths. What can an attacker who lands here actually reach?

05

Remediation prioritisation

Prioritise by attack-path impact, not by CIS check ID. A runbook your platform team can execute.

Deliverables

What you receive.

Everything you need to fix what we found — and prove it to your auditors.

  • Architecture risk assessment with annotated diagrams
  • IAM excessive-privilege report (per principal, per resource)
  • Misconfiguration findings mapped to CIS and provider best-practice
  • Attack-path diagrams showing privilege-escalation chains
  • Prioritised remediation runbook for your platform team
  • Compliance mapping (SOC 2, ISO 27001, PCI DSS) on request

FAQs

Common questions.

01

What access do you need to our cloud?

A read-only role at the organisation level is enough for most engagements. For audit scenarios we provide IaC templates (CloudFormation / Terraform / Bicep) that create the role with minimal permissions. We can also work from exported configuration if you cannot grant access.

02

How is this different from a CSPM tool?

CSPM tools find configuration drift against a library of rules. We find the attack paths those rules do not cover — combinations of identity, network, and trust relationships that result in real privilege escalation. The output is "attacker can reach the production database from this developer laptop because of these five chained findings", not "S3 bucket logging is disabled".

03

Do you cover multi-cloud?

Yes. Most modern enterprises are multi-cloud, and the interesting attack paths often cross provider boundaries (a federated identity in AWS that can assume into Azure, for instance). We treat the estate as a single attack surface.

04

Can you test our Kubernetes cluster without disrupting workloads?

Yes. Default is non-disruptive read-only assessment. Any test that could cause a workload restart is agreed with your platform team in advance and run in a maintenance window if needed.

05

Do you produce compliance-mapped output?

On request. Findings can be cross-walked to SOC 2 Trust Service Criteria, ISO 27001 Annex A controls, or PCI DSS requirements. Useful when the engagement output needs to land in front of an auditor.

Get in touch

Have a cloud estate to audit?

Book a call

Free 30-min scoping call. No commitment.