CREST-Certified Cloud Penetration Testing for AWS, Azure and GCP
We test the cloud the way attackers approach it: from leaked credentials in CI to over-permissive federation roles that move sideways between accounts and providers. Manual exploitation by CREST-registered testers, live findings during testing, free retests after remediation, fixed-price scope within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
clouds tested in depth and as one estate. The breaches that matter hide in the trust paths between providers, where single-cloud scanners cannot reach.
Misconfiguration tools tell you what looks wrong. A pen test tells you what is actually exploitable.
Most cloud teams already run a posture-management scanner. It produces thousands of CIS-benchmark deviations, public-resource alerts, and policy drift. The question that matters is which of those findings an attacker can chain together to read data, escalate privilege, or pivot to a connected provider.
A CREST-registered cloud penetration test models the real attacker path: leaked CI token, federation misuse, over-permissive role, public bucket, lateral movement to a connected provider. Findings come with exploited evidence, mapped to CIS Foundations Benchmarks, NIST SP 800-115, and CREST OVS.
Cyber Essentials Plus, ISO 27001, SOC 2, and FCA audits accept manual pen test evidence. Posture-scan-only evidence is generally insufficient.
CLOUD ATTACK SURFACE
What We Test Across Your Cloud Estate
Manual exploitation across AWS, Azure and GCP. Each finding is verified, reproducible, and chained into a demonstrable attack path, with the cross-cloud trust failures that single-provider scanners cannot follow.
Identity and Access (IAM)
AWS IAM and IMDS, Azure Entra ID and RBAC, GCP IAM and service accounts. Over-permissive roles, privilege escalation paths, and conditional-access bypass.
Federation and SSO Trust
SAML and OIDC trust policies across providers. AssumeRoleWithSAML assertions, Workload Identity, and federation that grants more access than intended.
CI/CD OIDC and Pipeline Trust
GitHub Actions and pipeline roles assumed via OIDC. Trust policies that fail to constrain the subject claim, letting any repository assume a production role.
Storage Exposure
Public S3 buckets, public Blob containers, and public Cloud Storage. Cross-provider duplication that a single-cloud scanner cannot see in full.
Secrets and Key Management
KMS, Key Vault, Secret Manager and Secrets Manager. Long-lived keys and service-account JSON leaked into CI variables and container images.
Container and Kubernetes
EKS, AKS and GKE. Managed identities, node-role abuse, pod escape, and the path from a workload to the control plane and cloud account.
Serverless and Compute
Lambda, Azure Functions, Cloud Run and Cloud Functions. Function-role over-permission, event-source injection, and impact validation on production data.
Network and Perimeter
Security groups, NSGs, firewall rules, public endpoints, and the exposed surface a new production workload inherits from the estate around it.
Cross-Cloud Attack Chains
The trust paths that cross a provider boundary. Federation, replicated data, and lateral movement from one cloud into another, exploited end to end.
Logging and Detection Gaps
CloudTrail, Azure Activity Log and Cloud Audit Logs. Split sinks and inconsistent retention that leave an attack chain reconstructable in one cloud and invisible in another.
FOUR-PHASE METHODOLOGY
Cloud Penetration Testing: Four Phases, Applied to Each Cloud in Scope
CREST OVS-aligned methodology. In multi-cloud engagements, phases two and three run in parallel across providers, culminating in the cross-cloud attack chains specific to your estate.
Estate Discovery
Read-only enumeration of accounts, subscriptions, projects, identity providers and federation paths. We map what exists before we touch what is exposed.
Benchmark Audit
CIS Foundations for each cloud, mapped to your framework targets (Cyber Essentials Plus, ISO 27001, SOC 2). This is the floor, not the ceiling.
Manual Exploitation
The work scanners cannot do. We chain identity, storage, secrets and compute findings into demonstrable attack paths, including cross-cloud federation paths.
Report and Hardening
Executive plus technical report, framework mapping, a 30 / 60 / 90-day hardening plan, walkthrough call, letter of attestation, and a free retest of fixed findings.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a fixed cloud pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Cloud Pen Test Reports Mapped to Every Framework
Findings are explicitly tagged to the relevant control reference across every cloud in scope. Your audit team submits the report directly without translation work.
Cyber Essentials Plus
Independent assurance evidence for IASME assessors, delivered single-vendor through our certifying-body status.
SOC 2 Type I & II
CC6 logical access and CC7 system operations evidence for cloud control environments.
ISO 27001
Annex A.8 technical vulnerability and A.5 access-control validation, mapped to each finding.
CIS Foundations
CIS AWS, Azure and GCP Foundations Benchmark deviations, with each finding tied to a control.
NCSC Cloud Security
Evidence against the NCSC Cloud Security Principles for cloud-hosted personal data.
FCA / Cyber Insurance
Cloud-security assurance evidence that FCA-regulated firms and cyber underwriters accept.
PRICING
Transparent Cloud Penetration Testing Pricing
All tiers include the same depth of testing. Price varies by estate complexity: account or subscription count, service breadth, resource volume, and how many providers are in scope. The day count flexes at £1,100-£1,400 per day; the included deliverables stay the same across all engagements.
Depends on app complexity
Single cloud, one account, subscription or project, up to 10 services, up to 50 resources, basic IAM. Typically 4-5 day engagement.
Get a fixed quoteDepends on app complexity
Single cloud at organisation scale, or two clouds with simple federation. 10-20 services, 50-200 resources, EKS, AKS, GKE or serverless, CI/CD via OIDC. Typically 7-10 day engagement.
Get a fixed quoteDepends on app complexity
Landing zone, full organisation, or a two-to-three cloud estate. 10+ accounts or projects, 20+ services, 200+ resources, multi-region, regulated workloads, complex federation. Typically 10-15 day engagement.
Get a fixed quoteBY SECTOR
Cloud Penetration Testing for Your Sector
Sector-specialist cloud scoping for UK businesses with sector-specific compliance regimes and threat models.
Fintech & FCA-Regulated
FCA SYSC, cloud-hosted payment platforms, federation into card-data environments, PCI scoping.
Fintech sector pageSaaS Companies
Multi-tenant cloud isolation, IAM and role escalation, customer-tenant boundaries, SOC 2 evidence.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data in cloud storage, partner-tier procurement assurance.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, cloud-hosted EHR and telehealth, patient-data residency.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cloud-hosted claims data, broker portals, cyber underwriting evidence.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC Cloud Security Principles, citizen-facing services, SC-cleared testers available.
Public sector pageWHY EJN LABS
What You Get From Cloud Penetration Testing
What distinguishes our cloud testing from posture scanners and single-provider box-tickers.
CREST-Registered Cloud Testers
Every engagement run by CREST-registered testers, with the company itself a CREST member. Verify our status on the CREST marketplace.
24-Hour Scope to Quote
A sizing call, a fixed quote, and a one-page scope you can route through procurement, all inside one business day.
Exploited Evidence, Not Theory
Findings arrive as demonstrated attack chains with reproduction steps, not CSPM severity scores. You see exactly what an attacker can reach.
Cross-Cloud Attack Chains
We follow the trust path between AWS, Azure and GCP, including federation, replicated data, and split audit logging that single-provider tools miss.
Free Retests, No Time Limit
Verify remediation of every fixed finding before close-out. Letter of attestation for audit submission included, with no per-retest charge.
30 / 60 / 90-Day Hardening Plan
Every report includes a prioritised, estate-scoped hardening plan and a 60-minute walkthrough call, so remediation starts the day you receive it.
FAQ
Frequently Asked
What is cloud penetration testing?
Cloud penetration testing is an authorised, time-boxed engagement in which CREST-registered testers attempt to compromise the confidentiality, integrity or availability of a cloud estate. Unlike automated posture scanning, it produces exploited attack chains with reproducible evidence, plus a hardening plan scoped to the estate.
How does multi-cloud differ from single-cloud testing?
Multi-cloud adds the connections between providers, which is where most modern breaches happen: federation paths, CI/CD with OIDC across clouds, replicated data, and split audit logging. A scanner licensed for one provider cannot see the trust path that crosses into another. We map the cross-cloud attack chains specific to your estate.
How long does a cloud pen test take?
A single-cloud SMB estate is typically 4-5 days. A growth-stage estate or simple two-cloud setup is 7-10 days. A full enterprise landing zone or a three-cloud estate is 10-15 days. The 24-hour scope-to-quote includes a sizing call so you know the duration before you commit.
How much does cloud penetration testing cost in the UK?
SMB engagements are £6,000-£10,000. Growth and mid-market engagements are £10,000-£18,000. Enterprise and multi-cloud engagements are £18,000-£28,000. The day rate for CREST-certified testers is £1,100-£1,400 per day. All tiers include free retests, executive and technical reports, a letter of attestation, and a walkthrough call.
How often should we run a cloud pen test?
Annually is the baseline that most audit, insurance and customer-due-diligence drivers expect. We also recommend a test before any significant architectural change, before a new production workload goes live, after an incident, and on entry to a new compliance regime.
Do we need to notify AWS, Azure or Google before testing?
All three providers permit penetration testing of customer-owned resources without prior notification, subject to their published rules of engagement (no denial-of-service testing, no testing of other tenants, certain services excluded). We confirm scope against the latest provider policies as part of the kick-off.
Is CREST registration relevant for cloud pen testing?
CREST registration is the most widely recognised UK assurance that the testers, the methodology and the company have been independently verified. Many UK regulated firms, insurers and government buyers require it. Our cloud testers are CREST-registered and the company is a CREST member.
Will testing impact production workloads?
We separate read-only enumeration from active exploitation and agree the rules of engagement up front. Active testing is scheduled into maintenance windows where appropriate. Storage and database actions are non-destructive by default. Every step is logged and reversible.
Which cloud providers do you test?
AWS, Azure and Google Cloud Platform, individually or as one multi-cloud estate. Each provider has its own attack surface across identity, storage, secrets, containers and serverless, and we test all three in depth using CIS Foundations as the floor.
Can you map findings to our compliance framework?
Yes. Every finding is tagged to the relevant control reference: CIS Foundations Benchmarks, Cyber Essentials Plus, ISO 27001, SOC 2, the NCSC Cloud Security Principles, and FCA requirements. Your audit team submits the report directly without translation work.
How quickly can you start?
From signed scope to active testing in as little as one business day where an incident, an audit deadline, or a regulator timeline requires it. The 24-hour scope-to-quote includes a sizing call, a fixed price, and a procurement-ready one-page scope.
Do you sign NDAs?
Yes. A standard NDA is in place before any scoping discussion of your cloud estate. We operate under a project-specific agreement covering access handling, post-engagement data destruction, and confidentiality of all findings.
20+ CREST-certified testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed cloud pen test quote in 24 hours
A CREST-certified cloud security specialist will contact you within one business day with a fixed price, a date for kick-off, and a one-page scope you can route through procurement. No sales pipeline.



