Cloud penetration test for a retailer
Surfaced 74 exploitable misconfigurations across a retailer's multi-account cloud estate.
74
Problem, approach, and the outcome
The client is a UK retailer whose cloud estate had grown fast behind the storefront to keep up with the business. With customer and payment data in scope, the security of that estate is directly a customer-trust issue.
The multi-account environment had never been tested, and no one could say what an attacker landing in one account could reach across the rest.
The cloud estate behind the storefront had grown fast to keep up with the business and had never been tested. Growth had outpaced assurance.
No one could say with confidence what an attacker landing in one account could reach across the rest. Lateral movement between accounts was an unknown.
With customer and payment data in scope, the retailer needed clarity before an incident forced it on them. Getting ahead of the risk was the whole point.
We assessed identity, network, and data paths across the multi-account estate, focusing on lateral movement between accounts rather than single-account hygiene. Cross-account movement is where the real risk in a multi-account estate lives.
Findings were prioritised by real blast radius (what an attacker could actually reach and exfiltrate) rather than by raw finding count. Prioritising by impact is what makes a remediation plan tractable.
We demonstrated the highest-impact chains concretely so they could not be dismissed, and the engagement closed with a remediation plan the platform team could execute in priority order. The team knew exactly what to fix first and why.
- 74 exploitable misconfigurations surfaced
- Prioritised by blast radius across accounts
- Cross-account lateral-movement paths demonstrated
- A remediation plan the team could run
More Cybersecurity case studies

Red-team engagement against a fintech app
Found and helped close three account-takeover paths before a fintech's launch.
Read the full case study
Penetration test for a hospital estate
Surfaced 61 exploitable paths across a hospital estate, prioritised by patient-safety impact.
Read the full case study
Zero-trust rollout for a government agency
Rolled zero-trust access to 25,000 civil servants without a productivity dip.
Read the full case studyGet a senior architect on the call, first time, every time.
No SDR gauntlet. 30 minutes with an engineer who can scope the problem, name the risks, and give you an honest feasibility call.
