Skip to content
Noroxi

Cloud security assessmentOne wrong permission opens the whole account.

Most cloud breaches start with a misconfiguration. We review your AWS, Azure and GCP environments end to end for permissions, networking and logging.

Duration
5–10 business days
Standard
CIS Benchmarks
Deliverables
Report, readout and retest within 30 days

What we test

  1. 01

    Identity and access

    User, role and service account permissions.

  2. 02

    Storage

    Buckets and shares left open to the public.

  3. 03

    Network

    Security groups, open ports, private connectivity.

  4. 04

    Logging and monitoring

    Audit logs and alerting rules.

  5. 05

    Containers and Kubernetes

    Cluster configuration and image security.

  6. 06

    Secrets

    Key management and rotation.

Vulnerabilities we often find

The ones we’ve run into most in recent engagements. You can’t know whether you have them until you test.

  • Service account with admin privilegesCritical
  • Publicly accessible storageHigh
  • Management port exposed to the internetHigh
  • Regions with no loggingMedium
  • Access keys that are never rotatedMedium

This is how a finding is delivered.

Clear enough for a developer to fix on their own. Plain enough for an executive to grasp at a glance.

NRX-2026-0141page 14 / 38
CriticalCVSS 4.0 · 9.1

Broken object-level authorization in the Orders API

Affected asset
api.ornek-sirket.com.tr
Category
OWASP API1:2023 · CWE-639
Discovered
September 12, 2026
Reported
Same day, by phone

Impact

A signed-in customer can view invoices that belong to other customers. Because the invoices include names and addresses, this may require notification under KVKK (Turkey’s personal data protection law).

Remediation

In the invoice lookup, verify that the record belongs to the signed-in user. Centralize authorization checks in a single middleware layer and apply it to every endpoint.

Retest · October 3, 2026 Resolved

How it works

  1. 011–2 days

    Scoping

    Account list and a read-only audit role.

  2. 023–5 business days

    Configuration review

    Benchmark checks plus manual validation.

  3. 032–3 business days

    Attack path analysis

    Paths that open up when misconfigurations combine.

  4. 043 days + 30 days

    Report and retest

    A prioritized remediation list and a follow-up check.

Frequently asked questions

What access do we need to grant?
A read-only audit role is enough. We don’t change any of your resources.
Do you support multiple accounts or subscriptions?
Yes. We consolidate them into a single, organization-level report.
Do you review infrastructure-as-code templates?
Yes. On request, we also review templates before they’re deployed.

Often paired with

Let’s take a free look first

Leave us your domain. Within 2 business days, we’ll review your external surface and send the priority risks and a recommended scope on a single page.

  1. 01Leave your email and domain.
  2. 02We review your external surface within two business days.
  3. 03You get a one-page summary and a recommended first step.

We use your details only for this request. Privacy notice

mini assessment1 page
14
Subdomains
6
Exposed services
B
TLS grade
3 / 7
Security headers

Top three risks

  1. 1Admin panel exposed to the internetHigh
  2. 2Outdated TLS version still supportedMedium
  3. 3Content Security Policy missingLow
Delivery: 2 business daysRecommended first step: web and API testing