Cloud security testing services in India are still frequently sold as a network scan pointed at an AWS account. That finds open ports. It does not find the read-only role that can assume a second role that can read every bucket, which is how cloud environments are actually taken apart.
In a data centre, the attacker moves through the network. In AWS, Azure and GCP, they move through identity. Our testing follows that: we enumerate roles, policies, trust relationships and service accounts, then trace what each principal can reach through the chain of things it is allowed to assume, attach or invoke.
Configuration review and penetration testing run together, because a misconfiguration matters only in proportion to what it exposes. Where your workloads are containerised we cover the cluster; where identity is federated with your directory, see identity and access management. If you are testing cloud for a certification, ISO 27017 is the cloud-specific control set.