📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
Cloud Security Testing in India | AWS, Azure, GCP — SIRI Law LLP
Cloud Security Testing · Hyderabad, India

Cloud security testing in India — secure architecture for multi-cloud deployments.

Cloud environments are fundamentally different from on-premise infrastructure — perimeter-based security does not apply. Most cloud breaches result from customer-side misconfigurations, not provider failures. SIRI Law LLP tests AWS, Azure, and GCP environments with exploit-validated findings, mapped to RBI's 2025 NBFC Outsourcing Directions and DPDPA, under attorney-client privilege.

3API calls from a Lambda role to full AWS account compromise, in our case study below
10 Apr 2026Transition deadline for RBI's 2025 NBFC Outsourcing Directions on existing contracts
72 hrsPreliminary cloud posture assessment turnaround
14IAM privilege escalation paths found in a single AWS environment we tested
The cloud regulatory clock
Live tracking · scroll to see every relevant development
Standing
10 APR 2023
RBI Master Direction on Outsourcing of IT Services notified — Appendix I sets specific expectations for regulated entities using cloud computing services.
New
NOV 2025
RBI (NBFC – Managing Risks in Outsourcing) Directions, 2025 notified — a broader update covering financial and IT outsourcing including cloud, SOC, and offshore arrangements.
Deadline
10 APR 2026
Transition deadline for existing NBFC IT outsourcing contracts to comply with the 2025 Directions — new arrangements are already subject to the rules immediately.
Detail
6 hrs
RBI incident reporting clock starts when the cloud vendor becomes aware of an incident, not when the regulated entity is notified — a gap most vendor contracts don't close.
Requirement
Segregation
Vendors must maintain clear separation and isolation of data from other clients' data — directly relevant to shared cloud infrastructure and multi-tenant SaaS platforms.
Standing
DPDPA
Section 8(4) safeguard obligations apply in full to cloud-hosted personal data — public S3/Blob/GCS exposure is a direct compliance failure, not just a technical one.

Why the deadline in the timeline above matters right now

RBI's NBFC outsourcing rules transition deadline is effectively here. Most cloud vendor contracts haven't caught up.

The RBI (Non-Banking Financial Companies – Managing Risks in Outsourcing) Directions, 2025, comprehensively redefined how NBFCs must govern, monitor, and manage outsourcing risk — covering financial services outsourcing and IT outsourcing together for the first time, including cloud, Security Operations Centre arrangements, group entity relationships, and offshore vendors. New outsourcing arrangements were subject to the Directions immediately; existing contracts have until 10 April 2026 to transition — a deadline that has effectively already arrived by the time most organisations get around to auditing their vendor portfolio against it.

One operational detail in the Directions catches nearly every regulated entity off guard: the 6-hour cyber incident reporting clock to RBI starts when the cloud vendor becomes aware of an incident, not when the regulated entity itself is notified. If your cloud provider or managed service vendor doesn't have a fast, contractually binding obligation to tell you the moment they detect something, you inherit a compliance gap you have no visibility into and no ability to control. This is exactly the kind of contractual detail that a technical cloud assessment alone won't catch — it requires legal review of the vendor agreement alongside the technical posture review.

Data segregation is now an explicit requirement, not an assumption
The 2025 Directions require vendors to maintain clear separation and isolation of a regulated entity's data from other clients' data — language written specifically with shared cloud infrastructure and multi-tenant SaaS platforms in mind. For any NBFC or bank using a multi-tenant cloud service, "our provider is ISO 27001 certified" is no longer sufficient evidence of compliance; the segregation itself needs to be technically demonstrated, which is precisely the kind of finding an IAM and access-boundary assessment is built to surface.

None of this replaces the more familiar DPDPA obligation that already applies to every cloud-hosted personal data set regardless of sector: Section 8(4) requires reasonable security safeguards, and a publicly exposed S3 bucket or Blob container containing personal data is a direct violation of that obligation the moment it's discoverable — not merely a technical misconfiguration to fix quietly. The two regulatory layers reinforce each other, which is exactly why our assessments are conducted with legal and technical findings mapped together from the outset.

SIRI Law LLP cloud security assessment

Under 60 seconds, in the case study below

A single over-permissioned Lambda role reached full AWS account compromise in three API calls.

What we test

End-to-end cloud security across the full modern attack surface

From misconfiguration to insider threats — SIRI secures your cloud estate with technical depth and regulatory clarity, across AWS, Azure, and GCP.

01 / POSTURE

Cloud Security Posture Management

Automated and manual assessment of cloud configurations across IAM policies, network ACLs, storage permissions, encryption settings, and logging gaps.

02 / EXPLOITATION

Infrastructure Penetration Testing

Simulated attacks on cloud-hosted applications, serverless functions, container orchestration, and CI/CD pipelines to uncover exploitable weaknesses.

03 / IAM

Identity & Access Management Audit

Privilege escalation path analysis, cross-account role abuse, service account over-permission, and zero-trust readiness assessment using tools like PMapper.

04 / DATA

Data Protection & Encryption Review

Assessment of encryption at rest and in transit, key management practices, secrets handling, and compliance with DPDPA 2023 data residency requirements.

05 / COMPLIANCE

Regulatory Compliance Mapping

Legal-technical gap analysis against CERT-In Directions 2022, RBI's 2025 NBFC Outsourcing Directions, and sectoral cloud security mandates with remediation timelines.

06 / DEVSECOPS

DevSecOps Integration

Security integration into CI/CD pipelines, SAST/DAST tool deployment, container image scanning, and Infrastructure-as-Code supply chain security controls.

07 / AI/ML

AI Cloud Infrastructure Security

Cloud-hosted AI workloads — SageMaker, Azure ML, Vertex AI — assessed for model extraction risk, training data exposure, and inference endpoint security.

08 / CONTAINERS

Container & Kubernetes Security

EKS, AKS, and GKE pod security review, container escape testing, and cluster-level privilege escalation analysis.

09 / MULTI-CLOUD

Multi-Cloud & Hybrid Review

Holistic security review of hybrid and multi-cloud environments, identifying cross-cloud attack paths enabled by over-permissioned service accounts.

In scope

What we handle

  • IAM policy review — least privilege assessment, privilege escalation path mapping
  • S3 / Azure Blob / GCS public exposure and access control review
  • Network segmentation — VPC, security groups, NACLs, firewall rules
  • Serverless security — Lambda, Azure Functions, Cloud Functions
  • Container and Kubernetes security — EKS, AKS, GKE pod security
  • Cloud logging and monitoring coverage — CloudTrail, Azure Monitor, GCP Logs
  • Cross-account and cross-tenant attack path analysis
  • Cloud-native service security — RDS, DynamoDB, Cosmos DB exposure review
  • AI/ML workload security — SageMaker, Azure ML, Vertex AI
  • DevOps pipeline security — CI/CD, IaC misconfiguration (Terraform, CloudFormation)
  • Third-party integration and API gateway security review
  • Secrets management — exposed API keys, credentials in code and environment variables

Evidence, not guesswork

What "exploit-validated" actually looks like

From our case study below: how a single IAM permission became full account compromise in under 60 seconds.

01
Starting point

Lambda execution role with iam:AttachRolePolicy

A single over-scoped IAM permission on an otherwise low-privilege service role — the kind of grant that looks harmless in a policy review but isn't, once you trace what it actually allows.

02
Exploit step

Attach AdministratorAccess to the role's own identity

One API call. No additional credentials required. The permission that was granted for a legitimate operational reason becomes the entire attack.

03
Result

Full AWS account compromise, three API calls total

Every one of the client's 50,000+ enterprise customers' data reachable from this single escalation path — one of 14 distinct paths our PMapper analysis identified in the same environment.

From a representative SIRI Law LLP engagement. Client details generalised to protect confidentiality. See the full case study below.

Evidence, not guesswork

RBI's cloud outsourcing framework — old rules vs. new

Most cloud vendor contracts predate the 2025 Directions. Here's what actually changed.

Requirement 2023 IT Outsourcing Master Direction 2025 NBFC Outsourcing Directions
Scope IT services outsourcing specifically Financial and IT outsourcing together — cloud, SOC, group entities, offshore
Incident reporting clock Reporting timelines by service category 6 hours from vendor's own awareness — not from RE notification
Data segregation General data protection expectation Explicit isolation requirement for multi-tenant/shared infrastructure
Existing contract transition N/A — original framework 10 April 2026 deadline, or contract renewal, whichever is earlier
Board governance Required for material outsourcing Reinforced — Board-approved due diligence policy required

Sources: RBI Master Direction on Outsourcing of Information Technology Services, 10 April 2023; RBI (Non-Banking Financial Companies – Managing Risks in Outsourcing) Directions, 2025. Confirm current applicability to your specific entity category and existing vendor contracts before relying on this summary.

Client outcomes

Measurable results

14
IAM paths closed

In a single AWS environment — fundamental architecture rebuilt, not patched one path at a time.

72 hrs
Posture assessment turnaround

Preliminary findings with critical issues and immediate remediation actions.

100%
Findings under legal privilege

Critical for regulated entities facing RBI and SEBI oversight.

30 days
Enterprise deal executed

After assessment completion in our case study below — remediation satisfied the customer's security questionnaire.

Case study · Cloud security testing

All customer data at risk: one IAM misconfiguration exposed an entire AWS environment

A 150-person HR technology SaaS company had recently completed a rapid migration from on-premises to AWS, processing payroll data, PAN numbers, Aadhaar references, bank account details, and employment records for 50,000+ enterprise customers. The trigger for engaging SIRI was a ₹3.2 crore enterprise deal whose security questionnaire required independent penetration testing within the last 12 months.

The engagement revealed that 100% of customer data was accessible from a single compromised low-privilege service account. A Lambda execution role's iam:AttachRolePolicy permission allowed escalation to full AdministratorAccess in three API calls — under 60 seconds. PMapper analysis found 13 additional escalation paths. Three publicly accessible S3 buckets contained 847 active payroll export files, complete unencrypted database backups, and hardcoded API keys for a payment gateway, SMS provider, and background verification service.

14Critical findings
100%Customer data exposed
5 daysAssessment duration
0Prior exploitations found
₹250 CrDPDPA exposure eliminated
AWS IAM privilege escalation DPDPA Aadhaar Act
AWS cloud security IAM misconfiguration case resolved by SIRI Law LLP

Representative matters

Typical engagements

All matters described generically to protect client confidentiality.

AWS Cloud Assessment — Financial Services

14 IAM paths, 3 exposed S3 buckets

Identified 14 critical IAM privilege escalation paths and 3 publicly exposed S3 buckets containing sensitive application data for a financial services company — all remediated within the agreed timeline.

Azure Kubernetes Security — SaaS

Container escape to cluster-admin

Discovered and demonstrated container escape from a misconfigured AKS pod to cluster-admin access for a SaaS provider — exposing all customer data hosted in the cluster.

GCP MLOps Security — AI Platform

Unauthenticated inference endpoints

Assessed a machine learning platform's GCP infrastructure, identifying unauthenticated model inference endpoints and insufficient isolation between customer ML workloads in a multi-tenant deployment.

Multi-Cloud Security Review — Hybrid

Cross-cloud attack paths found

Conducted a holistic security review of a hybrid AWS/Azure environment, identifying cross-cloud attack paths enabled by over-permissioned service accounts.

Tools & methodologies

Our testing arsenal

Manual exploitation validated by purpose-built cloud security tooling — not automated scanner output alone.

PMapper Pacu ScoutSuite Prowler CloudSploit Terraform Static Analysis CIS AWS Foundations Benchmark AWS Well-Architected Framework Azure Security Benchmark ISO 27001:2022 SOC 2 CC6 DPDPA 2023

Why SIRI

Cloud security with Indian regulatory compliance built in

We combine technical cloud security expertise with deep knowledge of RBI, SEBI, and IRDAI cloud mandates unique to Indian deployments.

01 — Platforms

Multi-cloud expertise

Certified expertise across AWS, Azure, GCP, and OCI, including Indian cloud regions and local data sovereignty requirements — we do not rely on a single cloud vendor's tooling or perspective.

02 — Privilege

Attorney-privilege protection

Cloud vulnerability findings delivered under legal privilege, critical for regulated entities facing RBI and SEBI oversight — findings generally cannot be compelled the way a standalone consultant's report can.

03 — Speed

72-hour quick scan

Preliminary cloud posture assessment in 72 hours with critical findings and immediate remediation actions, so urgent exposures don't wait for a full engagement to close.

04 — Continuity

Continuous monitoring option

SIRI Shield subscribers get quarterly cloud posture reviews, ensuring compliance holds as infrastructure evolves rather than degrading between annual assessments.

Frequently asked

Cloud security testing, answered directly

What is the difference between a cloud configuration review and a cloud penetration test?

A configuration review examines your cloud environment against security best practices and compliance benchmarks such as CIS and the AWS Foundations Benchmark, identifying misconfigurations without active exploitation. A cloud penetration test actively exploits identified weaknesses to demonstrate real attack paths and impact — for example, confirming an IAM privilege escalation chain actually reaches AdministratorAccess, not just that the permission exists on paper. We recommend combining both for comprehensive coverage.

How does the RBI's 2025 NBFC Outsourcing Directions affect cloud security testing?

The RBI (Non-Banking Financial Companies – Managing Risks in Outsourcing) Directions, 2025, apply to financial and IT outsourcing including cloud, SOC, and offshore arrangements, with existing contracts required to transition by 10 April 2026. A key operational detail regulated entities often miss: the 6-hour cyber incident reporting clock to RBI starts when the cloud vendor becomes aware of an incident, not when the regulated entity is notified — meaning your vendor contracts need explicit, fast internal reporting obligations built in, or you inherit a compliance gap you can't control.

Which cloud platform is most commonly assessed in your engagements?

AWS is the most frequently assessed platform in our engagements, followed by Azure. We have equivalent expertise across GCP, and multi-cloud assessments are increasingly common as organisations adopt two or more cloud providers, often creating cross-cloud attack paths that neither platform's native tooling will surface on its own.

How long does a cloud security assessment take?

A focused cloud security assessment typically takes 5–10 business days for assessment plus 3–5 days for reporting. Large or complex environments — multiple accounts, significant IAM complexity, AI/ML workloads — may require 15 or more days. We scope every engagement before starting, and a preliminary posture assessment with critical findings is available within 72 hours.

Do you test AI/ML workloads hosted in the cloud?

Yes. Cloud-hosted AI workloads — SageMaker, Azure ML, Vertex AI training pipelines and model serving endpoints — present distinct attack surfaces including model extraction risk, training data exposure, and inference endpoint security, which we assess as part of our AI cloud infrastructure testing alongside conventional cloud posture review.

What happens after the assessment — is retesting included?

All engagements include a complimentary retest of critical and high findings after remediation, confirming vulnerabilities are genuinely closed rather than merely reported as fixed. Findings are also mapped to ISO 27001, SOC 2, PCI DSS, and DPDPA controls, so remediation work advances your compliance programme at the same time.

Ready to secure your cloud?

Book your free cloud security consultation.

30-minute scoping call. No commitment. Privilege-protected from the first conversation.

or call +91 79819 12046 — Mon–Sat, 9 AM – 7 PM IST

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

All security testing is conducted under a signed rules-of-engagement agreement with explicit written authorisation from the asset owner. Findings are confidential and delivered only to authorised client representatives. References to RBI's 2025 NBFC Outsourcing Directions and related deadlines reflect publicly available information as of publication and remain subject to further regulatory clarification; confirm current applicability to your specific entity category before relying on any provision here. Case study and representative matter details are described generically to protect client confidentiality. This page does not constitute legal advice. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top