Cloud security testing in India — secure architecture for multi-cloud deployments.
Cloud environments are fundamentally different from on-premise infrastructure — perimeter-based security does not apply. Most cloud breaches result from customer-side misconfigurations, not provider failures. SIRI Law LLP tests AWS, Azure, and GCP environments with exploit-validated findings, mapped to RBI's 2025 NBFC Outsourcing Directions and DPDPA, under attorney-client privilege.
Why the deadline in the timeline above matters right now
RBI's NBFC outsourcing rules transition deadline is effectively here. Most cloud vendor contracts haven't caught up.
The RBI (Non-Banking Financial Companies – Managing Risks in Outsourcing) Directions, 2025, comprehensively redefined how NBFCs must govern, monitor, and manage outsourcing risk — covering financial services outsourcing and IT outsourcing together for the first time, including cloud, Security Operations Centre arrangements, group entity relationships, and offshore vendors. New outsourcing arrangements were subject to the Directions immediately; existing contracts have until 10 April 2026 to transition — a deadline that has effectively already arrived by the time most organisations get around to auditing their vendor portfolio against it.
One operational detail in the Directions catches nearly every regulated entity off guard: the 6-hour cyber incident reporting clock to RBI starts when the cloud vendor becomes aware of an incident, not when the regulated entity itself is notified. If your cloud provider or managed service vendor doesn't have a fast, contractually binding obligation to tell you the moment they detect something, you inherit a compliance gap you have no visibility into and no ability to control. This is exactly the kind of contractual detail that a technical cloud assessment alone won't catch — it requires legal review of the vendor agreement alongside the technical posture review.
None of this replaces the more familiar DPDPA obligation that already applies to every cloud-hosted personal data set regardless of sector: Section 8(4) requires reasonable security safeguards, and a publicly exposed S3 bucket or Blob container containing personal data is a direct violation of that obligation the moment it's discoverable — not merely a technical misconfiguration to fix quietly. The two regulatory layers reinforce each other, which is exactly why our assessments are conducted with legal and technical findings mapped together from the outset.
Under 60 seconds, in the case study below
A single over-permissioned Lambda role reached full AWS account compromise in three API calls.
What we test
End-to-end cloud security across the full modern attack surface
From misconfiguration to insider threats — SIRI secures your cloud estate with technical depth and regulatory clarity, across AWS, Azure, and GCP.
Cloud Security Posture Management
Automated and manual assessment of cloud configurations across IAM policies, network ACLs, storage permissions, encryption settings, and logging gaps.
Infrastructure Penetration Testing
Simulated attacks on cloud-hosted applications, serverless functions, container orchestration, and CI/CD pipelines to uncover exploitable weaknesses.
Identity & Access Management Audit
Privilege escalation path analysis, cross-account role abuse, service account over-permission, and zero-trust readiness assessment using tools like PMapper.
Data Protection & Encryption Review
Assessment of encryption at rest and in transit, key management practices, secrets handling, and compliance with DPDPA 2023 data residency requirements.
Regulatory Compliance Mapping
Legal-technical gap analysis against CERT-In Directions 2022, RBI's 2025 NBFC Outsourcing Directions, and sectoral cloud security mandates with remediation timelines.
DevSecOps Integration
Security integration into CI/CD pipelines, SAST/DAST tool deployment, container image scanning, and Infrastructure-as-Code supply chain security controls.
AI Cloud Infrastructure Security
Cloud-hosted AI workloads — SageMaker, Azure ML, Vertex AI — assessed for model extraction risk, training data exposure, and inference endpoint security.
Container & Kubernetes Security
EKS, AKS, and GKE pod security review, container escape testing, and cluster-level privilege escalation analysis.
Multi-Cloud & Hybrid Review
Holistic security review of hybrid and multi-cloud environments, identifying cross-cloud attack paths enabled by over-permissioned service accounts.
In scope
What we handle
- IAM policy review — least privilege assessment, privilege escalation path mapping
- S3 / Azure Blob / GCS public exposure and access control review
- Network segmentation — VPC, security groups, NACLs, firewall rules
- Serverless security — Lambda, Azure Functions, Cloud Functions
- Container and Kubernetes security — EKS, AKS, GKE pod security
- Cloud logging and monitoring coverage — CloudTrail, Azure Monitor, GCP Logs
- Cross-account and cross-tenant attack path analysis
- Cloud-native service security — RDS, DynamoDB, Cosmos DB exposure review
- AI/ML workload security — SageMaker, Azure ML, Vertex AI
- DevOps pipeline security — CI/CD, IaC misconfiguration (Terraform, CloudFormation)
- Third-party integration and API gateway security review
- Secrets management — exposed API keys, credentials in code and environment variables
Evidence, not guesswork
What "exploit-validated" actually looks like
From our case study below: how a single IAM permission became full account compromise in under 60 seconds.
Lambda execution role with iam:AttachRolePolicy
A single over-scoped IAM permission on an otherwise low-privilege service role — the kind of grant that looks harmless in a policy review but isn't, once you trace what it actually allows.
Attach AdministratorAccess to the role's own identity
One API call. No additional credentials required. The permission that was granted for a legitimate operational reason becomes the entire attack.
Full AWS account compromise, three API calls total
Every one of the client's 50,000+ enterprise customers' data reachable from this single escalation path — one of 14 distinct paths our PMapper analysis identified in the same environment.
From a representative SIRI Law LLP engagement. Client details generalised to protect confidentiality. See the full case study below.
Evidence, not guesswork
RBI's cloud outsourcing framework — old rules vs. new
Most cloud vendor contracts predate the 2025 Directions. Here's what actually changed.
| Requirement | 2023 IT Outsourcing Master Direction | 2025 NBFC Outsourcing Directions |
|---|---|---|
| Scope | IT services outsourcing specifically | Financial and IT outsourcing together — cloud, SOC, group entities, offshore |
| Incident reporting clock | Reporting timelines by service category | 6 hours from vendor's own awareness — not from RE notification |
| Data segregation | General data protection expectation | Explicit isolation requirement for multi-tenant/shared infrastructure |
| Existing contract transition | N/A — original framework | 10 April 2026 deadline, or contract renewal, whichever is earlier |
| Board governance | Required for material outsourcing | Reinforced — Board-approved due diligence policy required |
Sources: RBI Master Direction on Outsourcing of Information Technology Services, 10 April 2023; RBI (Non-Banking Financial Companies – Managing Risks in Outsourcing) Directions, 2025. Confirm current applicability to your specific entity category and existing vendor contracts before relying on this summary.
Client outcomes
Measurable results
In a single AWS environment — fundamental architecture rebuilt, not patched one path at a time.
Preliminary findings with critical issues and immediate remediation actions.
Critical for regulated entities facing RBI and SEBI oversight.
After assessment completion in our case study below — remediation satisfied the customer's security questionnaire.
Case study · Cloud security testing
All customer data at risk: one IAM misconfiguration exposed an entire AWS environment
A 150-person HR technology SaaS company had recently completed a rapid migration from on-premises to AWS, processing payroll data, PAN numbers, Aadhaar references, bank account details, and employment records for 50,000+ enterprise customers. The trigger for engaging SIRI was a ₹3.2 crore enterprise deal whose security questionnaire required independent penetration testing within the last 12 months.
The engagement revealed that 100% of customer data was accessible from a single compromised low-privilege service account. A Lambda execution role's iam:AttachRolePolicy permission allowed escalation to full AdministratorAccess in three API calls — under 60 seconds. PMapper analysis found 13 additional escalation paths. Three publicly accessible S3 buckets contained 847 active payroll export files, complete unencrypted database backups, and hardcoded API keys for a payment gateway, SMS provider, and background verification service.
Representative matters
Typical engagements
All matters described generically to protect client confidentiality.
14 IAM paths, 3 exposed S3 buckets
Identified 14 critical IAM privilege escalation paths and 3 publicly exposed S3 buckets containing sensitive application data for a financial services company — all remediated within the agreed timeline.
Container escape to cluster-admin
Discovered and demonstrated container escape from a misconfigured AKS pod to cluster-admin access for a SaaS provider — exposing all customer data hosted in the cluster.
Unauthenticated inference endpoints
Assessed a machine learning platform's GCP infrastructure, identifying unauthenticated model inference endpoints and insufficient isolation between customer ML workloads in a multi-tenant deployment.
Cross-cloud attack paths found
Conducted a holistic security review of a hybrid AWS/Azure environment, identifying cross-cloud attack paths enabled by over-permissioned service accounts.
Tools & methodologies
Our testing arsenal
Manual exploitation validated by purpose-built cloud security tooling — not automated scanner output alone.
Why SIRI
Cloud security with Indian regulatory compliance built in
We combine technical cloud security expertise with deep knowledge of RBI, SEBI, and IRDAI cloud mandates unique to Indian deployments.
Multi-cloud expertise
Certified expertise across AWS, Azure, GCP, and OCI, including Indian cloud regions and local data sovereignty requirements — we do not rely on a single cloud vendor's tooling or perspective.
Attorney-privilege protection
Cloud vulnerability findings delivered under legal privilege, critical for regulated entities facing RBI and SEBI oversight — findings generally cannot be compelled the way a standalone consultant's report can.
72-hour quick scan
Preliminary cloud posture assessment in 72 hours with critical findings and immediate remediation actions, so urgent exposures don't wait for a full engagement to close.
Continuous monitoring option
SIRI Shield subscribers get quarterly cloud posture reviews, ensuring compliance holds as infrastructure evolves rather than degrading between annual assessments.
Frequently asked
Cloud security testing, answered directly
What is the difference between a cloud configuration review and a cloud penetration test?
A configuration review examines your cloud environment against security best practices and compliance benchmarks such as CIS and the AWS Foundations Benchmark, identifying misconfigurations without active exploitation. A cloud penetration test actively exploits identified weaknesses to demonstrate real attack paths and impact — for example, confirming an IAM privilege escalation chain actually reaches AdministratorAccess, not just that the permission exists on paper. We recommend combining both for comprehensive coverage.
How does the RBI's 2025 NBFC Outsourcing Directions affect cloud security testing?
The RBI (Non-Banking Financial Companies – Managing Risks in Outsourcing) Directions, 2025, apply to financial and IT outsourcing including cloud, SOC, and offshore arrangements, with existing contracts required to transition by 10 April 2026. A key operational detail regulated entities often miss: the 6-hour cyber incident reporting clock to RBI starts when the cloud vendor becomes aware of an incident, not when the regulated entity is notified — meaning your vendor contracts need explicit, fast internal reporting obligations built in, or you inherit a compliance gap you can't control.
Which cloud platform is most commonly assessed in your engagements?
AWS is the most frequently assessed platform in our engagements, followed by Azure. We have equivalent expertise across GCP, and multi-cloud assessments are increasingly common as organisations adopt two or more cloud providers, often creating cross-cloud attack paths that neither platform's native tooling will surface on its own.
How long does a cloud security assessment take?
A focused cloud security assessment typically takes 5–10 business days for assessment plus 3–5 days for reporting. Large or complex environments — multiple accounts, significant IAM complexity, AI/ML workloads — may require 15 or more days. We scope every engagement before starting, and a preliminary posture assessment with critical findings is available within 72 hours.
Do you test AI/ML workloads hosted in the cloud?
Yes. Cloud-hosted AI workloads — SageMaker, Azure ML, Vertex AI training pipelines and model serving endpoints — present distinct attack surfaces including model extraction risk, training data exposure, and inference endpoint security, which we assess as part of our AI cloud infrastructure testing alongside conventional cloud posture review.
What happens after the assessment — is retesting included?
All engagements include a complimentary retest of critical and high findings after remediation, confirming vulnerabilities are genuinely closed rather than merely reported as fixed. Findings are also mapped to ISO 27001, SOC 2, PCI DSS, and DPDPA controls, so remediation work advances your compliance programme at the same time.
Ready to secure your cloud?
Book your free cloud security consultation.
30-minute scoping call. No commitment. Privilege-protected from the first conversation.
Related services
Other ways SIRI Law LLP secures cloud-deploying organisations
Cybersecurity testing services
Full portfolio — application, network, IoT, and AI/LLM security testing.
AI & LLM security testing
Adversarial testing for AI systems, including those deployed on cloud infrastructure.
Data privacy & cybersecurity law
DPDPA compliance and breach response for cloud-hosted personal data.
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

