A payments processor asked how far an attacker could get in two weeks.
The challenge
The client had passed two annual penetration tests and held PCI DSS certification, but leadership wanted to know whether the security team would notice a determined attacker. The objective was set as read access to a single day of transaction records.
What we did
Starting from a public marketing site, the team found a staging API that shared a service credential with production. That credential granted an assumed cloud role which, through a chain of trust policies, could read snapshots of the transaction database. Every step was timestamped and reported to the trusted contact the day it happened.
The outcome
The security team detected the initial API abuse but not the cloud role assumption. The client rotated the shared credential and rewrote the trust policies within the engagement window, then commissioned detection rules for cross-account role use. A follow-up run three months later was stopped at the second step.
Get the same answer for your systems.
One scoping call, a fixed-price proposal, and a written result you can show your board or your customers.