We break into cloud environments before attackers do.
Risk & Recon is a founder-led offensive security firm. We run penetration tests, red team engagements and cloud security reviews for teams on AWS and Google Cloud, and the person who scopes your test is the person who runs it.
An attack path we see often
- Public CI build log A debug step prints deploy credentials Rated low on its own
- ci-deploy role Allowed to pass any role: iam:PassRole on * Rated medium on its own
- Function execution role Left with administrator access from a prototype Rated medium on its own
- Customer data bucket Read and write on production records Critical as a chain
What we do
Manual, evidence-driven testing and advice, scoped to your environment, with findings written for the engineers who have to fix them.
-
Penetration testing
Manual testing of web applications, APIs, external and internal networks, and cloud environments, aligned to OWASP and PTES. Scanners are a starting point, not the deliverable.
You get a prioritized report with proof of impact and fixes, plus a re-test.
-
Red team and adversary emulation
Goal-based, fully authorized attack simulations aligned to MITRE ATT&CK. Instead of cataloguing vulnerabilities, we pursue an agreed objective and measure whether your detection and response catch us.
You get an attack narrative, the detections that fired and the ones that didn't.
-
Cloud security review
Design and configuration review of AWS and Google Cloud: identity and access, network boundaries, logging and detection coverage, and least-privilege guardrails. This is where most real compromises start now.
You get the attack paths through your accounts and projects, ranked, with the policy changes that close them.
-
Bug bounty program consulting
Design, scoping, triage and tuning of bug bounty and vulnerability disclosure programs, so you start narrow, set sensible rewards, and pay for signal instead of noise.
You get a program brief, scope and reward table, and a triage process your team can run.
Led by Sean Behan
Founder, Risk & Recon (2025)
Sean has spent a decade on the offensive side: computer network operations for the U.S. government and the U.S. Navy, then red teaming, security consulting and penetration testing at AWS, Google and Oracle Cloud. He founded Risk & Recon to bring that work directly to the teams who need it.
- U.S. GovernmentExploitation Analyst, Computer Network Operations
- Amazon Web ServicesRed Team Security Engineer
- GoogleSecurity Consultant
- Oracle CloudSenior Offensive Security Engineer
OSCP, CISSP, GIAC GRTP, GCPN, GCIA and GCTI. MS in Cybersecurity.
Tell us what needs testing
Send a few lines on your environment and timing. We'll reply with a proposed scope, approach and price.
Or email contact@riskandrecon.com