We break into cloud environments before attackers do.

Risk & Recon is a founder-led offensive security firm. We run penetration tests, red team engagements and cloud security reviews for teams on AWS and Google Cloud, and the person who scopes your test is the person who runs it.

An attack path we see often

  1. Public CI build log A debug step prints deploy credentials Rated low on its own
  2. ci-deploy role Allowed to pass any role: iam:PassRole on * Rated medium on its own
  3. Function execution role Left with administrator access from a prototype Rated medium on its own
  4. Customer data bucket Read and write on production records Critical as a chain
A composite, not a client. Scanners report these as three unrelated tickets. We report the path.

What we do

Manual, evidence-driven testing and advice, scoped to your environment, with findings written for the engineers who have to fix them.

  • Penetration testing

    Manual testing of web applications, APIs, external and internal networks, and cloud environments, aligned to OWASP and PTES. Scanners are a starting point, not the deliverable.

    You get a prioritized report with proof of impact and fixes, plus a re-test.

  • Red team and adversary emulation

    Goal-based, fully authorized attack simulations aligned to MITRE ATT&CK. Instead of cataloguing vulnerabilities, we pursue an agreed objective and measure whether your detection and response catch us.

    You get an attack narrative, the detections that fired and the ones that didn't.

  • Cloud security review

    Design and configuration review of AWS and Google Cloud: identity and access, network boundaries, logging and detection coverage, and least-privilege guardrails. This is where most real compromises start now.

    You get the attack paths through your accounts and projects, ranked, with the policy changes that close them.

  • Bug bounty program consulting

    Design, scoping, triage and tuning of bug bounty and vulnerability disclosure programs, so you start narrow, set sensible rewards, and pay for signal instead of noise.

    You get a program brief, scope and reward table, and a triage process your team can run.

All services and how an engagement runs

Led by Sean Behan

Founder, Risk & Recon (2025)

Sean has spent a decade on the offensive side: computer network operations for the U.S. government and the U.S. Navy, then red teaming, security consulting and penetration testing at AWS, Google and Oracle Cloud. He founded Risk & Recon to bring that work directly to the teams who need it.

More about the firm

  • U.S. GovernmentExploitation Analyst, Computer Network Operations
  • Amazon Web ServicesRed Team Security Engineer
  • GoogleSecurity Consultant
  • Oracle CloudSenior Offensive Security Engineer

OSCP, CISSP, GIAC GRTP, GCPN, GCIA and GCTI. MS in Cybersecurity.

Authorized testing only

Every engagement starts with a signed statement of work, a defined scope and agreed rules of engagement. We test only systems you own or are explicitly authorized to assess, and we tell you immediately if we find something critical mid-test.

Tell us what needs testing

Send a few lines on your environment and timing. We'll reply with a proposed scope, approach and price.

Or email contact@riskandrecon.com

Protected by reCAPTCHA. Google's Privacy Policy and Terms of Service apply.