uKnowva Cloud Security Assessment Report – September 2026

  • Print

This is to certify that SecIQ Technologies has performed Cloud Security Assessment from July 2026 to September 2026 for the uKnowva AWS Cloud Environment.

Executive Summary

The Cloud Security Assessment was performed to assess the overall security posture of the uKnowva AWS Cloud Infrastructure. The assessment focused on identifying security misconfigurations, assessing associated risks, and providing guidance for prioritizing remediation activities.

The assessment identified security observations across AWS services including IAM, Lambda, EC2, EBS, GuardDuty, SageMaker, and S3.

A total of 19 findings were identified during the assessment, comprising 5 Critical, 9 High, 3 Medium, and 2 Low-severity findings. All identified findings are recorded as Closed in the assessment report.

The assessment and subsequent remediation activities have addressed the identified security misconfigurations and strengthened the overall security posture of the uKnowva AWS Cloud Environment.

Scope of Testing

The scope of this Cloud Security Assessment was limited to the uKnowva AWS Cloud Service.

The assessment was performed from the perspective of an authenticated least-privileged read-only user as well as an external attacker who was not authorized to access the uKnowva AWS environment.

The assessment focused on reviewing AWS cloud service configurations, identifying security misconfigurations, assessing their potential impact, and validating remediation measures.

Findings & Summary

The Cloud Security Assessment identified observations related to identity and access management, AWS Lambda security, EC2 and EBS configuration, network exposure, GuardDuty, SageMaker security controls, S3 configuration, and AWS security monitoring capabilities.

The findings were classified according to their severity as follows:

Severity

Findings

Status

Critical

5

Closed

High

9

Closed

Medium

3

Closed

Low

2

Closed

Total

19

Closed

The identified findings included unrestricted administrative privileges, hardcoded secrets in Lambda code, publicly accessible Lambda functions, unrestricted inbound Security Group access, EBS encryption and snapshot configuration issues, IMDSv2 configuration, GuardDuty coverage, SageMaker network security controls, S3 Versioning, EC2 monitoring, and IAM Access Analyzer configuration.

All findings documented in the assessment are recorded as Closed.

Business-Critical Risks

The assessment identified security misconfigurations across several AWS services, including Critical and High-severity observations related to administrative privileges, exposed credentials, public access, network exposure, storage security, and cloud security controls.

All identified findings have been recorded as Closed following remediation or review.

Approach

This assessment was performed through a gray-box approach from the perspective of an authenticated end user with least-privileged, read-only access. A black-box approach was also performed from the perspective of an external attacker who was not an authorized user of the uKnowva AWS environment.

The tests were carried out assuming the identity of an attacker or a user with malicious intent; however, care was taken not to harm the cloud infrastructure.

The assessment involved manual testing combined with open-source automated tools. The following phases were covered during this assessment:

  • Cloud Security Audit, Review Cloud Services Configuration – White Box Approach

  • Triage and Exploitation

  • Report Generation & Review

Assessment Report (Summary)

The assessment identified security misconfigurations across the uKnowva AWS Cloud Environment covering identity and access management, compute resources, storage, serverless functions, monitoring, and machine-learning infrastructure.

The identified findings included Critical, High, Medium, and Low-severity observations. The assessment report records all findings as Closed, following remediation, validation, or documented security review.

The remediation activities and security controls implemented across the assessed AWS environment have strengthened the overall cloud security posture within the scope of this assessment.

This report is valid until any changes are made in the code or configuration, or six months from the date of testing, whichever is earlier.

If you have any questions or need additional support, feel free to contact us at This email address is being protected from spambots. You need JavaScript enabled to view it..

Was this Article helpful?