What we look at
| Area | Questions we answer |
|---|---|
| Accounts | How many accounts are there, and is production separated from everything else? Who can sign in to the management account? |
| Identity | Who and what has access, and how? Are there IAM users, long-lived access keys, unused roles, or policies with * permissions? |
| Logging and detection | Is CloudTrail on everywhere, and stored somewhere workloads can’t change? Are GuardDuty, Config and Security Hub CSPM on? |
| Network | What is reachable from the internet? Are databases and workloads in private subnets? How does traffic leave the VPC? |
| Data | Is storage encrypted? Are any buckets or snapshots public? Are backups taken, and has a restore been tested? |
| Compute and databases | What runs, on what, and how is it sized? Are any platform versions past end of support? |
| Infrastructure as code | How much is in code, and how much was built by hand? How are changes applied? |
| Deployments | How does a change reach production, and how is it rolled back? |
| Cost | Where does the money go? Does every cost have an owner? What is idle or oversized? |
How we do it
- Read-only access. We work through a role with read-only permissions. Nothing is changed during the review.
- Tools first, then people. We use AWS’s own reports (Security Hub CSPM findings, Cost Explorer, IAM access data) and then talk to the people who run the environment, because the reasons behind a setup matter.
How findings are ranked
| Rank | Meaning | Example |
|---|---|---|
| Fix this week | Exposed or likely to cause an incident | A public database, root access keys, an admin key in a repository |
| Fix this quarter | A real risk or cost, but not urgent | No separate production account, no tested restores, large idle spend |
| Fix this year | Makes the platform easier and cheaper to run | Bringing hand-built infrastructure under Terraform, rightsizing |
What you get
- A map of your accounts, identities and what is running, and who owns each cost.
- The risks, ranked, from “fix this week” to “fix this year”.
- A written plan and a price for the work, one problem at a time.
Then we fix things in that order, in your accounts, as code, and hand everything over to your team. See AWS consulting.
Next step
Want us to run it on your environment?
On a 30-minute call we’ll agree the scope and give you a price for the review.
Deep diveOffshore complianceSovereign desktops, controls and audit evidenceDeep diveFaster deploymentsPipelines, infrastructure as code and safe releasesDeep diveLower cloud costsTagging, scheduling, rightsizing and commitmentsDeep diveAI governanceChecks, review rules and policy for AI-written code