1. Home
  2. Articles
  3. Guide

Guide

How we review an AWS environment

What we look at in an AWS infrastructure review, how findings are ranked, and what you get at the end. Use it as a checklist for your own environment, or to know what to expect from ours.

  • By Anwar Alawad
  • Updated 1 October 2026
  • Read 6 min
01 · Scope

What we look at

AreaQuestions we answer
AccountsHow many accounts are there, and is production separated from everything else? Who can sign in to the management account?
IdentityWho and what has access, and how? Are there IAM users, long-lived access keys, unused roles, or policies with * permissions?
Logging and detectionIs CloudTrail on everywhere, and stored somewhere workloads can’t change? Are GuardDuty, Config and Security Hub CSPM on?
NetworkWhat is reachable from the internet? Are databases and workloads in private subnets? How does traffic leave the VPC?
DataIs storage encrypted? Are any buckets or snapshots public? Are backups taken, and has a restore been tested?
Compute and databasesWhat runs, on what, and how is it sized? Are any platform versions past end of support?
Infrastructure as codeHow much is in code, and how much was built by hand? How are changes applied?
DeploymentsHow does a change reach production, and how is it rolled back?
CostWhere does the money go? Does every cost have an owner? What is idle or oversized?
02 · Method

How we do it

  • Read-only access. We work through a role with read-only permissions. Nothing is changed during the review.
  • Tools first, then people. We use AWS’s own reports (Security Hub CSPM findings, Cost Explorer, IAM access data) and then talk to the people who run the environment, because the reasons behind a setup matter.
03 · Ranking

How findings are ranked

RankMeaningExample
Fix this weekExposed or likely to cause an incidentA public database, root access keys, an admin key in a repository
Fix this quarterA real risk or cost, but not urgentNo separate production account, no tested restores, large idle spend
Fix this yearMakes the platform easier and cheaper to runBringing hand-built infrastructure under Terraform, rightsizing
04 · Deliverables

What you get

  • A map of your accounts, identities and what is running, and who owns each cost.
  • The risks, ranked, from “fix this week” to “fix this year”.
  • A written plan and a price for the work, one problem at a time.

Then we fix things in that order, in your accounts, as code, and hand everything over to your team. See AWS consulting.

Next step

Want us to run it on your environment?

On a 30-minute call we’ll agree the scope and give you a price for the review.