Security consulting on AWS

A security posture you can prove, not just declare.

We audit identities, network, data and deployment pipeline across your AWS accounts. We prioritise by real risk, fix in code and leave detection running so you see the next finding before anyone else does.

Read-only access Report in 10 days ISO 27001 · ENS · SOC 2
AWS ORGANIZATIONS · SCPs · CONTROL TOWER IDENTITY · IAM IDENTITY CENTER · LEAST PRIVILEGE · MFA NETWORK · VPC · PRIVATE SUBNETS · WAF · ENDPOINTS DATA · KMS · ENCRYPTION · BACKUPS WORKLOADS EKS · LAMBDA · RDS · S3 HARDENING · SECRETS · SUPPLY CHAIN DETECTION AND RESPONSE · GUARDDUTY · SECURITY HUB · CLOUDTRAIL
What we review

The most common findings and how we close them.

An excerpt from our checklist. Every finding is scored by likelihood of exploitation and impact on your business, not just by the tool's generic severity.

Typical findingRiskHow we close itControl
Long-lived IAM access keys on human usersCriticalMigration to IAM Identity Center with SSO and temporary roles; key rotation and removalCIS 1.4 · ENS op.acc
Policies with * in action and resourceCriticalLeast privilege derived from IAM Access Analyzer and real activity over the last 90 daysCIS 1.16 · ISO A.9
Publicly accessible S3 buckets or RDS snapshotsCriticalAccount-level Block Public Access, reviewed bucket policies and alerts on changesCIS 2.1 · SOC 2 CC6
CloudTrail without multi-region coverage or integrityHighOrganisation trail, integrity validation and retention in an isolated log accountCIS 3.1 · ENS op.exp
Security groups open to 0.0.0.0/0 on SSH or RDPHighAccess via Systems Manager Session Manager; removal of exposed admin portsCIS 5.2
Secrets in environment variables or in the repositoryHighSecrets Manager with rotation, secret scanning in CI and revocation of exposed onesISO A.9.4 · SOC 2 CC6
Container images neither scanned nor signedMediumInspector on ECR, signing with Signer and admission policy on EKSSLSA · ISO A.14
No response plan or restore testsMediumRunbooks, incident drill and quarterly backup restore testISO A.16 · ENS op.cont
Services

From a one-off audit to continuous operations.

Audit

AWS posture review

Ten days with read-only access. Risk-prioritised report, with evidence per finding and a remediation plan estimated in effort.

  • Organizations, accounts, SCPs and IAM
  • Network, public exposure and encryption
  • Logging, detection and response capability
Remediation

Fixes as infrastructure as code

We close findings in Terraform or CDK, with your team's review and environment-by-environment deployment. Nothing is changed by hand in the console.

  • Multi-account landing zone with Control Tower
  • Identity Center, roles and permissions per team
  • Hardening of EKS, secrets and pipelines
Detection

Automated detection and response

GuardDuty, Security Hub, Inspector and Config with rules tuned to your environment to cut noise, and automated responses for the repetitive.

  • Automatic isolation of compromised instances
  • Revocation of exposed credentials within minutes
  • Alerts routed to your channel with context
Compliance

Audit preparation

We map your technical controls to ISO 27001, ENS, SOC 2 or PCI DSS and generate automated evidence so the audit does not stall your team.

  • Audit Manager with custom frameworks
  • Exportable evidence per control
  • Support during the external audit
Process

How we run an audit.

Scope and access

2 days

We define the accounts and systems in scope. We request a read-only role with the published policy; never administrator credentials.

Analysis

1 week

Automated tools plus manual review of IAM, network and architecture. Every finding carries reproducible evidence.

Report and plan

3 days

Separate presentations for management and engineers: business risk for one, concrete steps for the other.

Remediation

4 to 10 weeks

We close the critical and the least effortful items first. We verify with a second pass at the end.

Frequently asked questions

Before giving us access.

What permissions do you need to audit?

A role with the SecurityAudit and ViewOnlyAccess managed policies, assumable from our account with an ExternalId. We publish the exact policy and you remove it when we are done.

Will you disrupt production?

No. The audit is read-only. Active penetration tests are agreed separately, with a signed window and scope.

Do you also cover application code?

We review the deployment pipeline, dependencies and configuration. In-depth application code review is coordinated with a specialised partner when needed.

What do we get if we do not continue with remediation?

The full report with evidence, the prioritisation and the estimated remediation plan. It is yours and your team can execute it on its own.

Do you know how many critical findings are open today?

A ten-day audit gives you the answer with evidence.

Request an audit
Contact

Request a security audit.

Tell us how many accounts you have, which regulations apply and whether an external audit is on the horizon. We reply within 48 hours.