Cloud / AWS

AWS architecture, security and cost review.

An AWS estate that grew faster than its guardrails. We review it and write the fixes down.

AWS services

What we examine on AWS.

Organisations and Control Tower

Account structure, service control policies and whether the guardrail is enforced or just written.

IAM

Wildcard actions, unrotated access keys, role trust policies and the paths to administrator.

Detection

GuardDuty, Security Hub and CloudTrail: coverage per region, and whether findings reach a human.

Network

VPC exposure, security groups, NAT charges and cross-zone data transfer.

Cost

Savings Plans coverage, idle GPU and EBS, and S3 lifecycle rules that were never applied.

Failure modes

What we find on AWS estates.

  • GuardDuty enabled in one region while workloads run in three.
  • Service control policies written but never applied to the workload accounts.
  • CloudTrail logging to an account the same admins can delete from.
  • Savings Plans bought before rightsizing, locking in the oversized fleet.
  • Long-lived access keys on an IAM user instead of a role.
How to start

Three reviews, one platform.

Questions before you book

Practical answers.

Are you an AWS partner?

No. We hold no AWS partner tier and no partner funding. The recommendation is not shaped by a commercial arrangement with AWS.

Do you work in ap-southeast-2?

Yes. Data residency in the Sydney region is a normal part of the review for Australian buyers.

Can you review without production access?

We work read-only. Where a check needs more, we say so and you decide.

Let’s scope it

Scope a AWS review.

Send the accounts in scope and what prompted the question. We confirm scope and fee before any access.

Request a quote

Last reviewed: