Cloud Security

AWS Security Consulting

We assess and harden AWS environments end to end — account structure and guardrails, identity and least privilege, network segmentation, logging and detection, workload protection and compliance readiness — with remediation delivered as Infrastructure as Code.

The problem we solve

AWS estates grow faster than the guardrails around them. Accounts get created for a project and never governed, IAM policies accumulate wildcards nobody dares remove, and the blast radius of a single compromised credential quietly expands.

Detection is often nominally enabled but operationally useless: GuardDuty findings landing in an unwatched console, CloudTrail configured per account with no central retention, and no defined response for the alerts that do matter.

When an enterprise customer or auditor finally asks for evidence — who can reach production, how public exposure is prevented, how long logs are kept — the answer takes weeks to assemble.

An AWS security review is only worth what gets fixed. We prioritise findings by exploitability and blast radius rather than by scanner severity, and we hand back remediation as code your platform team can review, test and reuse.

Our approach

Adapted to your environment and constraints — but the shape of the work is consistent.

  1. Baseline the estate

    We review AWS Organizations structure, service control policies, account separation, root account handling, region enablement and the existing landing zone against the AWS Well-Architected Framework security pillar and CIS AWS Foundations Benchmark.

  2. Fix identity first

    Identity is the perimeter. We analyse IAM roles, policies, permission boundaries, identity federation and IAM Identity Center configuration, use IAM Access Analyzer and access history to remove unused permissions, and replace long-lived access keys with role assumption and OIDC workload identity.

  3. Segment and control the network

    VPC design, subnet and routing review, security group and NACL hygiene, egress control, VPC endpoints to keep traffic off the public internet, and WAF and Shield configuration at the edge.

  4. Make detection real

    Organisation-wide CloudTrail with immutable central storage, GuardDuty and Security Hub enabled across accounts and regions, Config rules for drift, log routing into your SIEM, and documented response runbooks for the finding types that warrant one.

  5. Sustain posture

    Guardrails as code — SCPs, Config conformance packs, IaC policy checks in CI — so new accounts and new workloads inherit the standard rather than requiring another remediation project next year.

Expected outcomes

What changes as a result of the engagement.

  • A documented, defensible AWS account and guardrail structure
  • Materially reduced IAM privilege and fewer standing credentials
  • Public exposure of storage, databases and endpoints under active control
  • Centralised, tamper-resistant audit logging with defined retention
  • GuardDuty and Security Hub findings routed to an owner with a runbook
  • Faster, evidence-backed responses to customer and audit questionnaires
  • Posture that holds as the estate grows, because guardrails are code

Typical deliverables

Confirmed in the proposal before work starts, and adjusted to scope.

  • AWS security assessment report scored against CIS and Well-Architected
  • Prioritised remediation roadmap with effort and risk-reduction estimates
  • Target-state AWS security architecture and landing-zone design
  • IAM least-privilege model and role/permission-boundary design
  • Service control policy set
  • Logging, monitoring and detection design
  • Terraform or CloudFormation modules implementing agreed controls
  • Incident response runbooks for priority AWS finding types
  • Compliance control mapping (SOC 2, ISO 27001, PCI DSS)

What this covers

The specific capabilities available under this service. Engagements usually draw on a subset — we scope to the problem, not the catalogue.

Architecture & governance

  • AWS security architecture review
  • Multi-account and Organizations design
  • Service control policies
  • Landing zone and account vending
  • Well-Architected security pillar review
  • CIS AWS Foundations Benchmark assessment

Identity & access

  • IAM least-privilege design
  • Permission boundaries and SCP guardrails
  • IAM Identity Center and federation
  • Cross-account access patterns
  • Access key elimination and OIDC workloads
  • IAM Access Analyzer review
  • Secrets Manager and KMS key policy

Detection & response

  • Organisation-wide CloudTrail
  • Amazon GuardDuty deployment and tuning
  • AWS Security Hub aggregation
  • AWS Config rules and conformance packs
  • CloudWatch logging and alerting
  • SIEM integration
  • Incident response runbooks

Network & workload

  • VPC segmentation and routing review
  • Security group and NACL hardening
  • Egress filtering and VPC endpoints
  • AWS WAF and Shield configuration
  • S3 public access and encryption controls
  • EKS and ECS workload protection
  • Cloud posture management (CSPM)

Who this is for

  • Teams running production workloads on AWS at multi-account scale
  • Engineering organisations that grew on AWS without a security baseline
  • Companies preparing for SOC 2, ISO 27001 or PCI DSS on AWS
  • Platform teams standing up or rebuilding a landing zone
  • Security leaders who need visibility across accounts they do not control

Recognise your situation? A 30-minute discovery call is the fastest way to find out whether this is the right engagement.

Book a security consultation

Common questions

Do you remediate, or only report?

Both, depending on scope. Many clients want the assessment plus working Terraform or CloudFormation for the agreed fixes, so remediation ships as reviewable code rather than console changes nobody can reproduce.

How disruptive is IAM least-privilege work?

Done carelessly, very. We work from actual access history and Access Analyzer data, stage changes behind permission boundaries, and monitor for denials before enforcing — so permissions come down without breaking production.

We are on both AWS and Google Cloud. Can you cover both?

Yes. We work across AWS and GCP and can deliver a single consolidated posture view with consistent standards, rather than two disconnected assessments.

These engagements are often scoped together — the underlying risks overlap.

Cloud Security

GCP Security

Google Cloud security architecture, IAM and organisation policy, VPC design, Security Command Center, Workload Identity and GKE hardening — built and maintained as code.

Cloud Security

Kubernetes & Containers

Cluster hardening, workload isolation, admission control, image supply-chain integrity and runtime detection for EKS, GKE, AKS and self-managed Kubernetes.

DevSecOps & AppSec

DevSecOps

Build security into the delivery pipeline instead of bolting it on at the end — secure SDLC, CI/CD hardening, IaC scanning, supply-chain controls and guardrails engineers will actually keep.

Discuss your security challenges

Tell us what you are trying to secure and where it hurts. We will tell you what we would do first, whether or not you engage us.