AWS Security and Access Review
Identify IAM privilege creep, internet-exposed assets, unencrypted storage, and missing audit trails through structured technical inspection.
Focus on access controls, IAM hygiene, and exposure reduction.
Engagement Guardrails
- Delivered directly by Shaun Estcourt (AWS Certified Solutions Architect – Associate)
- Strictly read-only access for assessments; zero root credential handling
- Plain-English findings report with evidence referenced to AWS resource IDs
Overview & Operational Context
Cloud security incidents rarely stem from zero-day flaws; they almost always arise from misconfigured permissions, open security groups, or forgotten access keys. This review focuses strictly on the identity boundary, exposure perimeter, and protective controls in your AWS accounts to highlight areas for improvement and assist your team in reducing risk.
What we inspect and evaluate
Every review is tailored to your architecture while maintaining systematic rigor across primary risk vectors.
IAM Users, Roles & Policies
Review of identity definitions, inline policy sprawl, overly permissive wildcards (*:*), and service-linked role boundaries.
Privileged Access & MFA Posture
Verification of root account protections, hardware/virtual MFA enforcement, and separation of administrative duties.
Public Perimeter & Security Groups
Detection of open ingress rules (0.0.0.0/0) on administrative ports (SSH 22, RDP 3389, databases), and public S3 bucket policies.
Logging & Audit Trails
Inspection of AWS CloudTrail coverage, log file validation, S3 access logging, and VPC Flow Logs configuration.
Data Protection & Encryption
Review of AWS KMS key usage, EBS default encryption, RDS encryption at rest, and TLS enforcement in transit.
Credential Lifecycle & Secrets
Audit of inactive access keys, rotation schedules, and usage of AWS Secrets Manager / Parameter Store versus hard-coded credentials.
What you will understand afterwards
Typical Deliverables
Start a discussion about your environment
Discuss your AWS setup directly with Shaun Estcourt to determine whether this service is the right fit.