Skip to main content
Kervora Cloud Emblem
Kervora CloudAWS Consultancy
AWS Consulting Service

AWS Security and Access Review

Identify IAM privilege creep, internet-exposed assets, unencrypted storage, and missing audit trails through structured technical inspection.

Focus on access controls, IAM hygiene, and exposure reduction.

Engagement Guardrails

  • Delivered directly by Shaun Estcourt (AWS Certified Solutions Architect – Associate)
  • Strictly read-only access for assessments; zero root credential handling
  • Plain-English findings report with evidence referenced to AWS resource IDs

Overview & Operational Context

Cloud security incidents rarely stem from zero-day flaws; they almost always arise from misconfigured permissions, open security groups, or forgotten access keys. This review focuses strictly on the identity boundary, exposure perimeter, and protective controls in your AWS accounts to highlight areas for improvement and assist your team in reducing risk.

Technical Scope

What we inspect and evaluate

Every review is tailored to your architecture while maintaining systematic rigor across primary risk vectors.

1

IAM Users, Roles & Policies

Review of identity definitions, inline policy sprawl, overly permissive wildcards (*:*), and service-linked role boundaries.

2

Privileged Access & MFA Posture

Verification of root account protections, hardware/virtual MFA enforcement, and separation of administrative duties.

3

Public Perimeter & Security Groups

Detection of open ingress rules (0.0.0.0/0) on administrative ports (SSH 22, RDP 3389, databases), and public S3 bucket policies.

4

Logging & Audit Trails

Inspection of AWS CloudTrail coverage, log file validation, S3 access logging, and VPC Flow Logs configuration.

5

Data Protection & Encryption

Review of AWS KMS key usage, EBS default encryption, RDS encryption at rest, and TLS enforcement in transit.

6

Credential Lifecycle & Secrets

Audit of inactive access keys, rotation schedules, and usage of AWS Secrets Manager / Parameter Store versus hard-coded credentials.

What you will understand afterwards

Where unnecessary privilege or public exposure exists across your accounts
The exact security controls that require strengthening based on AWS best practices
How to isolate sensitive workloads without interrupting daily developer workflows
Practical remediation guidance to address identified vulnerabilities step-by-step

Typical Deliverables

Security & Access Assessment Report detailing observations by severity
IAM & Network Exposure matrix with resource-level evidence
Remediation recommendations structured for controlled implementation
Security posture review session directly with the consultant

Start a discussion about your environment

Discuss your AWS setup directly with Shaun Estcourt to determine whether this service is the right fit.