AWS IAM & Access Cleanup
Who can do what in your account, who has not used it in a year, and what to take away first.
From $299 2–4 days
What is exposed, who can reach it, and what an attacker would find first. Nothing is changed.
From $299
Typically $299–$699, fixed in writing before anything starts.
What moves it up
Some of this you can check yourself, right now, for free: AWS IAM / S3 Policy Checker →
Security reviews usually find the same thing, and it is rarely a vulnerability: it is that nobody can answer basic questions about their own account. What is reachable from the internet right now. Which credentials have not been used in a year but still work. Whether the root account has MFA. Whether anything would tell you if it were used. None of that requires a scanner to discover and none of it is exotic — it just requires somebody to sit down and look, which is the thing that never gets scheduled because it is not urgent until it is.
aws accessanalyzer list-findings — resources shared outside the account, as AWS itself computes itaws iam get-account-summary, for root MFA, root access keys and the password policyaws ec2 describe-security-groups --filters Name=ip-permission.cidr,Values=0.0.0.0/0, across all regionsaws securityhub get-findings against the Foundational Security Best Practices standardNo. This is a configuration review read from the AWS APIs — nothing is attacked, nothing is exploited, and no traffic is sent to your systems. A penetration test is a different engagement with different rules and, on AWS, its own notification requirements.
This one only looks. Hardening changes things. They are deliberately separate so you can find out what is wrong without committing to a remediation project, and so nothing moves in your account while you are still deciding.
Both, in that order. Access Analyzer and Security Hub do the sweeping, because they are thorough and free. The value I add is the part they cannot do: deciding which of two hundred findings actually matter for your architecture, and finding the ones that are only visible if you understand what the system is for.
You hear about it immediately rather than in the report at the end of the week. Anything genuinely urgent gets a message the same day with what to do about it, whether or not you engage me to do it.
Who can do what in your account, who has not used it in a year, and what to take away first.
From $299 2–4 days
A record of who did what, kept long enough to be useful and somewhere it cannot be edited.
From $299 2–4 days
Tell me what you are running and I will come back with a fixed price and a date. If it turns out you do not need this, I will say that instead.
Prefer to talk? Book a free call ↗ · Or hire me on Upwork ↗ · Typical reply within one business day.
Sunday to Thursday, 09:00–18:00 EET. Outside that I will still look, but I will not promise a time.
One person, one time zone. If round-the-clock cover is what you need, you need a team, and I will say so rather than sell you a plan that cannot deliver it.
You pay Amazon directly and you keep control of the account. Nothing here resells your infrastructure or sits between you and your own billing.
Every service page lists exactly what pushes a quote above it, before you ask. You get a fixed number in writing before any work begins.