About Expertise Work Managed Apps
Business Website Online Store Sales CRM Team Drive Online Academy Newsletter System Booking System Shared Inbox Knowledge Base Short Links Business Manager Photo Gallery Survey Platform Community Forum Project Boards Estate Agency Car Workshop Restaurant Clinic Photography Studio
AWS
Assess & advise Build & migrate Automate & operate Secure & comply Urgent & go-live
Projects
Hosted Monitoring & Dashboards Self-Hosted Observability Stack Bulk Document Data Extraction Email Deliverability Diagnosis & Repair SEO Migration Recovery AWS Security Review VPS Hardening & ModSecurity Cloud Architecture & Resilience Review SSL & Server Configuration Container Security Review DNS & Email Troubleshooting DevOps Deployment & Rollback Review WordPress Hardening Retainer Data Pipeline Rerun Review Metric Reconciliation
Free Tools
Website Health Check Email Domain Health Check DNS Health Check SSL Certificate Checker Redirect Chain Checker Robots.txt Checker XML Sitemap Validator Docker Compose Checker WordPress Security Check AWS IAM / S3 Policy Checker Domain Registration Lookup Uptime Monitoring Trial Downtime Cost Calculator AWS Cost Estimator Cloud Architecture Self-Assessment DevOps Engagement Builder Self-Managed VPS vs Managed AWS
Blog Certifications Hire Me

AWS Security Posture Review

What is exposed, who can reach it, and what an attacker would find first. Nothing is changed.

Price and scope

From $299

Typically $299–$699, fixed in writing before anything starts.

2–4 days
Working days, counted from the moment I have access — not from the day you agree.

What moves it up

  • More than about fifty IAM principals, where the permission graph stops being readable by hand
  • Several accounts, especially with roles trusting each other across boundaries
  • A customer security questionnaire or an insurance renewal driving the deadline

Some of this you can check yourself, right now, for free: AWS IAM / S3 Policy Checker →

Four questions with no answerFour basic questions about an AWS account — what is reachable from the internet, which credentials are unused but still valid, whether the root account has MFA, and whether anything would report it being used. Each answer column is empty.not findings. questions the account cannot currently answer.what is reachable from the internet?unknownwhich credentials still work but are unused?unknowndoes the root account have MFA?unknownwould anything tell you if root were used?unknown
AWS Security Posture Review

What actually goes wrong

Security reviews usually find the same thing, and it is rarely a vulnerability: it is that nobody can answer basic questions about their own account. What is reachable from the internet right now. Which credentials have not been used in a year but still work. Whether the root account has MFA. Whether anything would tell you if it were used. None of that requires a scanner to discover and none of it is exotic — it just requires somebody to sit down and look, which is the thing that never gets scheduled because it is not urgent until it is.

How I find it

  • aws accessanalyzer list-findings — resources shared outside the account, as AWS itself computes it
  • aws iam get-account-summary, for root MFA, root access keys and the password policy
  • aws ec2 describe-security-groups --filters Name=ip-permission.cidr,Values=0.0.0.0/0, across all regions
  • aws securityhub get-findings against the Foundational Security Best Practices standard

What you get

  • A prioritised findings document, ordered by what an attacker reaches first rather than by severity label
  • Every finding with the command that produced it, so you can verify and re-run it
  • The exposure map — what is reachable from the internet, and what that reaches in turn
  • A short list of what to fix this week, separate from the longer list
  • The questions the account cannot currently answer, which is often the real finding

Questions

Is this a penetration test?

No. This is a configuration review read from the AWS APIs — nothing is attacked, nothing is exploited, and no traffic is sent to your systems. A penetration test is a different engagement with different rules and, on AWS, its own notification requirements.

How is this different from the security hardening work?

This one only looks. Hardening changes things. They are deliberately separate so you can find out what is wrong without committing to a remediation project, and so nothing moves in your account while you are still deciding.

Do you use automated scanners or do this by hand?

Both, in that order. Access Analyzer and Security Hub do the sweeping, because they are thorough and free. The value I add is the part they cannot do: deciding which of two hundred findings actually matter for your architecture, and finding the ones that are only visible if you understand what the system is for.

What if you find something serious?

You hear about it immediately rather than in the report at the end of the week. Anything genuinely urgent gets a message the same day with what to do about it, whether or not you engage me to do it.

AWS IAM & Access Cleanup

Who can do what in your account, who has not used it in a year, and what to take away first.

From $299 2–4 days

Want this done?

Tell me what you are running and I will come back with a fixed price and a date. If it turns out you do not need this, I will say that instead.

Prefer to talk? Book a free call ↗  ·  Or hire me on Upwork ↗  ·  Typical reply within one business day.

When I answer

Sunday to Thursday, 09:00–18:00 EET. Outside that I will still look, but I will not promise a time.

No 24/7 desk, and I will not pretend otherwise

One person, one time zone. If round-the-clock cover is what you need, you need a team, and I will say so rather than sell you a plan that cannot deliver it.

Your AWS bill stays yours

You pay Amazon directly and you keep control of the account. Nothing here resells your infrastructure or sits between you and your own billing.

A price that starts with "from" is a starting price

Every service page lists exactly what pushes a quote above it, before you ask. You get a fixed number in writing before any work begins.