Cloud security assessment
AWS Security Assessment
Your AWS account is where the business actually runs, and securing what you put in it is on you. This is a structured review of how your environment is set up and where it is exposed, with the shortest credible path to a stronger posture, so a quiet misconfiguration does not turn into a costly incident.
Book a discovery callSecure is not the default
Amazon Web Services secures the cloud infrastructure itself, the hardware and the network it runs on. Everything you build on top is yours to protect.
Most failures here are not exotic. They come from ordinary misconfigurations that pile up as you ship fast, and stay quiet until someone finds them.
An independent review measures your account against recognised best practice, ranks what it finds by what actually matters, and shows you where you stand. That is what this assessment is for.
What we look at
We review your environment against industry-recognised best practices, including Amazon's own security guidance, across the areas where cloud risk tends to concentrate. What we find becomes a prioritised roadmap.
Identity and access management
The accounts that take over an environment are rarely the obvious admins. A role created to deploy your app can quietly become an admin one, if it can hand its power to a machine it launches. We hunt the paths where one ordinary permission, chained to the next, ends in control of the whole account.
Network exposure
The whole internet is scanned constantly, so anything you expose is found. The danger is rarely the website itself. It is a management or database port left open, or a server reachable that was only meant for testing. We look at what is reachable from where, and what should not be.
Data protection
Storage that is private today can be public after one wrong change. We review where your data lives, how it is protected, and who can reach it.
Logging and visibility
When something goes wrong, you can only investigate as far back as your logs reach. We check whether yours would still show what happened, and how far back.
Threat detection
Without something watching, an attacker can move through your account unnoticed. We look at whether anything would catch the signs early, and whether a real person would see the alert in time to act.
What you walk away with
A prioritised picture of where your AWS environment stands. Every finding ranked by the risk to your business and the effort to fix it, and a route to a stronger baseline. A report your board and your engineers can both act on, and the evidence an investor's technical due diligence asks for.
We map the path and tell you what to fix first. And if you want our help making the changes, we will be happy to give it.
The shape of a finding
A deploy role with a path to admin
- What it is
- A role meant only to deploy the app can reach further than it should.
- If it is used
- It opens a path to the whole account.
- The fix
- Narrow what the role can do and reach.
- Fix within
- 7 days
An illustration of how we structure a finding. The data is generic.
Want a maturity rating across your whole security programme? The Custos Secure Baseline scores your security maturity and maps the way to the standard enterprise security reviews expect.
See the baselineCustos was founded by Liran Aknin, who has run security operations and hardened cloud environments in production. The work is delivered to that standard.
Who you work withSee where your AWS security stands
A 30-minute discovery call to scope the review and the questions that matter most for your environment.
Book a discovery call