AWS audit
An AWS account that grew over time rarely looks the way anyone would design it today. I review it against the six Well-Architected pillars and security benchmarks (CIS, AWS Foundational Security Best Practices), show you where you are exposed, where you overpay and where an outage would hurt — and write down what to do about it, in an order that makes sense. As a member of the AWS Partner Network I audit the way I run my own production accounts.
What you get
- Well-Architected review of all six pillars: operational excellence, security, reliability, performance, cost and sustainability
- Security assessment against the CIS AWS Foundations Benchmark and AWS Foundational Security Best Practices: IAM and access, network and segmentation, encryption, logging and detection, backup and recovery
- Cost review: idle and oversized resources, missing reservations and savings with an estimated benefit
- Prioritised remediation plan with effort estimates; findings mapped to ISO/IEC 27001, NIS2 and DORA where they apply to you
- Optionally I carry out or lead the remediation with your team and verify it in a follow-up audit
When to get in touch
- The AWS account grew for years without an architect and nobody is sure what is in it
- You need to show for ISO/IEC 27001, NIS2 or DORA that the cloud is governed and secured
- The AWS bill grows faster than the traffic
- A migration, a new product or a customer audit is coming and you want to know where you stand
How it works
- 01
Scope & access
Accounts, regions, critical workloads; read-only access through an IAM role
Duration: 1 h - 02
Assessment
Automated configuration collection plus manual review and interviews with the team
Duration: 3–6 d - 03
Report & plan
Findings by pillar and severity, remediation plan — walked through live with your engineers
Duration: 1–2 d - 04
Follow-up audit
Remediation verified and the report updated
Duration: as agreed
Other services
All services →Audit and regulatory readiness
Gap analysis, internal audit and certification readiness for ISO/IEC 27001 and ISO 22301, audits under NIS2 and the Czech Cybersecurity Act, DORA compliance assessment — including preparation of the documentation the regulation requires.
Read more →Risk assessment
Information-security risk analysis, business-impact analysis (BIA) and vendor risk assessment under ISO/IEC 27005 and the requirements of NIS2 and DORA — with a register you can actually maintain.
Read more →Technical due diligence
An independent assessment of the technology, security, operations and team of a company you are buying, funding or depending on — in days, with a report for the investment committee.
Read more →Thirty minutes that save you months
Tell me what you are dealing with — an audit before certification, a letter from the regulator, a customer requirement, or just not knowing where you stand. Within two working days you get a concrete proposal with scope and price.
- You talk directly to the auditor who does the work
- Fixed scope and price before anything starts
- NDA on request, deliverables in Czech or English