Back to case studies
SaaS 5 weeks
Cloud Security Assessment
Cloud Security Hardening
A regulated SaaS company required CIS benchmark validation across a multi-account AWS organization. We identified IAM privilege gaps and public-exposure drift that would have failed an upcoming SOC 2 audit.
Engagement scope: AWS multi-account organization, 11 accounts
11Accounts reviewed
23CIS controls failed
100%Exposure reduction
Engagement Objectives
- Validate CIS AWS Foundations benchmark posture
- Review IAM boundaries and cross-account trust
- Inventory unintended public exposure
Approach
We began with a scoping workshop to align on in-scope assets, rules of engagement, and success criteria. Over the following weeks, our consultants applied a manual-first methodology aligned to Cloud Security Assessment, validating every finding before reporting and coordinating closely with the client's engineering team.
Outcome
We produced an account-by-account hardening roadmap and worked with the platform team to remediate the top exposures. The organization passed its SOC 2 Type II audit the following quarter.
What We Delivered
Executive summary for leadership
Technical report with reproducible PoCs
CVSSv3.1 scored findings
Remediation walkthrough with engineers
Attack-path visualization
Free retest to confirm closure