Security · OrbitAUDIT 2–3 weeks · Fixed price · Written findings

A defensible answer to "is our AWS account secure?"

An AWS security audit covering 100+ checks across IAM, networking, logging, data, edge, and incident readiness. You leave with a prioritized findings list and a written report you can take to leadership or an auditor, walked through with me so you know what matters first.

Duration
2–3 weeks
Coverage
100+ checks
Outcome
A report, walked through with you
Defensible to
Leadership, auditors, customers
Why this exists

Insecure by accumulation.

Nobody sets out to build an insecure account. It accumulates: years of small decisions stacked up. A public S3 bucket that was 'temporary'. An IAM user with admin and a leaked key. CloudTrail logs nobody is shipping anywhere. None of it is dramatic. All of it adds up.

OrbitAUDIT is a point-in-time review against the checks I've built up over the years, with a written record you can act on or hand to an auditor. The fix list is prioritized by impact, so you know what to do first and what can wait.


What's included

What the audit covers — and what you walk away with.

Six domains, and a set of checks I built myself out of the accounts I've audited and run over the years. Every finding includes evidence and a recommended action.

Identity & access

IAM users, roles, policies, access keys, MFA posture, root-account use, and the federation story. The first place attackers look.

Networking

VPC design, security groups, NACLs, exposed endpoints, peering, and edge protections. Where the blast radius lives.

Logging & audit trail

CloudTrail, AWS Config, VPC Flow Logs, S3 access logging, and how long any of it is retained. The evidence layer.

Data protection

Encryption at rest and in transit, KMS key hygiene, S3 public access, RDS configuration, and the backup posture across services.

Edge & public surface

CloudFront, ALB, public IP exposure, WAF coverage where it exists, and the inventory of internet-reachable resources.

Incident readiness

GuardDuty findings, alerting paths, and the runbooks you have (or don't) for the alerts that fire. A surprising amount of audit value lives here.

Prioritized findings list

Every finding scored by impact and effort to fix. Suitable as a quarter's backlog, or as evidence for an upcoming compliance review.

A walkthrough, not a drop

I go through the report with you rather than emailing it over. We cover the top findings, agree what actually matters first, and I answer the questions your team will ask next.

How the audit runs

Two to three weeks. Read-only access. Written results.

It starts with data collection. I'm given a read-only role across the relevant accounts and run the checks — automated where possible, manual where it matters. You stay heads-down on real work.

Then analysis and write-up. Every finding gets evidence, an impact and effort score, and a recommended action. The output is a PDF report.

We finish by going through it together. The top findings, the backlog in priority order with whoever owns it on your side, and what needs fixing before the audit closes.

Related services

What teams often pair with this.

Most audits surface a handful of things worth fixing immediately. These are the engagements that usually follow.

Ready for a real answer

Book an audit before someone else does it for you.

Send a paragraph about the size of your AWS footprint, what's prompting the audit (compliance, incident, new customer requirement), and the timeline. I'll come back with a scope and a quote.