Find the AWS risks that actually deserve engineering time.

We manually validate the findings that matter, remove the noise your team will never action, and package the review into a report your engineers can use without translating scanner output into real work.

Free 30-minute intro call, no commitment. You get a fixed price before any paid work starts. Your team's time: a 30-minute kickoff and a 30-minute walkthrough; we do the rest.

From $495
Fixed scope and fixed price, agreed in the free intro call
1 to 2 weeks
From kickoff to the report walkthrough with your team
Search
Validated findingsInfo

Each finding checked by hand against the running account

Export reportCreate tickets
Scanner findings
1,248
Suppressed
1,225
Validated
23
Fix first
3
Findings (23)
Hide suppressed
SeverityFindingValidation
criticalEC2.19 Security groups should not allow unrestricted access to ports with high riskExploitable
criticalIAM.6 Hardware MFA should be enabled for the root userConfirmed
highS3.8 S3 general purpose buckets should block public accessConfirmed
highIAM.1 IAM policies should not allow full "*" administrative privilegesConfirmed
EC2.19 · sg-0b7f3c9e (orders-db)
ValidationBusiness impactRemediation
Found
TCP 5432 open to 0.0.0.0/0
Owner
Platform team
Effort
15 minutes
1aws ec2 revoke-security-group-ingress \
2 --group-id sg-0b7f3c9e21a4d5f86 \
3 --protocol tcp --port 5432 \
4 --cidr 0.0.0.0/0

Sample account, checked against real AWS Security Hub controls.

Where security reviews break down

The auditor asks which findings matter, and the scanner export has no answer.

A SOC 2 auditor, an enterprise customer's security questionnaire or an investor's due diligence all ask the same thing: which risks are real, and what are you doing about them? Security Hub lists everything as a finding, so nobody can answer with confidence.

  1. 01
    Hundreds of findings, all marked urgent
    The handful that are real risks in your account, confirmed by hand.
  2. 02
    A questionnaire nobody wants to sign
    A report you can share with auditors, customers and investors.
  3. 03
    Fixes that might break production
    Console and CLI steps for each finding, ordered so the riskiest gap closes first.
Report preview

A report your engineers fix from, not another PDF to triage.

Built for engineering use. Starts with the highest-risk issues, shows the validated technical detail, and ends with a remediation path your team can execute the same day.

Why teams act on it

Every section answers a question the team would have asked anyway: what matters first, what is real in this account, and how to fix it without another round of interpretation.

Sample report: a made-up account, checked against real AWS Security Hub controls.

Executive summary

What you see first
Every finding in one scorecard

One scorecard with every validated finding, ranked by severity and business impact. No scrolling through scanner exports to figure out where to start.

After the report

Then we fix it, as pull requests to your repo.

The report tells you which findings to fix first. Your team can work through them, or we ship the fixes: infrastructure as code in your own repository, reviewed and merged like any other change.

  • A fixed quote for the fixes before any work starts
  • Every change lands as a pull request your team reviews
  • The code stays in your repository, so nothing is locked in
From a client
“He has provided invaluable direction within the AWS system to help us with optimization of the services that we are utilizing and has laid out critical steps to provide security enhancements for the App.”
Mike Cantrell
Founder and CEO
Read the reviews on Google
How the review runs

The security review roadmap

The engagement is structured to move quickly from access to validated findings. The goal is not a generic audit artifact. It is a report your team can use to reduce real risk with less interpretation work.

  1. 30-minute kickoff

    Context and access

    We agree the scope and the concerns you already have, then set up time-limited, read-only access. Every action is logged in your own CloudTrail.

    • Scope agreed
    • Read-only access in place
    • Known concerns logged
  2. 4 to 8 days

    Deep validation against controls

    We check IAM, networking, storage, logging and adjacent services against 200+ controls, including AWS Foundational Security Best Practices, then confirm which findings are real risks in your environment.

    • Validated findings
    • False positives filtered out
    • Architecture-aware notes
  3. 30-minute walkthrough

    Report and remediation path

    We walk your team through a report built for engineering: prioritized risks, the evidence behind each one, and console and CLI steps you can act on the same day.

    • Executive summary
    • Technical deep dive
    • Console and CLI remediation
    • Prioritized roadmap
Security reviews start from
$495

We check your accounts against 200+ controls, confirm by hand which findings are real risks, and walk your team through them. You leave knowing the few to fix first, with the console and CLI steps for each: fix them yourselves, or have us fix them for a fixed quote. Bigger estates have more to check, so $495 is where it starts.

Buy it through AWS Marketplace to keep procurement and billing inside your AWS account.

Not quite the right fit?

Related services, and when to pick them

See all AWS services
Security Review FAQ

What teams ask
before granting access

What does the AWS Security Review cost?

Security Reviews start from $495. The final fixed price depends on the size of your AWS environment, the number of accounts, and the depth of remediation guidance you need. We confirm the scope and the price during the free intro call before any paid work starts. No commitment required. See how assessment pricing works.

Why pay you when AWS Security Hub and Trusted Advisor are free?

Security Hub and Trusted Advisor are useful signal sources, but they generate volume, not prioritization. They surface every finding regardless of whether it applies to your architecture, and they leave the validation, business-impact analysis, and remediation work to your team. Our review adds that layer: we filter for false positives, map findings to your specific workloads, and deliver a fix path your engineers can execute the same day.

How do you keep temporary access to our AWS account secure?

We use time-limited IAM roles with only the permissions required for the assessment. All activity is logged in your CloudTrail, and we remove access as soon as the review concludes. No long-lived credentials are ever created.

How long does the review take from start to finish?

A typical Security Review takes 1 to 2 weeks end to end: a 30-minute kickoff to scope and grant access, 4 to 8 days of analysis depending on environment size, and a 30-minute walkthrough where we present the findings live. You see the report and the walkthrough at the same time, not weeks later in your inbox.

What is included in the AWS Security Review Report?
Our Security Review Report provides a detailed breakdown of every security finding:
  • Finding Details: A clear explanation of the issue and its potential impact on your environment.
  • Affected Resources: A specific list of resources (e.g., Security Groups, S3 Buckets including ARNs) impacted by the finding.
  • Recommendation & Source: Step-by-step remediation instructions, including CLI commands and links to official AWS documentation for further reading.
This structured approach ensures you have a complete overview of each risk and the exact steps needed to fix it.
How is this different from relying on automated security tools?

Automated tools surface signals; we add context. We validate the findings, remove false positives, and deliver remediation guidance tailored to your workloads. We benchmark against the CIS AWS Foundations Benchmark, AWS Foundational Security Best Practices, the AWS Well-Architected Security Pillar, and relevant compliance frameworks such as SOC 2, HIPAA, and PCI DSS.

Can we share the report with auditors, customers, or investors?

Yes. The report is yours to use. Clients commonly share it during SOC 2 audits, with enterprise customers asking for security documentation, and with investors during due diligence. Each finding references the relevant CIS, AWS Foundational Security Best Practices, and SOC 2 / HIPAA / PCI-DSS controls so the evidence is recognizable to any auditor.

What if there are hundreds of findings? Will the report be overwhelming?

Findings are grouped by severity, service, and remediation pattern. For widespread issues we highlight bulk fixes, and every recommendation includes step-by-step console guidance plus copy-ready CLI commands so your team can act quickly.

What happens after the review, and can you help implement fixes?

We deliver the report, walk you through it in a 30-minute session, and then you choose the path forward: handle remediation internally, request a quote for us to assist, or schedule a follow-up validation review at a reduced rate. Implementation support is optional but available when you need it.

Book the review

Book a free security call

Scanners flatten every finding into one list. We'll look at your security posture and whether a focused review is the right first step.

You talk to Danny Steenman, the engineer who does the work. Pick a time below and he confirms it by email.

  • Free 30-minute call, no commitment
  • Fixed price before any paid work
  • Read-only, time-limited access