Checklist

The AWS Security Checklist Every Startup Should Run Before It Scales

Most startups don't have a security gap because nobody cares. They have one because nobody had a spare afternoon. Shipping features and closing customers wins out over reviewing IAM policies almost every time, until something forces the issue.

This is the checklist we run at the start of every AWS Startup Security Baseline sprint, before we touch anything else. It takes about twenty minutes to run yourself, and it catches most of what actually causes problems later.

1. Root account and MFA

Start here because root access can do anything. Log into the AWS account as root exactly once, just to check two things: is MFA turned on, and when was root last used for something other than confirming it exists?

2. IAM users and roles

Pull up your full list of IAM users and roles. In most growing AWS accounts, this list is longer than anyone expects, and a chunk of it shouldn't exist anymore.

3. CloudTrail coverage

CloudTrail usually looks fine in the account and region someone checks most often. The gaps show up in the regions and accounts nobody thinks about.

4. S3 public access

Public S3 buckets are one of the most common causes of real, public incidents, and one of the easiest things to check.

5. Backup existence and testing

Backups being configured and backups actually working are two different things. The second one only gets confirmed by testing a restore.

This is the short version. The full 10-point checklist includes exact steps for each category and a few additional checks we didn't cover here.

Get the Full Checklist

If you run through this and find more than a couple of gaps, that's normal, not alarming. It's also usually the point where a fixed-scope sprint is faster than trying to fix everything piecemeal between other work. The AWS Startup Security Baseline sprint covers all five of these areas in a fixed 7 to 14 day engagement, with two live working sessions where we fix what we can together instead of just handing you a list.