The exact checklist we run on every sprint before we touch anything else. Root account, IAM, CloudTrail, S3, and backups, in about twenty minutes. Useful on its own, whether or not you ever book the sprint.
Founders and engineers at startups and small SaaS teams who want a quick, honest read on where their AWS account stands.
Teams starting SOC 2 prep who want to catch the AWS-side gaps before an auditor does.
Anyone who inherited an AWS account from someone else and isn't fully sure what's actually configured.
Here's a preview of what the checklist covers. The full version includes exact steps and what to look for in each category.
Confirm MFA is enforced on root and on every privileged user, and check whether root is being used when it shouldn't be.
Find unused credentials, overly broad wildcard permissions, and access nobody remembers granting.
Verify logging is enabled in every region and account you actually use, not just the one you check most often.
Check every bucket for unintended public access and confirm encryption is on at rest and in transit.
Confirm backups are automated and that at least one restore has actually been tested.
The full checklist covers all 10 points with exact steps for each one.
If you already know your AWS account needs a real look, a fifteen-minute call will tell you if the sprint is the right next step.