An air traffic control tower at blue hour, its glass cab glowing amber above rows of blue taxiway lights.
AWS security, compliance & governance · Fixed price

Your AWS organization, audited from the inside.
Hardened in six weeks.

Identity, network exposure, data protection, logging, detection, and governance, across every account and every region, mapped to the framework your auditors use. We find it in two weeks. We close it in six.

Two-week audit, $25,000. Six-week hardening, $35,000, with half the fee invoiced only when every critical finding is closed. One signature, no procurement cycle.

2
Weeks to a verified findings register
6
Weeks to every critical finding closed
50
Accounts in scope, every region
0
Changes made outside your pull requests

Audit it, or fix it too.
Both fixed price.

Fixed scope, fixed price, one signature.
Both start within two weeks of it.

Two weeks

The Audit

$25,000

One AWS organization, read from the inside. We scan every account and every enabled region, verify every finding by hand, trace who can reach what, and map it all to the framework your auditors use.

  • Every account and region scored against the CIS AWS Foundations Benchmark and AWS Foundational Security Best Practices
  • Every finding verified by hand and ranked by exploitability and blast radius
  • An identity and access review: who and what can reach production
  • The findings mapped to SOC 2, HIPAA, PCI DSS, NIST 800-53, ISO 27001, or GxP
  • A remediation roadmap you can run yourselves, or with us

Charles’s time: up to 40 hours over the two weeks, about 8 of them live with your team.

Read-only, start to finish. The audit role sees how your accounts are configured, not what they store, and you delete it the day we finish.

Ask about the Audit
Guaranteed
Six weeks

The Hardening

$35,000

The Audit in the first two weeks. Then weeks three through five close the findings as code in your repositories, with the engineers who own each account. Week six runs the same scan again and hands it over.

  • Everything in the Audit
  • Every critical finding fixed as code, through your pull requests and your pipeline
  • Guardrails from the top: policies and account defaults every new account inherits
  • Single sign-on for people, least privilege for workloads, and no long-lived keys
  • Detection on in every account and region, routed to your on-call, with runbooks
  • The week-six re-scan against week one, and a team that knows how to keep it there

Charles’s time: up to 110 hours over the six weeks, about 38 of them live with your team.

The guarantee. The second half of the fee is invoiced only when every critical finding in the audit is closed, verified by the week-six re-scan.

No standing access to production. Every change goes in as code, reviewed by the engineer who owns the account, through your pipeline.

Ask about the Hardening

Week by week

Because the work has a shape.
The same weeks, every time, which is why it is fixed price.

The Audit · two weeks · $25,000
  1. Week 1
    Access and scan.The read-only role goes into every account on day one. Every account and every enabled region is scanned against the CIS and AWS benchmarks, the organization’s structure and policies are mapped, and the walkthroughs with your platform and identity leads happen here.
  2. Week 2
    Verify and plan.Every critical and high finding is verified by hand, false positives are removed, and each real one’s blast radius is traced. Then the compliance map, the remediation roadmap, and a readout with the sponsor: what is exposed, what an auditor will ask for, and what six weeks would close.
The Hardening · six weeks · $35,000
  1. Week 1
    Access and scan.The Audit’s first week: the read-only role in every account, the full scan, and the walkthroughs. No changes yet. This is the baseline everything is measured against.
  2. Week 2
    Verify and plan.The Audit’s second week: the verified findings register, agreed with your sponsor, and the roadmap the next four weeks follow, criticals first.
  3. Week 3
    Criticals and guardrails.Every critical finding fixed as code, highest risk first, proven in non-production before production. Service control policies and account defaults go in at the top of the organization, so what closed stays closed and every new account starts safe.
  4. Week 4
    Identity.People move to single sign-on, long-lived access keys are retired, over-broad roles are cut to what each workload actually uses, and the root and break-glass accounts are locked down and alarmed.
  5. Week 5
    Detection and response.GuardDuty, Security Hub, IAM Access Analyzer, and AWS Config on in every account and region, delegated to a security account and routed to your on-call. One organization trail into a log archive no application account can alter, and runbooks for what will page you.
  6. Week 6
    Re-scan and hand over.The same scan as week one, run the same way. You get the before and after, the runbooks, and a team that already knows how to keep the score where it is.

What you hold at the end.

Every deliverable is an artifact in your repositories or your inbox.
None of them is a promise in a deck.

The Audit · seven deliverables
  1. 01
    The scan.Every account and every enabled region scored against the CIS AWS Foundations Benchmark and AWS Foundational Security Best Practices, with the raw results exported.
  2. 02
    The findings register.Every finding verified by hand with the false positives removed, ranked by exploitability and blast radius, each with its evidence, the resources it touches, and its fix.
  3. 03
    The identity and access review.Who and what can reach production: human access, workload roles, cross-account trust, long-lived keys, privilege-escalation paths, and the root and break-glass accounts.
  4. 04
    The compliance map.The findings mapped to the controls of the framework your auditors use, with the AWS-side evidence each control will be asked for.
  5. 05
    The governance review.Account structure, service control policies, Control Tower, account provisioning, tagging, and logging and detection coverage across the organization.
  6. 06
    The remediation roadmap.Every fix sequenced by risk and effort, criticals first, each with an owner and an estimate. It is the Hardening’s plan customized to you, and it is what you run yourselves if you stop here.
  7. 07
    The sponsor readout.A short written document, presented in the closing meeting.
The Hardening · everything in the Audit, then eight more
  1. 08
    Every critical finding closedas code in your repositories, each through a pull request reviewed by the engineer who owns the account.
  2. 09
    Guardrails at the topof the organization: service control policies and account defaults for public access and encryption, inherited by every new account.
  3. 10
    Identity rebuilton single sign-on for people and least-privilege roles for workloads, with long-lived keys retired and the root and break-glass accounts alarmed.
  4. 11
    Detection everywhere:GuardDuty, Security Hub, IAM Access Analyzer, and AWS Config in every account and region, delegated to a security account and routed to your on-call.
  5. 12
    An organization trailinto a log archive that no application account can alter or delete.
  6. 13
    Incident runbooksfor the findings most likely to page you, walked through once with the people who will be paged.
  7. 14
    The week-six re-scanagainst week one: same method, same scope. It is the document that decides the second invoice.
  8. 15
    The handover workshop,and its recording.

How much of Charles you get.

Fixed price does not mean unbounded.
The cap is in the statement of work, and so is what we need from you.

The Audit
Up to 40 hours

Over two weeks. About 8 of them are live with your team; the rest are the verification, the reviews, the roadmap, and the agents doing the scanning and cross-referencing under Charles’s supervision.

The Hardening
Up to 110 hours

Over six weeks, roughly 18 hours a week. About 38 of them are live with your team: the change reviews, the pairing, the office hours, and the readouts.

Beyond the cap
$450 per hour

By written change order, agreed before the hour is spent. Remote by default; an on-site day is priced separately.

Scope
  • One AWS organization of up to 50 accounts, in every enabled region
  • One compliance framework mapped, beside the CIS and AWS benchmarks
  • Fixes in up to four infrastructure-as-code repositories, in the tool you already use: Terraform, CloudFormation, or the CDK
What we need from you
  • The read-only audit role in every in-scope account within three business days of signature, from a CloudFormation StackSet we hand you. The clock starts when it exists.
  • A platform or security lead available at least four hours a week
  • The sponsor available for thirty minutes a week, and in the Hardening, change approvals within two business days through your normal process

The rooms Charles leads.

Every meeting is on the calendar before week one.
Nothing else is asked of your engineers except the reviews and the pairing.

The Audit · about 8 live hours
  • Kickoff60 minutes

    Sponsor, platform and security leads. Scope, the framework, access, rules of engagement, and what happens in the two weeks.

  • Architecture walkthrough90 minutes, platform team

    The accounts, the network, and how a change reaches production, told by the people who run them.

  • Identity interview60 minutes

    With whoever owns identity: how people and workloads get access, and how it is taken away.

  • Office hours30 minutes, twice a week

    Drop-in while the scans run and the findings are verified.

  • Findings review90 minutes, end of week two

    The critical and high findings with the platform team, each with its evidence and its fix.

  • Sponsor readout60 minutes, end of week two

    What is exposed, what an auditor will ask for, the roadmap, and what six weeks would close.

The Hardening · about 38 live hours

Weeks one and two are the Audit’s: the kickoff, the walkthrough, the identity interview, office hours, and the findings review. Then:

  • Sponsor check-in30 minutes, weekly

    Criticals open and closed, what went in this week, what is blocked.

  • Change review60 minutes, twice a week, weeks three through five

    Every fix read as code with the engineer who owns the account, before it merges.

  • Pairing60 to 90 minutes, two or three times a week

    With the engineer who owns the change: guardrails, identity, logging, and detection, proven in non-production first. This is where the teaching actually happens.

  • Office hours45 minutes, twice a week

    Drop-in, weeks three through six.

  • Week sixabout 5 hours across the week

    The re-scan review, a 2-hour handover workshop with the runbooks, and the closing sponsor readout.

The tools of the engagement.

Nothing exotic, and nothing you have to buy.
Everything the engagement produces is recorded, transcribed, and left with you.

The access

The audit role

A read-only role in every account, from a CloudFormation StackSet we hand you before kickoff, carrying AWS’s SecurityAudit and ViewOnlyAccess policies and nothing else. It sees how your accounts are configured, not what they store. You delete it the day we finish.

The instruments

AWS’s own security services

Security Hub’s benchmark standards, IAM Access Analyzer, GuardDuty, and AWS Config, read where they are already on and turned on everywhere in the Hardening. Open-source scanners run through the audit role cover the rest, so nothing is installed in your accounts during the Audit.

Where the fixes land

Your repositories and pipeline

Every fix is code in your infrastructure repositories, in the tool you already use, merged through your pull requests and applied by your pipeline. We never hold standing write access to production.

Meetings, recorded

Zoom

Every session is held on Zoom and recorded with your permission, with Zoom’s transcripts and recaps delivered alongside each recording, so the people who were not in the room get the whole meeting.

The workspace

Pavilion

Set up for your engagement in week one: the calendar, every recording with its transcript and summary, the findings register and roadmap your sponsor accepts, the decisions, and the action items, in one place you keep afterward.

The paper trail

Email

Scheduling, approvals, change orders, and invoices go by email, so the commercial record of the engagement is in your inbox, not in a portal you lose access to.

Who this is for

  • A CTO, CISO, VP of Engineering, or head of platform whose production runs on AWS
  • A SOC 2, HIPAA, PCI DSS, or ISO 27001 audit coming, a customer security questionnaire to answer, or a board asking how exposed you are
  • An AWS organization that grew faster than its guardrails: accounts added by hand, access keys nobody rotates, logs nobody reads
  • Budget authority for a fixed-price engagement without a procurement cycle

Who it is not for

  • Teams that need a penetration test of their application. We audit the AWS environment it runs in.
  • Anyone who needs an attestation or a certificate. We prepare you for your auditor; we are not the auditor.
  • Organizations that cannot grant a read-only role in their own accounts

Who does the work

Charles Sieg. AWS Certified Solutions Architect — Professional, DevOps Engineer — Professional, and Security — Specialty. Cloud architect and platform engineer for Fortune 1000 clients across healthcare, pharma, and financial services, including the nightly compliance inventory that scans one pharmaceutical company’s more than 100 AWS accounts before morning. Both engagements are delivered by Charles personally, inside your accounts, with your engineers.

Questions a CISO asks first

Will this make us SOC 2 compliant?

Nothing makes you compliant by itself, and we are not your auditor: SOC 2 reports are issued by licensed CPA firms, and PCI DSS assessments by Qualified Security Assessors. What you get is the AWS side of the evidence, mapped to the controls your auditor will test, and in the Hardening, the gaps closed before they look.

Is this a penetration test?

No. A penetration test attacks your application from the outside. This audit reads how your AWS organization is built from the inside: identity, network exposure, data protection, logging, detection, and governance. In the cloud, the damage usually starts with a misconfiguration or an over-broad permission, and that is what this finds.

What access do you need?

A read-only role in each account, from a CloudFormation StackSet we hand you before kickoff: AWS’s SecurityAudit and ViewOnlyAccess policies, nothing else. It can read how your accounts are configured, not what they store: it cannot open an object in a bucket, query a database, or read a secret’s value. You can read every line before you deploy it, and delete it the day we finish.

What leaves our accounts?

Configuration findings: resource identifiers, settings, and policies, never your data. They are kept in your engagement’s Pavilion workspace, exported to you at the close, and deleted from our systems within thirty days after it. Security findings are never cited, with or without your name.

Do you ever change production?

Not directly. In the Hardening, every fix is written as code and goes through your pull requests and your pipeline, reviewed by the engineer who owns the account. We never hold standing write access to production.

What counts as critical?

Each finding is rated by how exploitable it is and how far the damage would reach, starting from the benchmark’s own severity. The register, with its ratings, is agreed with your sponsor at the week-two readout, and that list of critical findings is the one the guarantee is measured on.

What if we decide not to fix something?

Then it is your call, recorded in writing as an accepted risk, and it counts as closed for the guarantee. A risk you have decided to carry is a decision, not a failure.

Which frameworks can you map to?

SOC 2, HIPAA, PCI DSS, NIST 800-53, ISO 27001, and GxP. One is included, beside the CIS and AWS benchmarks; a second is a change order.

How much of Charles’s time do we actually get?

Up to 40 hours in the Audit and up to 110 in the Hardening, with about 8 and 38 of those hours live with your team. The caps are written into the statement of work. Anything beyond them is a written change order at $450 per hour, agreed before the hour is spent.

We are not on AWS. Can you still help?

Not with this engagement: it is built on AWS’s own services and on fifteen years of AWS work. If you run on Azure or Google Cloud, email us and we will tell you plainly whether we are the right people.

Start with an email.

Tell us how many accounts, which framework your auditors use, and what prompted the question. You will hear back from Charles within one business day, and the first call is thirty minutes.

AWS, Amazon Web Services, and the AWS service names are trademarks of Amazon.com, Inc. or its affiliates. SOC 2 is a registered trademark of the American Institute of Certified Public Accountants. PCI DSS is a trademark of the PCI Security Standards Council, LLC. ISO is a registered trademark of the International Organization for Standardization. CIS Benchmarks is a trademark of the Center for Internet Security, Inc. Zoom is a trademark of Zoom Video Communications, Inc. Vantalect is not affiliated with or endorsed by any of them.