
Your AWS organization, audited from the inside.
Hardened in six weeks.
Identity, network exposure, data protection, logging, detection, and governance, across every account and every region, mapped to the framework your auditors use. We find it in two weeks. We close it in six.
Two-week audit, $25,000. Six-week hardening, $35,000, with half the fee invoiced only when every critical finding is closed. One signature, no procurement cycle.
Audit it, or fix it too.
Both fixed price.
Fixed scope, fixed price, one signature.
Both start within two weeks of it.
The Audit
One AWS organization, read from the inside. We scan every account and every enabled region, verify every finding by hand, trace who can reach what, and map it all to the framework your auditors use.
- Every account and region scored against the CIS AWS Foundations Benchmark and AWS Foundational Security Best Practices
- Every finding verified by hand and ranked by exploitability and blast radius
- An identity and access review: who and what can reach production
- The findings mapped to SOC 2, HIPAA, PCI DSS, NIST 800-53, ISO 27001, or GxP
- A remediation roadmap you can run yourselves, or with us
Charles’s time: up to 40 hours over the two weeks, about 8 of them live with your team.
Read-only, start to finish. The audit role sees how your accounts are configured, not what they store, and you delete it the day we finish.
Ask about the AuditThe Hardening
The Audit in the first two weeks. Then weeks three through five close the findings as code in your repositories, with the engineers who own each account. Week six runs the same scan again and hands it over.
- Everything in the Audit
- Every critical finding fixed as code, through your pull requests and your pipeline
- Guardrails from the top: policies and account defaults every new account inherits
- Single sign-on for people, least privilege for workloads, and no long-lived keys
- Detection on in every account and region, routed to your on-call, with runbooks
- The week-six re-scan against week one, and a team that knows how to keep it there
Charles’s time: up to 110 hours over the six weeks, about 38 of them live with your team.
The guarantee. The second half of the fee is invoiced only when every critical finding in the audit is closed, verified by the week-six re-scan.
No standing access to production. Every change goes in as code, reviewed by the engineer who owns the account, through your pipeline.
Ask about the HardeningWeek by week
Because the work has a shape.
The same weeks, every time, which is why it is fixed price.
- Week 1Access and scan.The read-only role goes into every account on day one. Every account and every enabled region is scanned against the CIS and AWS benchmarks, the organization’s structure and policies are mapped, and the walkthroughs with your platform and identity leads happen here.
- Week 2Verify and plan.Every critical and high finding is verified by hand, false positives are removed, and each real one’s blast radius is traced. Then the compliance map, the remediation roadmap, and a readout with the sponsor: what is exposed, what an auditor will ask for, and what six weeks would close.
- Week 1Access and scan.The Audit’s first week: the read-only role in every account, the full scan, and the walkthroughs. No changes yet. This is the baseline everything is measured against.
- Week 2Verify and plan.The Audit’s second week: the verified findings register, agreed with your sponsor, and the roadmap the next four weeks follow, criticals first.
- Week 3Criticals and guardrails.Every critical finding fixed as code, highest risk first, proven in non-production before production. Service control policies and account defaults go in at the top of the organization, so what closed stays closed and every new account starts safe.
- Week 4Identity.People move to single sign-on, long-lived access keys are retired, over-broad roles are cut to what each workload actually uses, and the root and break-glass accounts are locked down and alarmed.
- Week 5Detection and response.GuardDuty, Security Hub, IAM Access Analyzer, and AWS Config on in every account and region, delegated to a security account and routed to your on-call. One organization trail into a log archive no application account can alter, and runbooks for what will page you.
- Week 6Re-scan and hand over.The same scan as week one, run the same way. You get the before and after, the runbooks, and a team that already knows how to keep the score where it is.
What you hold at the end.
Every deliverable is an artifact in your repositories or your inbox.
None of them is a promise in a deck.
- 01The scan.Every account and every enabled region scored against the CIS AWS Foundations Benchmark and AWS Foundational Security Best Practices, with the raw results exported.
- 02The findings register.Every finding verified by hand with the false positives removed, ranked by exploitability and blast radius, each with its evidence, the resources it touches, and its fix.
- 03The identity and access review.Who and what can reach production: human access, workload roles, cross-account trust, long-lived keys, privilege-escalation paths, and the root and break-glass accounts.
- 04The compliance map.The findings mapped to the controls of the framework your auditors use, with the AWS-side evidence each control will be asked for.
- 05The governance review.Account structure, service control policies, Control Tower, account provisioning, tagging, and logging and detection coverage across the organization.
- 06The remediation roadmap.Every fix sequenced by risk and effort, criticals first, each with an owner and an estimate. It is the Hardening’s plan customized to you, and it is what you run yourselves if you stop here.
- 07The sponsor readout.A short written document, presented in the closing meeting.
- 08Every critical finding closedas code in your repositories, each through a pull request reviewed by the engineer who owns the account.
- 09Guardrails at the topof the organization: service control policies and account defaults for public access and encryption, inherited by every new account.
- 10Identity rebuilton single sign-on for people and least-privilege roles for workloads, with long-lived keys retired and the root and break-glass accounts alarmed.
- 11Detection everywhere:GuardDuty, Security Hub, IAM Access Analyzer, and AWS Config in every account and region, delegated to a security account and routed to your on-call.
- 12An organization trailinto a log archive that no application account can alter or delete.
- 13Incident runbooksfor the findings most likely to page you, walked through once with the people who will be paged.
- 14The week-six re-scanagainst week one: same method, same scope. It is the document that decides the second invoice.
- 15The handover workshop,and its recording.
How much of Charles you get.
Fixed price does not mean unbounded.
The cap is in the statement of work, and so is what we need from you.
Over two weeks. About 8 of them are live with your team; the rest are the verification, the reviews, the roadmap, and the agents doing the scanning and cross-referencing under Charles’s supervision.
Over six weeks, roughly 18 hours a week. About 38 of them are live with your team: the change reviews, the pairing, the office hours, and the readouts.
By written change order, agreed before the hour is spent. Remote by default; an on-site day is priced separately.
- One AWS organization of up to 50 accounts, in every enabled region
- One compliance framework mapped, beside the CIS and AWS benchmarks
- Fixes in up to four infrastructure-as-code repositories, in the tool you already use: Terraform, CloudFormation, or the CDK
- The read-only audit role in every in-scope account within three business days of signature, from a CloudFormation StackSet we hand you. The clock starts when it exists.
- A platform or security lead available at least four hours a week
- The sponsor available for thirty minutes a week, and in the Hardening, change approvals within two business days through your normal process
The rooms Charles leads.
Every meeting is on the calendar before week one.
Nothing else is asked of your engineers except the reviews and the pairing.
- Kickoff60 minutes
Sponsor, platform and security leads. Scope, the framework, access, rules of engagement, and what happens in the two weeks.
- Architecture walkthrough90 minutes, platform team
The accounts, the network, and how a change reaches production, told by the people who run them.
- Identity interview60 minutes
With whoever owns identity: how people and workloads get access, and how it is taken away.
- Office hours30 minutes, twice a week
Drop-in while the scans run and the findings are verified.
- Findings review90 minutes, end of week two
The critical and high findings with the platform team, each with its evidence and its fix.
- Sponsor readout60 minutes, end of week two
What is exposed, what an auditor will ask for, the roadmap, and what six weeks would close.
Weeks one and two are the Audit’s: the kickoff, the walkthrough, the identity interview, office hours, and the findings review. Then:
- Sponsor check-in30 minutes, weekly
Criticals open and closed, what went in this week, what is blocked.
- Change review60 minutes, twice a week, weeks three through five
Every fix read as code with the engineer who owns the account, before it merges.
- Pairing60 to 90 minutes, two or three times a week
With the engineer who owns the change: guardrails, identity, logging, and detection, proven in non-production first. This is where the teaching actually happens.
- Office hours45 minutes, twice a week
Drop-in, weeks three through six.
- Week sixabout 5 hours across the week
The re-scan review, a 2-hour handover workshop with the runbooks, and the closing sponsor readout.
The tools of the engagement.
Nothing exotic, and nothing you have to buy.
Everything the engagement produces is recorded, transcribed, and left with you.
The audit role
A read-only role in every account, from a CloudFormation StackSet we hand you before kickoff, carrying AWS’s SecurityAudit and ViewOnlyAccess policies and nothing else. It sees how your accounts are configured, not what they store. You delete it the day we finish.
AWS’s own security services
Security Hub’s benchmark standards, IAM Access Analyzer, GuardDuty, and AWS Config, read where they are already on and turned on everywhere in the Hardening. Open-source scanners run through the audit role cover the rest, so nothing is installed in your accounts during the Audit.
Your repositories and pipeline
Every fix is code in your infrastructure repositories, in the tool you already use, merged through your pull requests and applied by your pipeline. We never hold standing write access to production.
Zoom
Every session is held on Zoom and recorded with your permission, with Zoom’s transcripts and recaps delivered alongside each recording, so the people who were not in the room get the whole meeting.
Pavilion
Set up for your engagement in week one: the calendar, every recording with its transcript and summary, the findings register and roadmap your sponsor accepts, the decisions, and the action items, in one place you keep afterward.
Scheduling, approvals, change orders, and invoices go by email, so the commercial record of the engagement is in your inbox, not in a portal you lose access to.
Who this is for
- A CTO, CISO, VP of Engineering, or head of platform whose production runs on AWS
- A SOC 2, HIPAA, PCI DSS, or ISO 27001 audit coming, a customer security questionnaire to answer, or a board asking how exposed you are
- An AWS organization that grew faster than its guardrails: accounts added by hand, access keys nobody rotates, logs nobody reads
- Budget authority for a fixed-price engagement without a procurement cycle
Who it is not for
- Teams that need a penetration test of their application. We audit the AWS environment it runs in.
- Anyone who needs an attestation or a certificate. We prepare you for your auditor; we are not the auditor.
- Organizations that cannot grant a read-only role in their own accounts
The receipts
The same work, done for regulated companies in pharma, healthcare, and financial services.
Client names withheld per NDA.
Who does the work
Charles Sieg. AWS Certified Solutions Architect — Professional, DevOps Engineer — Professional, and Security — Specialty. Cloud architect and platform engineer for Fortune 1000 clients across healthcare, pharma, and financial services, including the nightly compliance inventory that scans one pharmaceutical company’s more than 100 AWS accounts before morning. Both engagements are delivered by Charles personally, inside your accounts, with your engineers.
Questions a CISO asks first
Will this make us SOC 2 compliant?
Nothing makes you compliant by itself, and we are not your auditor: SOC 2 reports are issued by licensed CPA firms, and PCI DSS assessments by Qualified Security Assessors. What you get is the AWS side of the evidence, mapped to the controls your auditor will test, and in the Hardening, the gaps closed before they look.
Is this a penetration test?
No. A penetration test attacks your application from the outside. This audit reads how your AWS organization is built from the inside: identity, network exposure, data protection, logging, detection, and governance. In the cloud, the damage usually starts with a misconfiguration or an over-broad permission, and that is what this finds.
What access do you need?
A read-only role in each account, from a CloudFormation StackSet we hand you before kickoff: AWS’s SecurityAudit and ViewOnlyAccess policies, nothing else. It can read how your accounts are configured, not what they store: it cannot open an object in a bucket, query a database, or read a secret’s value. You can read every line before you deploy it, and delete it the day we finish.
What leaves our accounts?
Configuration findings: resource identifiers, settings, and policies, never your data. They are kept in your engagement’s Pavilion workspace, exported to you at the close, and deleted from our systems within thirty days after it. Security findings are never cited, with or without your name.
Do you ever change production?
Not directly. In the Hardening, every fix is written as code and goes through your pull requests and your pipeline, reviewed by the engineer who owns the account. We never hold standing write access to production.
What counts as critical?
Each finding is rated by how exploitable it is and how far the damage would reach, starting from the benchmark’s own severity. The register, with its ratings, is agreed with your sponsor at the week-two readout, and that list of critical findings is the one the guarantee is measured on.
What if we decide not to fix something?
Then it is your call, recorded in writing as an accepted risk, and it counts as closed for the guarantee. A risk you have decided to carry is a decision, not a failure.
Which frameworks can you map to?
SOC 2, HIPAA, PCI DSS, NIST 800-53, ISO 27001, and GxP. One is included, beside the CIS and AWS benchmarks; a second is a change order.
How much of Charles’s time do we actually get?
Up to 40 hours in the Audit and up to 110 in the Hardening, with about 8 and 38 of those hours live with your team. The caps are written into the statement of work. Anything beyond them is a written change order at $450 per hour, agreed before the hour is spent.
We are not on AWS. Can you still help?
Not with this engagement: it is built on AWS’s own services and on fifteen years of AWS work. If you run on Azure or Google Cloud, email us and we will tell you plainly whether we are the right people.
Two more fixed-price engagements.
Same two shapes, same two prices.
Two weeks and $25,000 for the diagnostic, six weeks and $35,000 for the result.

Engineering Leverage
Your board asked what the company is getting from Claude Code, and the honest answer is faster autocomplete.
Read the engagement
AWS Cost Analysis & Optimization
The AWS bill grew faster than the business, and nobody can say who owns which line.
Read the engagementStart with an email.
Tell us how many accounts, which framework your auditors use, and what prompted the question. You will hear back from Charles within one business day, and the first call is thirty minutes.
AWS, Amazon Web Services, and the AWS service names are trademarks of Amazon.com, Inc. or its affiliates. SOC 2 is a registered trademark of the American Institute of Certified Public Accountants. PCI DSS is a trademark of the PCI Security Standards Council, LLC. ISO is a registered trademark of the International Organization for Standardization. CIS Benchmarks is a trademark of the Center for Internet Security, Inc. Zoom is a trademark of Zoom Video Communications, Inc. Vantalect is not affiliated with or endorsed by any of them.