AWS Architecture Review
Independent engineering evaluation of AWS workload resilience, IAM boundaries, network topology, Terraform IaC, and cost efficiency.
Why This Audit Exists
AWS environments frequently accumulate technical debt: over-privileged IAM roles granted full AdministratorAccess, unencrypted S3 buckets, unmonitored security groups with 0.0.0.0/0 ingress, and runaway cloud costs driven by idle compute or unmanaged NAT Gateways.
Our AWS Architecture Review provides a hands-on, 7–10 business day inspection by a senior cloud systems engineer. We assess your environment against the AWS Well-Architected Framework and produce actionable Terraform/CLI remediation code.
What Is Inspected (Scope)
1. IAM Least Privilege & Credentials Governance
Analysis of IAM users, roles, cross-account trusts, hardcoded static access keys, and the absence of MFA on privileged roles.
2. VPC Network Architecture & Perimeter Security
Inspection of subnets, Route Tables, Internet Gateways, NAT Gateways, Security Groups, and database isolation.
3. Data Protection & Encryption at Rest/Transit
Review of KMS key policies, S3 bucket public access blocks, RDS automated backup configurations, and snapshot encryption.
4. Cloud Cost Rationalisation & FinOps Analysis
Identification of orphaned EBS volumes, oversized EC2/RDS instances, inefficient transfer costs, and Savings Plan opportunities.
What Is Excluded
This audit conducts a non-destructive read-only assessment of up to 3 AWS accounts or 1 primary production environment. Extensive multi-tenant re-architecture or massive terraform migrations are scoped as subsequent engineering deliverables.
Deliverables Included:
- ✔ Executive Summary
- ✔ Cloud Topology & IAM Boundary Findings
- ✔ Resilience & Security Gap Analysis
- ✔ Cost & Architecture Optimisation Path
- ✔ 90-Day Action Plan
- ✔ 60-Minute Senior Engineer Debrief