AWS Serverless Audit
I go through your AWS infra top to bottom — security, costs, performance, compliance. You get a clear report and a concrete action plan.
36+
checkpoints
5-10
business days
4
deliverables
What I Audit
IAM & Network Security
IAM roles, MFA, policies, security groups, NACLs, public/private subnets, SSH, VPN.
FinOps
Lambda sizing, DynamoDB mode, S3 lifecycle, CloudWatch logs, Reserved Capacity.
Serverless Architecture
Lambda, API Gateway, DynamoDB, S3, CloudFront, SQS, EventBridge. Patterns and anti-patterns.
Observability
CloudTrail, GuardDuty, AWS Config, VPC Flow Logs, X-Ray, CloudWatch alarms.
Compliance
GDPR, ISO 27001, SOC2, AWS Well-Architected Framework. Scoring and gap analysis.
Secrets & IaC
Plaintext secrets, rotation, Secrets Manager, CloudFormation/Terraform review.
Deliverables
Complete Audit Report
Each finding categorized by severity (critical, high, medium, low) with framework references (ISO 27001, SOC2, GDPR, Well-Architected). Current architecture documented.
Technical Remediation Plan
Target architecture, CloudFormation/Terraform stacks, dependency graph and execution order. Not just recommendations — an executable plan.
Costed Estimation
Implementation cost per phase, impact on monthly AWS bill, and options (security only vs full modernization).
Leadership Briefing
Non-technical summary for CEO/CTO: risks in business language, legal/financial consequences, clear recommendation.
Process
Scoping
30 min — context, scope, access
Analysis
3-7 days — live audit + IaC review
Delivery
Report + plan + estimation
Presentation
Team call + leadership briefing
Pricing
Standard Audit
2 500 EUR
5 business days
- IAM & network security
- FinOps analysis
- Serverless architecture review
- Report + action plan
Full Audit
5 000 EUR
10 business days
- Everything in standard +
- Compliance (GDPR, ISO 27001, SOC2)
- Detailed technical remediation plan
- Costed estimation of work
- Non-technical leadership briefing
- Target architecture documented
Real Case
Health startup: 36 vulnerabilities, 9 critical, score 2/10
Database in public subnet, plaintext Stripe secrets, zero MFA, zero monitoring. The full audit revealed vulnerabilities that could have cost millions in GDPR fines.
Frequently Asked Questions
How much does an AWS audit cost?+
What does the AWS audit deliverable include?+
How long does an AWS audit take?+
Worried about your AWS infrastructure?
Free 30-minute call. Let's see together if an audit makes sense for you.
Schedule a call