Listing Thumbnail

    AWS Security Assessment by 22 Security

     Info
    Sold by: 22 Security 
    When everything is a priority, nothing is. This AWS security assessment ranks every finding by whether it sits on an attack path to your critical data, so you know what to fix first. Your accounts are mapped as a graph, each instance's vulnerabilities are analyzed as chains, and custom checks written from the root causes of real breaches run alongside the CIS AWS Foundations Benchmark.

    Overview

    When everything is a priority, nothing is. I review your AWS accounts for misconfigurations and vulnerabilities, then rank what I find by whether it leads to the systems and data that matter most, so you know what to fix first.

    I'm John Patota: CISSP, CISM, CISA, CCSP, and 8x AWS Certified.

    How it works

    Your accounts are mapped as a graph on Amazon Neptune, and the analysis runs on it:

    • Attack paths: routes from the internet to your critical assets, such as an open security group, the instance behind it, and a role that can read your customer data.
    • Vulnerability chains: if you run Amazon Inspector, each instance's CVEs are analyzed together, checked against CISA's KEV catalog, and scored with EPSS.
    • Checks from real breaches: checks AWS Security Hub doesn't have, written from the root causes of breaches such as Capital One's in 2019.
    • Critical assets: AI on Amazon Bedrock flags data stores that look sensitive from their names, tags, and settings. Bedrock doesn't train models on your data.

    Every finding keeps the vendor's severity rating. Next to it is my priority: a critical finding with no path to anything important ranks below a medium one on the path to your customer data.

    Scope: IAM, network exposure, encryption, compute, storage, logging and detection, and edge protection, in the accounts and regions agreed at scoping. Measured against the CIS AWS Foundations Benchmark, the AWS Well-Architected Security Pillar, and NIST SP 800-53 Rev. 5. The report can serve as supporting evidence for SOC 2, HIPAA, ISO 27001, and NIST CSF 2.0.

    How it runs

    1. Scoping: we agree on the accounts and regions.
    2. Access: you deploy an AWS CloudFormation template that creates a cross-account IAM role with the AWS managed SecurityAudit policy. I use it to collect the configuration.
    3. Critical assets: a 30-minute call to confirm what matters most.
    4. Report and live readout.

    Timeline: two weeks.

    You get: an executive summary, a fix-first list, the attack paths step by step, findings with severity and priority side by side, benchmark results, and a remediation roadmap.

    Pricing: a fixed fee, quoted after the scoping call, based on the accounts, regions, and size of the environment. You pay any AWS infrastructure charges in your own accounts, such as Amazon Inspector, separately from this purchase.

    Support: before you buy, the scoping call. After you buy, email support plus the calls above.

    Full details: https://22security.com/aws-security-assessments/ 

    Highlights

    • Priority, not just severity: every finding keeps the vendor's severity rating and gets a priority based on your critical assets and whether it sits on an attack path to one of them. A critical finding with no path to anything important ranks below a medium one on the path to your customer data, and the report leads with the fixes that break the most paths.
    • Attack paths through a graph of your environment: every account in scope is loaded into a graph database on Amazon Neptune, and the analysis traces routes from the internet to your critical assets, such as an open security group, the instance behind it, and a role that can read your customer data. Misconfigurations alone can form a path; no vulnerability is needed.
    • Vulnerability chains and checks from real breaches: with Amazon Inspector, each instance's CVEs are analyzed together for an entry point plus a privilege escalation, checked against CISA's Known Exploited Vulnerabilities catalog, and scored with EPSS. Two mediums that chain are ranked by what they add up to. Plus checks AWS Security Hub doesn't have, written from the root causes of breaches such as Capital One's in 2019.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support

    • Email: hello@22security.com 
    • Book a scoping call: 22security.com/go/calendly
    • Service details: 22security.com/aws-security-assessments

    Before you buy: a 30-minute scoping call to agree on the AWS accounts and regions in scope and quote the fixed fee.

    After you buy: email support with John Patota, plus two scheduled calls: a 30-minute call to confirm your critical assets and a live readout of the report. Send questions about using the service, deploying the CloudFormation template, or the findings to hello@22security.com . Replies come within two business days.

    Refunds: send requests to hello@22security.com . They are handled under the terms of your private offer.