Overview
CyberCX AWS Environment Review
The CyberCX AWS Environment Review delivers a structured, expert-led assessment of your AWS environment mapped against the AWS Well-Architected Framework Security Pillar and industry best practices. In one to four weeks, you receive a prioritized remediation roadmap and actionable findings report so you can strengthen security, improve reliability, optimize costs, and enhance operational excellence across your AWS workloads.
AWS Services and Tools Assessed
The review evaluates a broad range of AWS services and configurations, including:
- Identity and Access Management - IAM, IAM Identity Center (roles, permission sets, federation, privileged access, key age and rotation), and IAM Access Analyzer
- Governance - AWS Organizations, Service Control Policies, Control Tower, and landing zone configuration
- Networking - VPC segmentation, security groups, NACLs, ingress/egress paths, and endpoint policies
- Data Protection - KMS encryption at rest, S3 (public access, bucket policies, encryption, lifecycle), Secrets Manager, and Parameter Store
- Compute and Storage - EC2, EBS, RDS, and container platforms (ECS/EKS) where present
- Security and Monitoring - CloudTrail (coverage, integrity, retention), AWS Config, GuardDuty, Security Hub, WAF, Shield, and AWS Backup
- Logging and Alerting - End-to-end assessment of logging, monitoring, and alerting pipelines
Findings are recorded in the AWS Well-Architected Tool so they remain visible in your own AWS account after handover. Configuration analysis draws on AWS Security Hub (AWS Foundational Security Best Practices, CIS AWS Foundations Benchmark, and NIST 800-53 standards), AWS Config, IAM Access Analyzer, and Trusted Advisor, supplemented by CyberCX tooling. Findings are also mapped to ISM, NZISM, ISO 27001 Annex A, and ASD Essential Eight to support your existing assurance obligations.
Engagement Phases and Timeline
The review is delivered in one to four weeks across four phases:
- Kickoff and Scoping - Align on objectives, confirm environment scope, and provision secure access
- Automated Evidence Collection and Configuration Analysis - CyberCX tooling and AWS-native services analyze your environment against security benchmarks
- Discovery Workshops - Two facilitated sessions covering platform architecture and identity/governance respectively
- Findings Analysis and Reporting - Draft report, findings readout, and delivery of a prioritized remediation roadmap
Deliverables
- Environment Review Report - Detailed findings identifying issues, mitigations, and recommended enhancements with priority and severity ratings
- Prioritized Remediation Roadmap - Implementation approach for recommended changes, ordered by risk and impact
- AWS Well-Architected Tool Record - Findings captured in your AWS account for ongoing visibility
- Findings Readout Session - Walkthrough of results with your team
Scope and Prerequisites
A standard engagement covers a single AWS Organization of up to 10 member accounts and up to 100 production workloads. Additional accounts or workloads can be included via a scoped extension.
Explicitly out of scope: penetration testing and red teaming, remediation implementation, application source code review, non-AWS cloud platforms and on-premises infrastructure, ongoing monitoring or managed detection, and issuance of any compliance certification or attestation.
CyberCX can assist with implementing identified changes and provide ongoing support and managed services as a separate engagement.
Secure Engagement Delivery
Access to your environment is provisioned using a CloudFormation template supplied by CyberCX, creating a cross-account IAM role with an ExternalId assumable only by named CyberCX principals with MFA enforced. The role is read-only, scoped to the AWS-managed SecurityAudit and ViewOnlyAccess policies, with no data-plane read permissions to customer object storage or database contents. All CyberCX activity is visible in your own CloudTrail.
Access is time-bound to the engagement window and revoked by deleting the CloudFormation stack at completion. CyberCX confirms revocation in writing. Collected configuration evidence is retained under CyberCX's standard retention schedule and is available for deletion on request.
Getting Started
Request a scoping consultation to define your engagement and get started with the CyberCX AWS Environment Review.
Highlights
- Structured against the AWS Well-Architected Framework Security Pillar and recorded in the AWS Well-Architected Tool, so findings remain in your own account after handover. Configuration analysis draws on Security Hub (AWS Foundational Security Best Practices, CIS AWS Foundations Benchmark, NIST 800-53), AWS Config, IAM Access Analyzer, and Trusted Advisor. Findings are mapped to ISM, NZISM, ISO 27001 Annex A, and ASD Essential Eight to support your existing assurance obligations.
- Delivered in one to four weeks across four phases: kickoff and scoping, automated evidence collection and configuration analysis, two facilitated discovery workshops covering platform architecture and identity and governance, and a findings readout with a prioritised remediation roadmap. A standard engagement covers a single AWS Organization of up to 10 member accounts and up to 100 production workloads, with scoped extensions available for larger environments.
- Access is provisioned via a CyberCX-supplied CloudFormation template creating a read-only cross-account IAM role scoped to SecurityAudit and ViewOnlyAccess policies - no data-plane access to object storage or database contents. All CyberCX activity is visible in your CloudTrail. Access is time-bound to the engagement window and revoked by deleting the CloudFormation stack at completion, with written confirmation from CyberCX.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Resources
Vendor resources
Support
Vendor support
CyberCX provides 24/7 support from our team of skilled consultants. Contact us through the following channels:
Phone (New Zealand): +64 800 467 046 Phone (Australia): +61 1800 531 942 Email: aws-sales@cybercx.com Web: https://cybercx.co.nz/about-cybercx/aws/
Engagement Overview
The AWS Environment Review is delivered in two to four weeks across four phases:
- Kickoff and scoping - Align on objectives, confirm environment scope (standard engagement covers a single AWS Organization of up to 10 accounts and up to 100 production workloads), and provision read-only access via a CyberCX-supplied CloudFormation template.
- Automated evidence collection and configuration analysis - CyberCX analyses your environment using Security Hub, AWS Config, IAM Access Analyzer, Trusted Advisor, and CyberCX tooling.
- Facilitated discovery workshops - Two workshops covering platform architecture and identity/governance respectively.
- Findings analysis and delivery - Draft report, findings readout, and a prioritised remediation roadmap mapped to ISM, NZISM, ISO 27001 Annex A, and ASD Essential Eight.
Access and Security
Access uses a cross-account IAM role with ExternalId, assumable only by named CyberCX principals with MFA enforced. The role is read-only (SecurityAudit and ViewOnlyAccess policies) with no data-plane permissions. All activity is visible in your CloudTrail. Access is time-bound and revoked by deleting the CloudFormation stack at completion.
Out of Scope
Penetration testing, remediation implementation, application source code review, non-AWS platforms, ongoing monitoring, and compliance certification issuance. Additional accounts or workloads can be included via a scoped extension.