NextGen Global IT ParkNextGen Global IT Park
← All services

Fixed price · Fixed scope

AWS Cost & Security Audit

We read your whole AWS account the way an auditor would, then hand you a written report that ranks every finding by risk and by the money it costs you each month. You get the fix list whether or not you hire us to apply it.

Starts
Within a week
Scope
Fixed, in writing
Rollback plan
On every change

Built from the same checklist we used to close every compliance finding on a US healthcare platform during its SOC 2 certification.

This is for you if

  • You inherited an AWS account and nobody is sure what is running in it
  • Your bill grew faster than your traffic
  • A customer or investor has started asking security questions
  • You are about to start SOC 2 and want to know the size of the problem

What we do

What the $2,000 covers

Identity and access

Every IAM user, role and policy reviewed for least privilege. Long-lived access keys, unused credentials, over-broad wildcards and missing MFA are listed individually.

Network exposure

Security groups, network ACLs, public subnets and load balancers checked for anything reachable from the internet that should not be — including databases, admin ports and S3 buckets.

Data and backups

RDS and S3 encryption, backup retention, snapshot age and restore testing. We say plainly whether you could actually recover, not just whether backups exist.

Monitoring and alerting

CloudWatch alarms, log retention and what currently pages a human at 3am. Gaps where a failure would go unnoticed are called out.

Cost

Idle instances, oversized databases, orphaned volumes and snapshots, unattached IPs, and savings-plan opportunities — each with the monthly dollar figure attached.

What you get

  • Written report (PDF), typically 15–25 pages, one page per theme
  • Prioritised fix list: every finding scored by risk and by monthly cost
  • Quick-wins section: what your own team can fix in an afternoon
  • A 60-minute walkthrough call with the engineer who did the audit
  • Terraform or CLI snippets for the fixes that are safe to automate

Not included

  • Applying the fixes (quoted separately once you have the list)
  • Penetration testing or application code review
  • Multi-account AWS Organizations landing zones

Anything outside this list is quoted before we start it, never invoiced afterwards.

Timeline

How it runs, start to finish

  1. Day 0 — access

    You create a read-only IAM role for us. We never need write access for an audit, and the role is yours to delete the day we finish.

  2. Days 1–3 — review

    We work through the account service by service, against our own checklist built from real SOC 2 remediation work.

  3. Day 4 — report

    Findings are written up and scored. No raw tool output dumped on you — every finding is in plain language with the fix next to it.

  4. Day 5 — walkthrough

    We present the report, answer questions, and agree what matters most. You leave the call with a plan your team can execute alone if you want to.

Questions we always get

Do you need production access?

Read-only, and only to AWS. We do not need database contents, customer data or your application source code to run the audit.

What if you find almost nothing?

Then you have a written, dated statement that your account is in good shape — which is exactly what the security questionnaire in your next enterprise deal is going to ask for.

Can you fix what you find?

Yes. Most clients take the fix list and ask us to quote the top items. Those are priced separately so the audit stays honest.

Start your AWS Audit

Book a 20-minute call. Bring your AWS account, your compliance dashboard or your database version, and we will tell you what we would do and what it costs — on the call, not in a proposal two weeks later.

See the case studies behind this work →