| Workstream | Driver from discovery | Outcome |
|---|---|---|
| Landing zone & account separation | Workloads in mgmt acct; flat org; empty Lazka | Move workloads to a dedicated account; OUs + SCP guardrails |
| Delegated security account | No delegated admin; unaddressed GD findings; Lazka dark | Central GuardDuty/Security Hub admin; org-wide monitoring |
| Cost optimization | EC2 = 67% of spend; 4× growth; unattached EBS | Rightsizing + Savings Plans + cleanup → recurring savings |
| Identity hardening | Stale admin keys; 2 users w/o MFA | Rotate/retire keys, enforce MFA, move to short-lived roles/SSO |
| Exposure reduction | 13 internet-open SGs | Least-privilege ingress; WAF already in place to leverage |
| Landing zone & account separation | Workloads in mgmt acct; flat org, no OUs; empty Lazka; SCP region-deny absent | Dedicated workload account; OUs + SCP guardrails (region deny, root protection) |
| Delegated security account | Zero delegated admins — GuardDuty, Security Hub and Config all flagged high; 4 open GD high/critical findings; Lazka dark | Central security account admins all three org-wide; findings get a named owner and triage SLA |
| Backup & resilience | 0 of 9 EBS volumes have snapshots or a backup plan (18 high/medium failures) | AWS Backup plans, tested restores, RPO/RTO defined — today a volume loss is unrecoverable |
| Identity hardening | Admin keys 322 & 319 days; 5 keys >90d; 6 users on static creds; 9 users + root without hardware MFA; AdministratorAccess attached (*:*) | IAM Identity Center + short-lived roles; retire static keys, scope admin, hardware MFA on root |
| Exposure reduction | 13 internet-open SGs; 3 permissive NACLs; 7 public-IP instances; 6 internet-facing instances carrying instance profiles; IMDSv2 not enforced account-wide | Least-privilege ingress, IMDSv2 enforced, ALB/WAF fronting — closes the credential-theft path |
| Secrets & key management | 19 secrets with no rotation and no restrictive resource policy; 2 KMS keys without auto-rotation; 19 log groups unencrypted; secrets detected in 7 log groups | Rotation on every secret, KMS/CMK coverage for logs and SNS, resource policies scoped to consumers |
| Cost optimization | $858/mo, +284% Jan→Jul; EC2 = 67% of spend; 2 unattached EBS + 7 EIPs; orphaned EKS roles from a torn-down cluster | Rightsizing + Savings Plans + Graviton/spot + cleanup → recurring savings and a growth-safe baseline |
| Compliance acceleration | Prowler: 363 failures (2 critical, 111 high); SOC 2 81%, ISO 27001 77%, CIS 3.0 74%; Secureframe + Intruder already engaged | Close the SOC 2 gap on evidence they already collect; Security Hub as the standing control monitor |
The first three are the fastest to land and the hardest to defend leaving open — no delegated security owner, no backups, and workloads in the management account are each a single-event risk. Cost optimization is the lever that funds the rest.