
Complimentary AWS Security Review
Understand your AWS security posture before small issues become larger risks
As digital platforms grow on AWS, it becomes increasingly important to ensure the cloud environment remains secure, well governed and architecturally sound.
Habitat3 offers a Complimentary AWS Security Review as part of our discovery and pre-sales process. The review gives our engineers an opportunity to understand your current AWS security posture, identify potential risks and provide practical recommendations for improvement.
There is no obligation to proceed with further work. The purpose of the review is to provide useful security insight and help your team make more informed decisions about your AWS environment.
Why request an AWS security review?
AWS environments rarely remain static.
New applications are deployed. Permissions change. Team members join and leave. Additional services and accounts are introduced. Security requirements become more demanding as the platform grows.
Over time, this can create issues such as:
-
excessive permissions
-
incomplete MFA adoption
-
publicly exposed resources
-
overly permissive security groups
-
inconsistent logging
-
gaps in threat detection
-
incomplete security-service coverage
-
configuration drift
-
limited compliance visibility
A security review provides a practical snapshot of the current environment and helps identify where attention should be focused first.
What the review covers
Habitat3 uses a combination of experienced AWS engineers and automated security tooling to assess the security posture of your AWS environment.
The review may examine areas including:
Identity and access management
We review identity and access controls for signs of unnecessary risk, including:
-
IAM users, roles and permissions
-
overly broad access
-
MFA usage
-
privileged access
-
root-account security
-
inactive or unnecessary credentials
Public exposure
We look for AWS resources that may be unintentionally accessible from the public internet, including:
-
compute resources
-
storage
-
databases
-
application endpoints
-
administrative interfaces
Network security
We assess areas such as:
-
security-group configuration
-
open ports
-
network access rules
-
VPC and subnet design
-
public and private resource placement
Logging and monitoring
We review whether the environment has appropriate visibility into security and operational activity, including:
-
AWS CloudTrail
-
AWS Config
-
Amazon CloudWatch
-
centralised logging
-
alerting coverage
-
account activity visibility
Detection and threat monitoring
We assess the use and coverage of AWS-native security services such as:
-
AWS Security Hub
-
Amazon GuardDuty
-
Amazon Inspector
-
IAM Access Analyzer
-
AWS Config
Compliance posture
Where relevant, we review how AWS Security Hub findings align with commonly used AWS security and compliance practices.
This is an initial assessment rather than a formal certification audit, but it can help highlight areas that may require further attention.
How the review is performed
The review combines AWS-native security findings with automated analysis and Habitat3 engineering expertise.
Depending on the environment, Habitat3 may use tools such as 6pillars Automate or AWS Service Screener to analyse AWS configuration against recognised security practices. These tools use information provided by AWS services, including AWS Security Hub, to help compile the findings.
Automated tooling provides useful coverage, but the value of the review comes from interpreting those findings in the context of your AWS architecture, applications and business requirements.
What you receive
Following the review, Habitat3 provides a clear summary of the findings.
This typically includes:
-
identified risks or misconfigurations
-
recommended remediation actions
-
priority areas for improvement
-
practical next steps
-
areas that are already operating effectively
-
issues that may require architectural or operational changes
We then schedule a short session to walk through the findings, explain their significance and answer questions.
The objective is not to overwhelm your team with a large list of alerts. It is to provide a practical view of what matters most and what should happen next.
Secure read-only access
Habitat3 does not make changes during the review
To complete the review, our engineers normally require read-only access to the relevant AWS environment.
This allows us to analyse configuration, security posture and relevant usage information without modifying your infrastructure.
Read-only access means Habitat3 cannot:
-
modify AWS resources
-
delete infrastructure
-
deploy new services
-
make configuration changes
-
alter applications or data
Access is limited to viewing the information required to complete the review safely and transparently.
How access is provided
Habitat3 works with your team step by step through the access process.
This is normally completed during a shared-screen session so you can see exactly what is being configured and approve the level of access being provided.
The setup process typically takes approximately 5–10 minutes, depending on the environment and access method. Once access has been confirmed, our engineers can begin the review.
What happens next
Once access is available:
1. We assess the AWS environment
Habitat3 engineers use AWS security information, automated assessment tools and expert review to examine the environment.
2. We compile the findings
The results are consolidated into a clear summary covering risks, priorities and recommended actions.
3. We review the results with you
We schedule a short session to walk through the findings and discuss the recommended next steps.
This conversation helps your team understand:
-
your current AWS security posture
-
the most important improvement opportunities
-
which risks should be prioritised
-
where an AWS Landing Zone may strengthen security
-
whether ongoing monitoring or Cloud Operations would be useful
From findings to a practical security roadmap
The Complimentary AWS Security Review is often the first step in a broader security improvement journey.
Depending on the findings, Habitat3 may recommend:
-
remediating individual security issues
-
improving IAM and MFA controls
-
enabling or extending AWS-native security services
-
redesigning network access
-
deploying a secure AWS Landing Zone
-
assessing an existing AWS Landing Zone
-
introducing AWS Control Tower and guardrails
-
improving backup and disaster recovery controls
-
preparing for an AWS Well-Architected Review
-
preparing for an AWS Foundational Technical Review
-
introducing ongoing Cloud Operations
There is no requirement to engage Habitat3 for any remediation work. The recommendations are provided so your team can make an informed decision about the best way forward.
AWS Landing Zones
Strengthen the foundation beneath your AWS workloads
Some security findings are symptoms of a broader architectural issue.
For example, inconsistent account structures, incomplete logging, weak identity controls and limited governance may indicate that the AWS foundation itself needs to be improved.
A secure AWS Landing Zone can introduce:
-
structured AWS account separation
-
centralised identity
-
MFA and least-privilege access
-
centralised logging
-
AWS Security Hub
-
Amazon GuardDuty
-
AWS Config
-
governance guardrails
-
backup controls
-
improved operational visibility
Learn more: AWS Landing Zone Deployments
Learn more: AWS Landing Zone Assessments
Ongoing visibility with Habitat3 CloudOps
A point-in-time review can identify current issues, but AWS security posture continues to change as the environment evolves.
Habitat3 CloudOps helps customers maintain ongoing visibility through monitoring, patch management, backup oversight, incident response, cost management and continuous improvement.
CloudOps customers can also gain access to the Habitat3 Security Command Centre, which provides a centralised view of AWS security findings, compliance posture, exceptions, audit history and reporting across connected AWS environments.
Learn more: Cloud Operations Service
Learn more: Habitat3 Security Command Centre
Who the review is for
The Complimentary AWS Security Review is particularly useful for:
-
SaaS providers
-
software and digital platforms
-
startups and scaleups
-
web and mobile application teams
-
organisations with production workloads on AWS
-
teams that have inherited an AWS environment
-
businesses preparing for enterprise customers
-
organisations that have not recently reviewed AWS security
-
teams without a dedicated internal AWS security specialist
-
organisations planning a Landing Zone or CloudOps engagement
Why Habitat3?
Habitat3 is an Australian AWS consulting partner specialising in AWS infrastructure, security, DevOps, compliance and Cloud Operations.
Our engineers work directly with technical teams to understand how the AWS environment supports the application and business—not simply whether individual controls pass or fail.
Our approach is:
-
practical
-
collaborative
-
read-only during the review
-
focused on material risk
-
grounded in AWS-native services
-
designed to produce clear next steps
Frequently asked questions
Will Habitat3 change anything in our AWS environment?
No. The Complimentary AWS Security Review is normally completed using read-only access.
Our engineers can view relevant configuration and security information, but they cannot modify or delete AWS resources.
How long does the review take?
Once access is provided, the review typically takes a few business days to complete.
The exact timeframe depends on the size, complexity and number of AWS accounts involved.
Is this a full security audit?
No. The review is a high-value initial security assessment, not a formal compliance audit, penetration test or certification process. It is designed to identify key risks and improvement opportunities and does not replace a formal audit where one is required.
Will we receive a report?
Yes. Habitat3 provides a summary of the findings and recommendations.
We then review the results with your team in a short session to explain the issues, priorities and possible next steps.
Are we obligated to proceed with further work?
No. There is no obligation to continue working with Habitat3 after the review.
The review is designed to provide practical insights regardless of whether you proceed with remediation, a Landing Zone or Cloud Operations engagement.
Why is read-only access required?
Read-only access allows Habitat3 to inspect relevant AWS configuration and security information without making changes. This gives our engineers enough visibility to assess the environment while maintaining a controlled and transparent process.
What happens if the review identifies security issues?
Habitat3 will explain the findings, prioritise the risks and provide recommended remediation actions. You can address the issues internally, engage Habitat3 to assist, or use the findings as part of a broader security-improvement project.
Can the review lead to an AWS Landing Zone project?
Yes. If the findings show that account structure, identity, logging, governance or security services need broader improvement, Habitat3 may recommend deploying or remediating an AWS Landing Zone.
Learn more: AWS Landing Zone Deployments
Can Habitat3 monitor our AWS security after the review?
Yes. if requested, Habitat3 CloudOps can provide ongoing operational and security visibility after the initial review. CloudOps customers may also gain access to the Habitat3 Security Command Centre.
Learn more: Cloud Operations Service
Related services
Build a secure and well-governed AWS foundation.
Identify security, governance and operational gaps in an existing Landing Zone.
AWS Well-Architected Framework Review
Assess workloads against AWS architectural best practices.
AWS Foundational Technical Review
Prepare an AWS-hosted product for AWS technical validation.
Monitor controls and compliance posture over time.
Habitat3 Security Command Centre
Centralise AWS security findings, exceptions, compliance visibility and reporting.
