How we execute a remediation
Turning an assessment that has sat unactioned into a bounded piece of completed work, executed alongside the team so the knowledge stays with them.
The situation
A security or architecture assessment sitting unactioned, sometimes for months. Rarely negligence — the team is committed to its own roadmap, the findings have no clear owner, and no single item is urgent enough on its own to displace planned work.
What we did
A fixed-scope engagement targeting the findings ranked highest for risk, executed alongside the existing team rather than separately from it, so the knowledge of what changed and why stays with the people who'll maintain it.
- Overly broad access narrowed to scoped, role-based permissions.
- Secrets moved out of application configuration and into a managed service with rotation.
- Logging extended and routed to a channel someone actually monitors.
- A backup restore tested end to end — often for the first time. Finding a gap during a scheduled test is a far better outcome than finding it during an incident.
Result
The highest-risk findings closed, verified rather than assumed fixed, and documented so the team can maintain the change without us.
- IAM
- Secrets Manager
- CloudTrail
- GuardDuty
- KMS
These describe our approach to each type of engagement, illustrated by the kind of situation and findings we see repeatedly. They are not attributed to a named client.