Financial institution · Multi-account AWS estate
A financial institution had moved most of its applications to AWS and bought a strong set of security tools along the way — Wiz, Security Hub, GuardDuty, Inspector, Macie, Arctic Wolf, and others. On paper the program looked well funded. In practice, the team could not say with confidence how well any given account was protected. Ask two people and you would often get two different answers.
This was costing real time and goodwill. When clients and partners sent security questionnaires, answering them took weeks, because no one could give a clear, consistent picture of how the accounts were secured. A few deals slowed in procurement while evidence was pulled together, and audits kept raising the same issues quarter after quarter — which made every renewal harder than it should have been.
The reason behind all of it was simple: the program reacted to problems instead of preventing them. Coverage varied from account to account, new environments went live without an agreed set of baseline controls, and no single team owned the path from alert to fix. Leadership did not need another tool. They needed a clear view of what they already had, what was missing, and what a healthy program should look like.
We ran a full-scope AWS security assessment across prevention, detection, response, and governance — going to the root of why findings kept recurring rather than just cataloguing them, and mapping controls to CIS, NIST, and CSA CCM.
From there we designed a required security-service baseline every account had to meet before hosting production, implemented preventive guardrails through Control Tower and Service Control Policies, standardized logging into the enterprise SIEM, and redrew detection-to-response with named owners and clear SLAs — delivered as a 30/90/365-day maturity roadmap.
1. Moved from tool-based coverage to a structured operating model with clear ownership across prevention, detection, response, and governance
2. Cut new-account time-to-production-ready from ~3 weeks to days
3. Mapped 100+ controls across CIS, NIST, and CSA CCM — an audit-ready evidence base
4. Reduced recurring critical findings by an estimated 40–55% via preventive guardrails
5. Estimated annual risk avoidance of $500K–$1M
Tooling spend isn't security maturity. The fastest commercial wins came from defining a baseline and making prevention the default — which is also what shortened the sales and audit conversations the business cared about most.