We're a 6-person team based in Austin building logistics software. Last month we migrated our entire database and server infrastructure from on-prem servers to AWS. The migration is done, but we have zero peace of mind on the security side. We can't really tell if we left open ports exposed to the internet, left storage buckets public, or granted way too many IAM permissions.
Since we're about to sign contracts with enterprise clients in the US market, we asked an independent cybersecurity firm for an audit quote. They asked for $6,000 for a one-time general infrastructure audit. Since we already spent a ton during the migration, that figure is way beyond our budget right now.
Before hiring an expensive outside auditor, is there a reliable cloud security audit tool or method where we can scan our cloud environment thoroughly on our own and get a list of critical misconfigurations and leak risks? Where should we start?