- Job title
- Co-founder
- Sector
- Machinery manufacturing
- Organization type
- boutique agency
- Joined
- May 2022
- Message
- 155
We're a team of 6 based in London developing accounting middleware. Two months ago, we migrated all our on-prem databases and app servers to AWS infrastructure. We hired a freelancer for the migration and paid around 3,500 GBP to get it across the finish line; but once he wrapped up and left, no one went back to do a thorough review of account configurations and security permissions.
After seeing cloud data breach headlines online last week, everyone internally started to panic a bit. We don't have a full-time DevOps or cloud security engineer on the team. We can log into the console with our basic dev knowledge, but we can't really tell what kind of vulnerabilities might be lurking beneath the surface.
Before bringing in an expensive third-party audit, is there a step-by-step checklist we can run through ourselves on a small architecture like ours to patch the most critical holes? Where should we start?