forumNew topic

We moved everything to AWS — is there a DIY security checklist we can run through?

MMustafa G***Member
Job title
Co-founder
Sector
Machinery manufacturing
Organization type
boutique agency
Joined
May 2022
Message
155
#1

We're a team of 6 based in London developing accounting middleware. Two months ago, we migrated all our on-prem databases and app servers to AWS infrastructure. We hired a freelancer for the migration and paid around 3,500 GBP to get it across the finish line; but once he wrapped up and left, no one went back to do a thorough review of account configurations and security permissions.

After seeing cloud data breach headlines online last week, everyone internally started to panic a bit. We don't have a full-time DevOps or cloud security engineer on the team. We can log into the console with our basic dev knowledge, but we can't really tell what kind of vulnerabilities might be lurking beneath the surface.

Before bringing in an expensive third-party audit, is there a step-by-step checklist we can run through ourselves on a small architecture like ours to patch the most critical holes? Where should we start?

FFatihExpert
Job title
Chief Technology Officer
Joined
Jun 2023
Message
204
Most Helpful#2

Short answer: For your initial self-audit, don't try to inspect the entire system; focus strictly on authentication, open ports, and storage permissions. The overwhelming majority of cloud breaches don't stem from sophisticated exploits, but from publicly exposed resources and unmanaged keys.

Knock out these four steps yourself within the first 24 hours: 1) Root account security: Delete all API access keys on the root account, make sure hardware or app-based multi-factor authentication (MFA) is enabled, and never use this account for daily operations. 2) IAM and access keys: Create individual accounts for every team member following the principle of least privilege, revoke the contractor's access, and deactivate any unused access keys older than 90 days. 3) Security groups and open ports: Scan your instance security groups; verify that SSH (22) or database ports (3306, 5432) are never exposed to the world (0.0.0.0/0), but restricted solely to your static office IP or VPN. 4) Storage buckets: Confirm that 'Block Public Access' is turned on globally across your S3 buckets.

Once you finish these manual checks, run AWS's built-in security hub and best-practice recommendation tools (including the checks available in the free tier). Work through the high-priority findings step by step, mapping them against the four-point filter I outlined above.

MMehmet A***Expert
Job title
Agency owner
Organization type
early-stage startup
Joined
Sep 2023
Message
187
#3

Three urgent things you need to do today: 1) Set up Billing Alerts; if there's an unauthorized cryptomining attempt, you'll know before your account racks up thousands of pounds in charges. 2) Verify that CloudTrail logging is enabled across all regions. 3) Confirm that automated database backups are turned on.

OOsman K***Member
Job title
Logistics planning
Sector
Energy
Organization type
a company within a holding
Joined
Sep 2025
Message
125
#4

Since you store customer financial data under UK data protection regulations (UK GDPR), legal liability rests directly on company directors. Even if you don't commission a full-scale external penetration test, I strongly recommend documenting these security checks with dates and screenshots.

GGamze D***Veteran
Job title
Courier coordinator
Sector
Food wholesale
Organization type
300-person organization
Joined
Jan 2024
Message
209
#5

When we audited after a similar migration last year, we found that the external contractor had left an admin-level API key sitting on their local machine. That key was exposed for 4 whole months. Luckily, nothing leaked, but ever since then, we audit IAM keys on the first Monday of every month.

HHakan S***ExpertCommunity member
Joined
Apr 2024
Message
36
#6

Head over to the IAM console and download the 'Credential Report'. That single file will show you in one table which users haven't enabled MFA, when each access key was last used, and how old passwords are. You'll catch your biggest blind spots within the first 10 minutes.

MMelekNew member
Job title
Daycare owner
Joined
Sep 2024
Message
40

Doki · Log management setup · 2026

#7

If we completely block public access on S3 will that affect customer invoice PDFs? They download documents through the app, so I wasnt sure if locking that down would throw errors for end users.

FFeyza K***Member
Job title
Intern
Sector
Catering
Organization type
workshop
Joined
Nov 2024
Message
2
#8

The general rule for S3 access is simple: files shouldn't be directly accessible to the public internet. When serving a file to a customer, your application generates temporary presigned URLs behind the scenes. That keeps your bucket completely closed to the outside world while giving the authenticated user a secure 5-minute download link.

AAycan K***Member
Job title
Store Manager
Sector
Catering
Organization type
20-person company
Joined
Mar 2024
Message
132
#9

Everyone talks about turning on security tools and logging, but no one mentions the cost. If you blindly enable security and monitoring services across all regions, you'll end up paying more for logs at the end of the month than for your actual production servers. Only enable them in the active regions you actually use.

SSimgeMember
Job title
Event organizer
Joined
May 2024
Message
88

Doki · Log management setup · 2025

#10

First thing you should do is check the Trusted Advisor dashboard. Even the free tier raises red flags for core security gaps, open ports and root account MFA status. Just clearing out the red alerts there will eliminate the vast majority of your risk.

EElif Y***Expert
Job title
Intern
Sector
Packaging
Organization type
120-person company
Joined
Feb 2023
Message
286
#11

Quick summary for newcomers: If you scold false alarms nobody will report again.

I'm also curious if anyone does it differently.

SSelin Y***Veteran
Job title
Front office accounting
Sector
Real estate
Organization type
120-person company
Joined
Sep 2024
Message
111
#12

Here's how it went for us. Everyone rushing into AWS security checklist gets stuck at the same point.

Don't rely on a single measure; go layer by layer. If you post the result here, it will help others too.

HHaticeMember
Job title
Family business
Organization type
boutique agency
Joined
Jun 2024
Message
86
#13

Sorry, but this doesn't apply in every case. Everyone rushing into AWS security checklist gets stuck at the same point.

Just leaving this note it might be useful.

MMetin U***Expert
Job title
Human Resources Specialist
Sector
Cosmetics
Organization type
regional distributor
Joined
Jun 2024
Message
20

Doki · Penetration test · 2023

#14

Thanks this was very helpful.

YYiğit K***MemberCommunity member
Joined
Mar 2024
Message
226
#15

I went through the same thing two years ago. Forgotten test environments are more often the entry point than live systems.

If you have questions, write them; I'll answer as best I can.

OOya E***Member
Job title
Human Resources Specialist
Sector
Insurance
Organization type
chain store
Joined
Mar 2024
Message
118
#16

Let me clarify the technical side. Don't rely on a single measure; go layer by layer.

OOrhan A***Member
Job title
QA Tester
Sector
Software
Organization type
40-person manufacturing company
Joined
Jan 2024
Message
2
#17

Good call starting this thread. The biggest time-waster for us was not knowing who had the final say.

Hasty decisions become decisions you have to fix six months later. This is my opinion I'm not claiming it's absolute truth.

KKadir S***Member
Job title
Secretary
Sector
Textile
Organization type
sole proprietorship
Joined
Oct 2023
Message
308
#18

Following.

DDilara Y***Veteran
Job title
Human Resources Manager
Sector
Real estate
Organization type
8-person team
Joined
Oct 2024
Message
98
#19

The opposite happened to me that's why I'm writing. honestly solutions that work at a small scale collapse when you grow; I learned this late.

That's all sorry if I went on too long.

YYavuz Ö***Expert
Job title
Graphic Designer
Sector
Cleaning services
Organization type
chain store
Joined
Jul 2023
Message
95
#20

The most overlooked point about AWS security checklist is this: Just because everyone does it doesn't mean it's right.

This is my opinion, I'm not claiming it's absolute truth.

Reply