Cloud SecurityCloud Security / Compliance
Security Hardening & SOC 2 Prep
A client heading into a SOC 2 audit had accumulated exposure across a multi-region estate. 3 Dices ran a full security assessment across 325 resources, remediated identity and network gaps, enabled continuous monitoring in every region, and mapped controls to SOC 2, passing the audit technical controls on the first attempt.
Passed audit technical controls on first attempt
325
Resources assessed
162
Issues identified
1st try
Passed technical controls
50+
Well-Architected checks
The challenge
A client heading into a SOC 2 audit had accumulated exposure across a multi-region estate: unencrypted volumes, open security groups, IAM users without MFA, and monitoring gaps in secondary regions.
- Unencrypted EBS volumes across the estate
- Unrestricted security groups exposing services
- IAM users without MFA
- Monitoring gaps in secondary regions
- Controls not yet mapped to SOC 2 requirements
Our solution
Assessment
- Multi-region security assessment across IAM, S3, EC2, RDS, VPC, and EBS
- 325 resources reviewed, 162 issues identified and prioritized
- Well-Architected review: 50+ best-practice checks, 539 Trusted Advisor items
Remediation
- Encrypted previously unencrypted EBS volumes
- Locked down unrestricted security groups
- Enforced MFA on IAM users and closed public S3 buckets
Continuous Monitoring & Compliance
- Enabled GuardDuty, AWS Config, and Inspector in secondary regions
- Consistent monitoring across all regions
- Mapped controls to SOC 2 requirements
The results
Audit
- Passed audit technical controls on the first attempt
- Controls mapped to SOC 2 requirements
Exposure
- 162 issues identified and prioritized across 325 resources
- Encryption, MFA, and network gaps closed
Monitoring
- Consistent monitoring across all regions
- GuardDuty, Config, and Inspector enabled everywhere
Technologies & AWS services
- IAM
- GuardDuty
- AWS Config
- Inspector
- Security Hub
- Well-Architected
More projects
Want Results Like These?
Tell us what you're building. We'll tell you honestly how we'd approach it.
