All case studies
Retail & E-commerce
Cloud Security Configuration Review
AWS configuration review cuts a retailer's internet-exposed attack surface by 60%
A structured review of identity, network and data controls across three AWS accounts identified over-permissive roles and forgotten public resources left behind by seasonal campaigns.
- Client
- Omnichannel retailer running 3 AWS accounts and 40 services
- Duration
- 10 days
- Headline issue
- Privilege escalation from a build role to full account administrator
- Sector
- Retail & E-commerce
The challenge
Rapid seasonal launches left orphaned infrastructure and broad IAM roles, with no consistent guardrails between production and marketing accounts.
Our approach
- Enumerated identity paths to privileged actions rather than listing policy findings in isolation.
- Correlated network exposure with data sensitivity to rank remediation by real risk.
- Delivered infrastructure-as-code snippets for each recommended guardrail.
Outcome
- Internet-exposed services reduced by 60%.
- Service control policies introduced to prevent public S3 and open security groups.
- Quarterly review cadence adopted as a managed service.
More case studies
Financial Services
Payments platform API penetration test uncovers account takeover chain
A grey-box API assessment across 180 endpoints exposed a broken object-level authorisation chain that allowed full merchant account takeover without user interaction.
SaaS & Platforms
Multi-tenant isolation review for a B2B SaaS ahead of enterprise onboarding
Authenticated testing across four tenant personas confirmed strong perimeter controls but revealed cross-tenant data leakage through an export job and a background webhook worker.