Silamir


AWS
security
audit _

Risk mapping by domain and 90-day remediation plan.
Client
Maison Verano · Demo
Audit date
22/09/2026
Reference
SIL-AUD-B41E07D5
Silamir Group
Cybersecurity & Cloud
Contents
Audit / Maison Verano · Demo
02 / 17
Table of contents

Six chapters to frame
the security posture.

01
Audit context
Scanned AWS scope and methodological approach.
p. 03 — 04
02
Overall verdict
Score, posture, findings distribution and top 5 risks.
p. 05 — 07
03
Results by domain
IAM, data, network, FinOps, resilience & observability.
p. 08 — 12
04
Remediation plan
90-day roadmap, quick wins, structural investments.
p. 13 — 15
05
Summary & commitments
Key messages, next steps, delivered documents.
p. 16
06
Contacts
Silamir contacts and review schedule.
p. 17
01 — Context
Audited scope
03 / 17
Audited scope

What we examined.

AWS footprint

1
AWS accounts
scanned read-only
2
Regions
active within scope
2,146
Resources
EC2 · S3 · IAM · RDS · Lambda · VPC
142
Findings
collected before correlation

Domains covered — 10

IAM & Identities
D01
Perimeter security
D02
Data
D03
Network & VPC
D04
Observability
D05
Secrets & KMS
D06
Compute
D07
Resilience
D08
FinOps
D09
Compliance
D10

Audit mode

Read-only
No modifications made to the client environment.
DAST ZAP Baseline enabled
External dynamic tests on the exposed surface.
01 — Context
Methodology
04 / 17
Approach

Four steps, two frameworks,
one AI-driven correlation.

01
Read-only
collection
Automated inventory of resources, configurations and logs across all accounts — without any mutation.
~ 12 min
02
Claude AI
analysis
Each finding is qualified, prioritized and contextualized by an audited model, with citations of the triggered rules.
142 findings
03
Action
plan
0-30-60-90 day roadmap with effort, gain and owner for each identified initiative.
34 actions
Frameworks
applied
AWS FSBP
Foundational Security Best Practices
CIS AWS 1.5
Center for Internet Security Benchmark
NIST CSF
Cybersecurity Framework — cross-cutting mapping
02 — Overall verdict
Score & posture
05 / 17
Overall verdict

A COMPLIANT posture,
held back by 2 critical findings.

Silamir global score
74/100
Posture · COMPLIANT
Critical At risk Compliant Mature

Findings distribution

P0
2
P1
21
P2
119
02 — Overall verdict
Heatmap by domain
06 / 17
Heatmap by domain

10 domains, 4 levels,
a snapshot of risk.

Domain Risk level Findings (P0 / P1 / P2) Score
D01 — Inventory
Mature
0  ·  0  ·  2
84
D02 — Security FSBP / CIS
Compliant
1  ·  2  ·  2
76
D03 — FinOps
Compliant
0  ·  3  ·  2
61
D04 — Well-Architected
Compliant
0  ·  1  ·  2
78
D05 — Resilience
Compliant
0  ·  2  ·  2
72
D06 — Network & VPC
Mature
0  ·  1  ·  1
81
D07 — Web security (DAST)
Compliant
1  ·  1  ·  1
68
D08 — IAM & Identities
Compliant
0  ·  2  ·  2
79
D09 — Containers & Serverless
Compliant
0  ·  2  ·  1
74
D10 — Secrets & KMS
Compliant
0  ·  1  ·  2
70
02 — Overall verdict
Top 5 major risks
07 / 17
Top 5 major risks · P0 / P1

Five breakpoints
to neutralize within 30 days.

01
P0 · CRITICAL
Reflected XSS on the checkout flow, with no WAF in front of CloudFront
Business impact: A crafted link can hijack customer sessions at checkout: fraud, chargebacks and PCI DSS exposure of the payment flow.
DomainWeb security
Linked findingsWEB-001
02
P0 · CRITICAL
Aurora snapshot of the customer database shared publicly
Business impact: Any AWS account can restore 310,000 customer records: a major GDPR breach in a single command.
DomainSecurity
Linked findingsSEC-007
03
P1 · HIGH
Oversized compute with no commitment: 31% of the bill avoidable
Business impact: Nearly €11,000 a month spent with no business return, the equivalent of a senior hire every year.
DomainFinOps
Linked findingsFIN-002
04
P1 · HIGH
24-hour RPO on the orders database, at odds with seasonal peaks
Business impact: An outage on Black Friday could lose up to a full day of orders, about €420k of revenue.
DomainResilience
Linked findingsRES-003
05
P1 · HIGH
Payment provider API keys in plain text in ECS task definitions
Business impact: Anyone reading the configuration can trigger refunds: direct fraud risk and PCI non-compliance.
DomainSecrets
Linked findingsKMS-002
03 — Results by domain · 1 / 5
Security & IAM
08 / 17
D01 · D02

Security & IAM

Governance of human and machine identities, IAM configurations, MFA, root policies and access keys.
79/100
Level · COMPLIANT

Key findings

P1
IAM user of an external CI agency with AdministratorAccess
P1 · arn:aws:iam::111122223333:user/ext-ci-agency
P1
3 application roles with permissions unused for 90 days
P1 · arn:aws:iam::111122223333:role/ecs-*
P2
2 active access keys older than 90 days
P2 · 2 IAM users
P2
IAM Access Analyzer not enabled in us-east-1
P2 · us-east-1
P2
No permission boundary on the developers group
P2 · developers group
Human identities on SSO
96%
24 of 25 users via IAM Identity Center
Over-privileged third parties
1
External CI agency with AdministratorAccess
MFA on console access
100%
Root protected by a FIDO2 key
Access keys > 90 days
2
Rotation can be automated
Priority action
Replace the CI agency's access with an OIDC role
GitHub Actions OIDC federation, deploy role scoped to ECS and S3, external IAM user removed.
Effort
2 d
Score gain
+4 pts
03 — Results by domain · 2 / 5
Data — S3, RDS, Backup
09 / 17
D03

Data

S3, RDS, EBS and backup strategies — exposure, encryption at rest and in transit, retention and restorability.
70/100
Level · COMPLIANT

Key findings

P1
Payment API keys in plain text in 4 ECS task definitions
P1 · arn:aws:ecs:eu-west-3:111122223333:task-definition/checkout
P1
Rotation disabled on the Aurora customer database CMK
P1 · alias/verano-customers
P2
No versioning on the product media bucket
P2 · arn:aws:s3:::verano-media-prod
P2
Log bucket without a lifecycle policy
P2 · arn:aws:s3:::verano-logs
P2
TLS 1.0 still accepted on an internal endpoint
P2 · ALB internal-erp-sync
Public S3 buckets
0 / 48
Block Public Access on at account level
Plain-text secrets found
6
ECS task definitions and Lambda variables
CMKs with rotation
7 / 9
2 keys rotated manually
Storage encrypted at rest
100%
S3, EBS, Aurora and DynamoDB
Priority action
Move payment secrets to Secrets Manager
Native ECS secrets, automatic 90-day rotation and revocation of exposed keys with the PSP.
Effort
2 d
Score gain
+6 pts
03 — Results by domain · 3 / 5
Network & external exposure
10 / 17
D04

Network & exposure

VPC, segmentation, security groups, public surface and external dynamic tests (DAST) on exposed endpoints.
81/100
Level · MATURE

Key findings

P0
Reflected XSS on /checkout/confirm found by the DAST scan
P0 · www.demo-verano.example/checkout
P1
No AWS WAF attached to the CloudFront distribution
P1 · CloudFront E2VERANODEMO
P2
Content-Security-Policy header missing on the storefront
P2 · www.demo-verano.example
P2
Flow Logs not enabled on the staging VPC
P2 · vpc-staging · eu-west-3
P2
Orphaned security group with RDP open to the Internet
P2 · sg-07be91d3 · no resource
Exposed public endpoints
6
All behind CloudFront or ALB over HTTPS
Security groups open 0.0.0.0/0
1
Orphaned group, no attached resource
DAST alerts (ZAP)
9
1 high (XSS), 2 medium, 6 low
VPCs with Flow Logs
2 / 3
Production covered, staging to complete
Priority action
Deploy AWS WAF and fix the checkout XSS flaw
AWS managed rules, rate limiting on checkout and parameter encoding in the application.
Effort
3 d
Score gain
+5 pts
03 — Results by domain · 4 / 5
FinOps
11 / 17
D09

FinOps

Monthly cost, savings opportunities activatable without impact on service quality or security.
61/100
Level · COMPLIANT

Identified opportunities

P1
18% Savings Plans coverage on a stable Fargate baseline
P1 · 82% of compute on demand
P1
Oversized Fargate tasks and Aurora instances (14% average CPU)
P1 · catalog, search, reco services
P1
Full staging environment running 24/7
P1 · ~€2,100/month outside business hours
P2
High cross-AZ transfer between ECS and ElastiCache
P2 · ~€640/month
P2
CloudWatch logs with unlimited retention (2.1 TB)
P2 · 27 log groups
Savings potential
10,900 €/month
31% of the bill, no customer impact
Savings Plans coverage
18%
Recommended target: 65% of stable compute
Tagged resources
88%
Allocation by brand and sales channel
Monthly AWS bill
35,600 €
3-month average excl. tax, 58% compute
Priority action
Right-size Fargate / Aurora and buy a 1-year Savings Plan
Sizing to measured usage, then commitment on 65% of the baseline: €7,400/month, no customer impact.
Effort
4 d
ROI
~7,400€/month saved
03 — Results by domain · 5 / 5
Resilience & Observability
12 / 17
D05 · D08

Resilience & Observability

RTO/RPO documented and tested, monitoring coverage, operational alerting and end-to-end incident chain.
72/100
Level · COMPLIANT

Key findings

P1
24-hour RPO on the orders database (daily snapshot only)
P1 · aurora:verano-orders
P1
No load or failover test before seasonal peaks
P1 · Black Friday plan
P2
Alarms not wired to on-call for 3 secondary services
P2 · search, reco, newsletter
P2
No cross-region copy of backups
P2 · AWS Backup eu-west-3
P2
No SLOs defined for the purchase journey
P2 · CloudWatch
Resources under AWS Backup
91%
64 of 70 eligible resources
Orders database RPO
24 h
Recommended target: 5 min (PITR)
Multi-AZ services
100%
Aurora, ECS and ElastiCache across 3 AZs
Last restore test
5 months
Target: quarterly and documented
Priority action
Enable Aurora PITR and run a game day
PITR on orders and customers, cross-region copy and a timed failover before the November peak.
Effort
4 d
Score gain
+6 pts
04 — Remediation plan
90-day roadmap
13 / 17
Remediation plan · 90 days

From P0 to P2,
a trajectory in three waves.

WAVE P0
D+0 → D+30

Neutralize
critical breakpoints

01
Fix the checkout XSS flaw and deploy AWS WAF
3 d
02
Remove public sharing of the customer Aurora snapshot
1 d
03
—
—
04
—
—
05
—
—
2 actions4 d
WAVE P1
D+30 → D+60

Harden domains
with structural risk

06
Move payment secrets to Secrets Manager
2 d
07
Least-privilege OIDC role for the CI agency
2 d
08
Right-size Fargate tasks and Aurora instances
3 d
09
1-year Compute Savings Plan on 65% of baseline
1 d
10
Enable Aurora PITR on orders and customers
1 d
15 actions26 d
WAVE P2
D+60 → D+90

Industrialize
and maintain the posture

11
Scheduled shutdown of staging outside business hours
2 d
12
CloudWatch log retention and S3 archiving
1 d
13
Content-Security-Policy on the storefront
2 d
14
Cross-region copy of backups
2 d
15
SLO dashboards for the purchase journey
4 d
17 actions28 d
04 — Remediation plan
Quick wins
14 / 17
Quick wins · 5 actions

High impact, low effort,
activatable within 14 days.

QW · 01
Remove public sharing of the Aurora snapshot
Ends the exposure of 310,000 customer records within minutes.
Effort
1 d
Gain
Security
QW · 02
Deploy AWS WAF in front of checkout
AWS managed rules and rate limiting while the code fix ships.
Effort
2 d
Gain
Security
QW · 03
Buy a 1-year Compute Savings Plan
Commitment on 65% of the stable Fargate baseline, no architecture change.
Effort
1 d
Gain
+4,300€/month
QW · 04
Enable Aurora PITR
RPO cut from 24 hours to 5 minutes on orders and customer databases.
Effort
1 d
Gain
Resilience
QW · 05
Stop staging outside business hours
Instance Scheduler on the staging environment, nights and weekends.
Effort
2 d
Gain
+1,400€/month
Total effort
7 d
Cumulative score gain
+5 to +8 pts
Annualized savings
68,400 €/year
Activation timeline
≤ 14 d
04 — Remediation plan
Structural investments
15 / 17
Structural investments · long-term initiatives

Four foundations
for a mature posture at 12 months.

Multi-account governance and SCP guardrails

Storefront, data and staging separated; SCPs blocking public sharing and unused regions.
Effort
10 d
Timeline
M2-M4
Owner
Cloud / Sec

Checkout AppSec programme

Authenticated DAST in CI, checkout code review, strict CSP and dependency scanning to shrink PCI scope.
Effort
8 d
Timeline
M1-M3
Owner
Security

Seasonal resilience and game days

5x load tests, timed cross-AZ failover, PITR and cross-region copy: ready for Black Friday.
Effort
6 d
Timeline
M1-M2
Owner
Platform

SLO-driven observability of the purchase journey

Availability and latency SLOs per step, error-budget alerts and unified on-call.
Effort
5 d
Timeline
M2-M3
Owner
SOC / Sec
05 — Summary & commitments
Key messages
16 / 17
Summary & commitments

Three messages,
three next steps.

Key messages

01
Compliant posture, to consolidate
Solid foundation (SSO, encryption, Multi-AZ); 2 critical findings limited to checkout and one public snapshot, fixed in 4 d.
02
FinOps pays for security
€10,900/month of savings identified; the FinOps quick wins alone return €68k/year, more than the whole roadmap costs.
03
Mature (80+) before Black Friday
PITR, WAF and a failover game day lift the score above 80 and secure the November peak, 22% of annual revenue.

Next steps

→
Validation & framing
Executive debrief, scope validation, ownership assignment.
→
Quick-wins sprint (W1-W2)
Public snapshot removed, WAF deployed, PITR enabled, Savings Plan purchased.
→
Roadmap M1-M4
Checkout AppSec, multi-account governance, game days and SLOs before the seasonal peak.

Documents delivered today

10 detailed reports by domain.docx
Action plan and findings registry.xlsx
Executive summary — this document.pdf
06 — Contacts & acknowledgments
Confidential · Maison Verano · Demo
SILAMIR GROUP — CYBERSECURITY & CLOUD
17 / 17
Silamir
Thank you.

Let's stay in touch
for what comes next.

Contact
cloud@silamir.com
Silamir Group — Cybersecurity & Cloud
Next step
Certification re-scan at D+90 — publication of the closing report and new score.