Silamir


AWS
security
audit _

Risk mapping by domain and 90-day remediation plan.
Client
Kaelis Pay · Demo
Audit date
15/09/2026
Reference
SIL-AUD-7F3A9C21
Silamir Group
Cybersecurity & Cloud
Contents
Audit / Kaelis Pay · Demo
02 / 17
Table of contents

Six chapters to frame
the security posture.

01
Audit context
Scanned AWS scope and methodological approach.
p. 03 — 04
02
Overall verdict
Score, posture, findings distribution and top 5 risks.
p. 05 — 07
03
Results by domain
IAM, data, network, FinOps, resilience & observability.
p. 08 — 12
04
Remediation plan
90-day roadmap, quick wins, structural investments.
p. 13 — 15
05
Summary & commitments
Key messages, next steps, delivered documents.
p. 16
06
Contacts
Silamir contacts and review schedule.
p. 17
01 — Context
Audited scope
03 / 17
Audited scope

What we examined.

AWS footprint

1
AWS accounts
scanned read-only
3
Regions
active within scope
1,284
Resources
EC2 · S3 · IAM · RDS · Lambda · VPC
187
Findings
collected before correlation

Domains covered — 10

IAM & Identities
D01
Perimeter security
D02
Data
D03
Network & VPC
D04
Observability
D05
Secrets & KMS
D06
Compute
D07
Resilience
D08
FinOps
D09
Compliance
D10

Audit mode

Read-only
No modifications made to the client environment.
DAST ZAP Baseline enabled
External dynamic tests on the exposed surface.
01 — Context
Methodology
04 / 17
Approach

Four steps, two frameworks,
one AI-driven correlation.

01
Read-only
collection
Automated inventory of resources, configurations and logs across all accounts — without any mutation.
~ 12 min
02
Claude AI
analysis
Each finding is qualified, prioritized and contextualized by an audited model, with citations of the triggered rules.
187 findings
03
Action
plan
0-30-60-90 day roadmap with effort, gain and owner for each identified initiative.
44 actions
Frameworks
applied
AWS FSBP
Foundational Security Best Practices
CIS AWS 1.5
Center for Internet Security Benchmark
NIST CSF
Cybersecurity Framework — cross-cutting mapping
02 — Overall verdict
Score & posture
05 / 17
Overall verdict

A AT RISK posture,
driven by 9 critical findings.

Silamir global score
52/100
Posture · AT RISK
Critical At risk Compliant Mature

Findings distribution

P0
9
P1
38
P2
140
02 — Overall verdict
Heatmap by domain
06 / 17
Heatmap by domain

10 domains, 4 levels,
a snapshot of risk.

Domain Risk level Findings (P0 / P1 / P2) Score
D01 — Inventory
Compliant
0  ·  1  ·  2
71
D02 — Security FSBP / CIS
At risk
2  ·  3  ·  2
46
D03 — FinOps
At risk
0  ·  2  ·  3
58
D04 — Well-Architected
At risk
0  ·  2  ·  2
55
D05 — Resilience
At risk
1  ·  2  ·  1
44
D06 — Network & VPC
At risk
1  ·  2  ·  1
49
D07 — Web security (DAST)
Compliant
0  ·  1  ·  2
62
D08 — IAM & Identities
Critical
3  ·  2  ·  1
34
D09 — Containers & Serverless
At risk
0  ·  2  ·  2
57
D10 — Secrets & KMS
Critical
2  ·  1  ·  1
38
02 — Overall verdict
Top 5 major risks
07 / 17
Top 5 major risks · P0

Five breakpoints
to neutralize within 30 days.

01
P0 · CRITICAL
Root account in use with active access keys and no hardware MFA
Business impact: A single leaked key gives full control of production: payments halted, data exfiltrated and a reportable DORA incident.
DomainIAM
Linked findingsIAM-001
02
P0 · CRITICAL
Transaction-export S3 bucket publicly readable
Business impact: 12,400 customer statements exposed on the Internet: 72-hour GDPR breach notice, potential fine and loss of trust.
DomainData
Linked findingsS3-004
03
P0 · CRITICAL
Production RDS PostgreSQL open to 0.0.0.0/0 (port 5432)
Business impact: The payment database is reachable from the Internet; a brute-force attack is enough to compromise the core business.
DomainNetwork
Linked findingsNET-002
04
P0 · CRITICAL
No tested restore and no cross-region copy of the payment database
Business impact: After ransomware or a region outage, recovery is not guaranteed: unknown RTO, at odds with DORA requirements.
DomainResilience
Linked findingsRES-001
05
P0 · CRITICAL
GuardDuty disabled and CloudTrail limited to a single region
Business impact: An intrusion could stay invisible for weeks, with no usable audit trail for investigators or the regulator.
DomainSecurity
Linked findingsSEC-003
03 — Results by domain · 1 / 5
Security & IAM
08 / 17
D01 · D02

Security & IAM

Governance of human and machine identities, IAM configurations, MFA, root policies and access keys.
34/100
Level · CRITICAL

Key findings

P0
Active root access keys (last used 6 days ago)
P0 · arn:aws:iam::123456789012:root
P0
ci-deploy user with AdministratorAccess and a 412-day-old key
P0 · arn:aws:iam::123456789012:user/ci-deploy
P1
7 console users without MFA, including 2 administrators
P1 · 7 IAM users
P1
Inline policies with Action "*" on 4 application roles
P1 · arn:aws:iam::123456789012:role/app-*
P2
Password policy not compliant with CIS 1.8
P2 · Account 123456789012
Access keys > 90 days
11
3 of them tied to admin service accounts
Users without MFA
7 / 19
37% of human identities
Over-privileged roles
14
Permissions unused for more than 90 days
Root usage, last 30 days
4
Console sign-ins and API calls with root keys
Priority action
Delete root keys, enforce MFA and federate through IAM Identity Center
Root keys removed, hardware MFA on root, SSO for all 19 users and least-privilege roles generated with Access Analyzer.
Effort
6 d
Score gain
+14 pts
03 — Results by domain · 2 / 5
Data — S3, RDS, Backup
09 / 17
D03

Data

S3, RDS, EBS and backup strategies — exposure, encryption at rest and in transit, retention and restorability.
38/100
Level · CRITICAL

Key findings

P0
Export bucket: Block Public Access disabled and public-read ACL
P0 · arn:aws:s3:::kaelis-exports-prod
P0
Database credentials in plain text in Lambda environment variables
P0 · arn:aws:lambda:eu-west-3:123456789012:function:settlement
P1
3 RDS instances encrypted with the AWS-managed key, no dedicated CMK
P1 · kaelis-core, kaelis-ledger, kaelis-kyc
P1
Rotation disabled on 9 secrets older than 180 days
P1 · Secrets Manager eu-west-3
P2
EBS encryption by default disabled in 2 regions
P2 · eu-west-1, us-east-1
Public S3 buckets
2 / 64
1 of them holds transaction data
Plain-text secrets found
23
Lambda variables, ECS and EC2 user-data
KMS keys without rotation
6 / 11
Customer-managed keys without yearly rotation
Unencrypted EBS volumes
18
412 GB of data unencrypted at rest
Priority action
Close S3 exposure and centralise secrets in Secrets Manager
Account-level Block Public Access, public ACLs purged, 23 secrets moved to Secrets Manager with rotation.
Effort
5 d
Score gain
+12 pts
03 — Results by domain · 3 / 5
Network & external exposure
10 / 17
D04

Network & exposure

VPC, segmentation, security groups, public surface and external dynamic tests (DAST) on exposed endpoints.
49/100
Level · AT RISK

Key findings

P0
Payment database security group opens port 5432 to 0.0.0.0/0
P0 · sg-0a41c7e2 · RDS kaelis-core
P1
SSH (22) open to the Internet on 5 bastions and workers
P1 · 5 EC2 instances eu-west-3
P1
VPC Flow Logs disabled on the production VPC
P1 · vpc-0c93e1f0 · prod-eu-west-3
P1
HTTP security headers missing on the public API (ZAP DAST)
P1 · api.demo-kaelis.example
P2
Default NACL allowing all traffic on 3 subnets
P2 · 3 private subnets
Security groups open 0.0.0.0/0
9
2 of them on database ports
Exposed public endpoints
14
ALB, API Gateway, CloudFront, public EC2
DAST alerts (ZAP)
17
3 medium, 14 low, no high
VPCs without Flow Logs
2 / 3
No visibility on east-west traffic
Priority action
Restrict security groups and route admin access through SSM Session Manager
Ports 22 and 5432 closed to the Internet, bastions replaced by SSM, Flow Logs enabled and AWS Config rules to prevent regressions.
Effort
4 d
Score gain
+10 pts
03 — Results by domain · 4 / 5
FinOps
11 / 17
D09

FinOps

Monthly cost, savings opportunities activatable without impact on service quality or security.
58/100
Level · AT RISK

Identified opportunities

P1
No Savings Plan or Reserved Instance on a stable compute baseline
P1 · 71% of EC2/Fargate compute on demand
P1
22 EC2 instances averaging under 10% CPU over 30 days
P1 · staging and batch environments
P1
Non-production environments running 24/7
P1 · dev, QA and performance
P2
41 unattached EBS volumes and orphaned snapshots
P2 · 3.8 TB in eu-west-3
P2
Redundant NAT Gateways on lightly used VPCs
P2 · 4 NAT Gateways · ~€290/month
Monthly AWS bill
38,400 €
Average of the last 3 months, excl. tax
Savings potential
7,250 €/month
19% of the bill, no service impact
Savings Plans coverage
0%
Recommended target: 60–70% of stable compute
Untagged resources
46%
Cost allocation per product not possible
Priority action
Buy a 1-year Compute Savings Plan and stop non-prod at night
Commitment on 60% of the stable compute baseline plus Instance Scheduler on dev and QA: €4,800/month saved from the first month.
Effort
3 d
ROI
~4,800€/month saved
03 — Results by domain · 5 / 5
Resilience & Observability
12 / 17
D05 · D08

Resilience & Observability

RTO/RPO documented and tested, monitoring coverage, operational alerting and end-to-end incident chain.
44/100
Level · AT RISK

Key findings

P0
No restore test and no cross-region copy of the payment database
P0 · kaelis-core · AWS Backup not configured
P1
Ledger database deployed Single-AZ
P1 · kaelis-ledger · db.r6g.xlarge
P1
No CloudWatch alarm on 5xx errors of the payment API
P1 · API Gateway payments-api
P1
No log retention set on 38 CloudWatch log groups
P1 · 38 log groups
P2
RTO and RPO undocumented for critical services
P2 · DORA continuity plan
Resources under AWS Backup
12%
7 of 58 eligible resources
Multi-AZ databases
1 / 4
Only the payment database is replicated
Actionable alarms
6
None routed to on-call
Last restore test
Never
No evidence of recoverability
Priority action
Deploy AWS Backup with cross-region copy and restore testing
Backup plans by criticality, locked vault (Vault Lock), copy to eu-west-1 and a documented quarterly restore test for DORA.
Effort
6 d
Score gain
+15 pts
04 — Remediation plan
90-day roadmap
13 / 17
Remediation plan · 90 days

From P0 to P2,
a trajectory in three waves.

WAVE P0
D+0 → D+30

Neutralize
critical breakpoints

01
Delete root keys and enforce hardware MFA
1 d
02
Block S3 public access at account level
1 d
03
Close PostgreSQL 5432 and SSH 22 to the Internet
1 d
04
Enable GuardDuty and multi-region CloudTrail
1 d
05
Revoke ci-deploy admin key, switch to OIDC
2 d
9 actions18 d
WAVE P1
D+30 → D+60

Harden domains
with structural risk

06
Federate access through IAM Identity Center
4 d
07
Buy a 1-year Compute Savings Plan
1 d
08
Move the ledger database to Multi-AZ
1 d
09
Enable Flow Logs, replace bastions with SSM
3 d
10
Route 5xx and latency alarms to on-call
2 d
18 actions41 d
WAVE P2
D+60 → D+90

Industrialize
and maintain the posture

11
Tagging policy and cost allocation
3 d
12
Clean up orphaned EBS volumes and snapshots
1 d
13
EBS encryption by default in every region
1 d
14
CloudWatch log retention policy
1 d
15
Document RTO / RPO and the DORA continuity plan
4 d
17 actions32 d
04 — Remediation plan
Quick wins
14 / 17
Quick wins · 5 actions

High impact, low effort,
activatable within 14 days.

QW · 01
Delete root keys and enable hardware MFA
Removes the risk of a full account takeover.
Effort
1 d
Gain
Security
QW · 02
Block S3 public access at account level
Closes the exposure of transaction exports in under an hour.
Effort
1 d
Gain
Security
QW · 03
Close ports 5432 and 22 to the Internet
Takes the payment database and bastions off the attack surface.
Effort
1 d
Gain
Security
QW · 04
Enable GuardDuty and multi-region CloudTrail
Threat detection and the audit trail DORA expects.
Effort
1 d
Gain
Security
QW · 05
Buy a 1-year Compute Savings Plan
Commitment on 60% of stable compute, no architecture change.
Effort
1 d
Gain
+3,900€/month
Total effort
5 d
Cumulative score gain
+12 to +16 pts
Annualized savings
46,800 €/year
Activation timeline
≤ 14 d
04 — Remediation plan
Structural investments
15 / 17
Structural investments · long-term initiatives

Four foundations
for a mature posture at 12 months.

Multi-account landing zone (Control Tower)

Prod, non-prod and security separated, guardrail SCPs and centralised logging in a Log Archive account.
Effort
12 d
Timeline
M2-M5
Owner
Cloud / Sec

IAM Identity Center federation and least privilege

Single SSO, MFA everywhere, roles derived from real usage with Access Analyzer, IAM users removed.
Effort
8 d
Timeline
M1-M3
Owner
Security

AWS Backup, cross-region copy and tested DR plan

Backups by criticality, Vault Lock and proven quarterly restores: the DORA continuity foundation.
Effort
6 d
Timeline
M1-M2
Owner
Platform

Centralised detection and response

Aggregated Security Hub FSBP / CIS, GuardDuty in all regions, alerts routed to the SOC with automated runbooks.
Effort
5 d
Timeline
M2-M3
Owner
SOC / Sec
05 — Summary & commitments
Key messages
16 / 17
Summary & commitments

Three messages,
three next steps.

Key messages

01
At-risk posture, fixable in 90 days
9 critical findings concentrated on IAM, data exposure and continuity; all can be fixed without re-architecting the application.
02
5 quick wins, 5 d, €46k/year
Root keys, public S3, open ports and detection are fixed within a week; the Savings Plan alone pays for the remediation.
03
DORA target to secure within 6 months
Tested continuity, audit trail and controlled privileged access: three DORA requirements that cannot be evidenced today.

Next steps

→
Validation & framing
Executive debrief, scope validation, ownership assignment.
→
Quick-wins sprint (W1-W2)
Execute P0 actions: root keys, public S3, open ports, detection.
→
Roadmap M1-M6
Landing zone, identity federation, tested DR plan and centralised detection.

Documents delivered today

10 detailed reports by domain.docx
Action plan and findings registry.xlsx
Executive summary — this document.pdf
06 — Contacts & acknowledgments
Confidential · Kaelis Pay · Demo
SILAMIR GROUP — CYBERSECURITY & CLOUD
17 / 17
Silamir
Thank you.

Let's stay in touch
for what comes next.

Contact
cloud@silamir.com
Silamir Group — Cybersecurity & Cloud
Next step
Certification re-scan at D+90 — publication of the closing report and new score.