A real assessment of your AWS environment — not a 60-second guess.
14 questions across security, backup readiness, access governance and cost. Built for someone who actually owns the AWS bill — a founder, CTO or ops lead — not a marketing quiz. Takes about 5 minutes and gives you a scored breakdown by category, not just a single number.
The findings that most often turn into an actual incident — unauthorised access, exposed data or a compromised account.
Does every account with administrative access to your AWS environment have MFA enforced — not just enabled, but required?
Enabled-but-optional MFA is common and doesn't count.
Is your AWS root account used for day-to-day work, or locked away with MFA and used only for account-level tasks?
Do you know exactly which S3 buckets, databases or endpoints in your account are publicly accessible right now?
Are security groups and network access rules reviewed on a schedule, or only touched when something breaks?
If an access key or credential leaked today, would you know within hours — or would you find out some other way?
Backups that exist but were never tested are the single most common gap we find in a Cloud Health Check.
Do all production workloads and databases have automated backups configured?
Have you actually performed a test restore from backup in the last 6 months — not just confirmed a backup job ran?
If your primary AWS region had an outage, how long could your business realistically operate without it?
Is there a written retention policy for backups (how long they're kept, where, and who's responsible)?
Who can do what in your AWS account, and whether that list is actually kept current.
When someone joins or leaves the company, is their AWS access updated as part of that process — or as an afterthought?
Roughly how many people or services have full administrator access to your AWS account?
Whether your AWS spend is under control, or just something that gets glanced at when the invoice arrives.
Over the last quarter, has your AWS spend grown faster than your actual usage or customer base?
Has anyone audited for unused or oversized resources (idle instances, unattached volumes, over-provisioned databases) in the last 3 months?
Does anyone get an alert before AWS spend crosses a budget threshold, or is the first sign of a problem the monthly invoice?
What stood out
This is a self-assessment — useful for spotting where to look, but it can't see your actual AWS configuration. A CloudGuard Cloud Health Check goes through your account directly and gives you a prioritized, evidence-based report.