Free AWS Risk Assessment

A real assessment of your AWS environment — not a 60-second guess.

14 questions across security, backup readiness, access governance and cost. Built for someone who actually owns the AWS bill — a founder, CTO or ops lead — not a marketing quiz. Takes about 5 minutes and gives you a scored breakdown by category, not just a single number.

~5 min To complete
4 categories Security · Backup · Access · Cost
No card required Just a work email for your report
0 of 14 answered
Security

The findings that most often turn into an actual incident — unauthorised access, exposed data or a compromised account.

Question 1 of 14

Does every account with administrative access to your AWS environment have MFA enforced — not just enabled, but required?

Enabled-but-optional MFA is common and doesn't count.

Question 2 of 14

Is your AWS root account used for day-to-day work, or locked away with MFA and used only for account-level tasks?

Question 3 of 14

Do you know exactly which S3 buckets, databases or endpoints in your account are publicly accessible right now?

Question 4 of 14

Are security groups and network access rules reviewed on a schedule, or only touched when something breaks?

Question 5 of 14

If an access key or credential leaked today, would you know within hours — or would you find out some other way?

Backup & Recovery

Backups that exist but were never tested are the single most common gap we find in a Cloud Health Check.

Question 6 of 14

Do all production workloads and databases have automated backups configured?

Question 7 of 14

Have you actually performed a test restore from backup in the last 6 months — not just confirmed a backup job ran?

Question 8 of 14

If your primary AWS region had an outage, how long could your business realistically operate without it?

Question 9 of 14

Is there a written retention policy for backups (how long they're kept, where, and who's responsible)?

Access & Governance

Who can do what in your AWS account, and whether that list is actually kept current.

Question 10 of 14

When someone joins or leaves the company, is their AWS access updated as part of that process — or as an afterthought?

Question 11 of 14

Roughly how many people or services have full administrator access to your AWS account?

Cost

Whether your AWS spend is under control, or just something that gets glanced at when the invoice arrives.

Question 12 of 14

Over the last quarter, has your AWS spend grown faster than your actual usage or customer base?

Question 13 of 14

Has anyone audited for unused or oversized resources (idle instances, unattached volumes, over-provisioned databases) in the last 3 months?

Question 14 of 14

Does anyone get an alert before AWS spend crosses a budget threshold, or is the first sign of a problem the monthly invoice?

What stood out

Want the full picture?

This is a self-assessment — useful for spotting where to look, but it can't see your actual AWS configuration. A CloudGuard Cloud Health Check goes through your account directly and gives you a prioritized, evidence-based report.