AWS · Security Hub · GuardDuty · IAM Identity Center · Macie · CloudTrail · Zero-Trust
AWS Has Over 30 Security Services.
Most Deployments Are Using Three.
The average AWS environment has Security Groups, IAM access keys, and CloudTrail enabled. GuardDuty is off or unreviewed. Macie has never run. IAM Identity Center was not set up at account creation. The tools exist. The configuration is missing.Symhas activates and configures every relevant AWS security service — tuned to your environment, not at default settings — producing a Zero-Trust posture that satisfies SOC 2, HIPAA, or PCI DSS on first audit submission.
0Critical security incidents across all Symhas-managed AWS production environments
100%First-submission compliance audit pass rate on AWS environments Symhas secures
CIS L2CIS AWS Foundations Benchmark Level 2 achieved on all Symhas security engagements
4wkAWS Zero-Trust implementation — all services configured — fixed price
AWS certified architects available nowActive
0Critical security incidents across all Symhas-managed AWS production environments since go-live
100%Compliance audit pass rate on first submission — SOC 2, HIPAA, PCI DSS on AWS
CIS L2CIS AWS Benchmark Level 2 — target for all Symhas AWS security engagements
4wkFull Zero-Trust — assessment to compliance-ready posture — fixed price
What We Deliver
Core Capabilities.
Production-Grade on AWS.

Every capability designed, deployed, and documented by Symhas AWS-certified architects. Fixed price. SLA-backed from go-live.

IAM Identity Center & Zero-Trust AccessSSO · MFA · Permission sets · Federation · Least-privilege
AWS IAM Identity Center replaces per-account IAM users with federated MFA-enforced access — one identity provider, time-limited least-privilege access to every account, permission sets replacing wildcard policies, and no shared credentials.
IAM Identity Center — Azure AD or Okta federation, MFA enforced for all human access
Permission sets — least-privilege sets validated against actual job function requirements
SCIM provisioning — user and group sync from IdP, joiners/movers/leavers automated
Service principals — instance roles and resource policies replacing static access keys
Privileged access — separate elevated accounts, time-limited elevation, full audit trail
Every AWS access decision tied to an identity and MFA — no shared accounts, no long-lived credentials
AWS Security Hub & GuardDutySecurity Hub · GuardDuty · Automations · SIEM · Threat Intelligence
Security Hub aggregates findings from GuardDuty, Inspector, Macie, Config, and Firewall Manager into a unified view — with Security Hub Automations triggering immediate Lambda-based response to critical findings without waiting for human triage.
Security Hub organisation-wide — CIS Level 2, AWS Foundational, and PCI DSS standards
GuardDuty in all accounts and regions — EC2, S3, EKS, Lambda, and RDS threat detection
Security Hub Automations — critical findings trigger automated Lambda remediation actions
SIEM forwarding — findings streamed to Microsoft Sentinel or Splunk via EventBridge
Suppression rules — false positives suppressed per service, signal-to-noise maintained
Threats detected and remediated automatically — not found in the next quarterly review
AWS Macie & Sensitive Data DiscoveryPHI · PII · S3 · Custom identifiers · Anomalous access
AWS Macie continuously discovers and classifies sensitive data across all S3 buckets — alerting on public buckets, unencrypted objects, and anomalous access. For HIPAA environments, Macie runs pre-migration to discover PHI the team does not know about.
Macie across all accounts — automated discovery on every S3 bucket in every account
Custom data identifiers — patient IDs, account numbers, and internal reference formats
Public bucket alerts — any bucket made public triggers immediate cross-account notification
Unencrypted object detection — objects without CMK encryption flagged automatically
Anomalous access detection — unusual API patterns on sensitive data flagged by Macie ML
Sensitive data in S3 discovered before the regulators discover it — Macie runs pre-go-live
CloudTrail Lake & Compliance EvidenceCloudTrail Lake · Config · Audit Manager · SOC 2 · HIPAA · PCI
CloudTrail Lake provides an immutable searchable audit trail of every API call across every account — with AWS Audit Manager collecting compliance evidence automatically against SOC 2, HIPAA, or PCI DSS, eliminating manual evidence assembly before every audit.
CloudTrail organisation trail — all accounts and regions, central S3 with object lock
CloudTrail Lake — immutable event store, 7-year retention, SQL-queryable
AWS Config — resource configurations recorded, compliance rules evaluated continuously
Audit Manager — SOC 2, HIPAA, or PCI framework configured, evidence auto-collected
Log integrity — CloudTrail log file validation detecting tampering
Compliance evidence produced automatically — audit pack assembled by AWS, not by your team
Delivery Model
Assessment to Production.
Fixed Price. Fixed Timeline.

Four phases with go/no-go gates. Scope and price agreed before week one.

01
Security Assessment & Gap AnalysisWeek 1

CIS AWS Benchmark assessment. IAM over-permission analysis. Security Hub and GuardDuty findings triage. Macie initial scan. Compliance gap against target framework. Prioritised remediation plan produced.

02
IAM & Identity HardeningWeek 2

IAM Identity Center deployed and federated to IdP. MFA enforced. Permission sets replace IAM users. Root account secured. Static access keys rotated to instance roles. SCPs tightened.

03
Detective Controls & Data SecurityWeek 3

Security Hub all standards enabled. GuardDuty across all accounts and regions. Macie on all S3 buckets — findings remediated before go-live. CloudTrail Lake configured. Security Hub Automations deployed.

04
Compliance Validation & HandoverWeek 4

CIS AWS Level 2 score validated. Audit Manager evidence pack produced. Security team trained on Security Hub triage and GuardDuty investigation. P1 response runbooks documented.

Healthcare · AWS Zero-Trust Security450-Bed Health System.
Zero HIPAA Findings. Macie Found 340 PHI Objects Pre-Go-Live.

The health system AWS environment had CloudTrail but no GuardDuty, no Macie, no IAM Identity Center, and 47 IAM users with administrator access across 6 accounts. HIPAA compliance was required on go-live day with the first audit 8 weeks later.

Symhas implemented AWS Zero-Trust security in 4 weeks — IAM Identity Center replacing 47 IAM users, GuardDuty active across all accounts, Macie finding 340 PHI objects in unencrypted S3 before go-live, and Audit Manager producing the HIPAA evidence pack automatically. Zero findings at audit.

0HIPAA findings at audit
340PHI objects found pre-go-live
47→0IAM users with admin access
4wkAssessment to Zero-Trust
Discuss Your Programme
What was delivered

AWS Zero-Trust Security — Healthcare HIPAA Deployment

IAM Identity Center — 47 per-account IAM users replaced, Azure AD federation, MFA enforced for all 340 users
Permission sets — 8 least-privilege sets replacing wildcard administrator policies
GuardDuty — 6 accounts, 3 regions, 23 high-severity findings resolved in week 2
Macie — 340 PHI objects in unencrypted S3 discovered and remediated before migration cutover
Security Hub — CIS Level 2 and HIPAA standards, 892 findings remediated over 4 weeks
Audit Manager — HIPAA framework, evidence for 82 controls collected automatically

“Macie found 340 PHI objects in S3 buckets we did not know existed. We fixed every one before go-live. Without Macie running pre-migration, that would have been a HIPAA breach.”

— CISO, Regional Health System

AWS Services Deployed
The Specific AWS Services
We Configure for This Capability.
AWS
AWS IAM Identity Center

Federated MFA-enforced access — single identity plane replacing per-account IAM users.

Azure AD or Okta federation
MFA enforcement for all users
Permission set design and deployment
SCIM provisioning
AWS
AWS Security Hub

Unified posture — GuardDuty, Inspector, Macie, Config findings aggregated with automated response.

All standards enabled organisation-wide
Security Hub Automations
Cross-account aggregation
SIEM via EventBridge
AWS
AWS GuardDuty

ML threat detection — CloudTrail, DNS, VPC Flow Logs, EKS audit logs across all accounts.

Organisation-wide enablement
EC2, S3, EKS, Lambda, RDS detection
Malware Protection for EC2
Routing to Security Hub
AWS
AWS Macie

Sensitive data discovery — PHI, PII, and financial data classified in S3, anomalous access detected.

Automated discovery on all buckets
Custom data identifiers
Public bucket immediate alert
Anomalous access detection
AWS
AWS CloudTrail Lake

Immutable audit trail — all API calls, all accounts, all regions, SQL-queryable, 7-year retention.

Organisation trail and object lock
CloudTrail Lake event store
7-year retention
Log file integrity validation
AWS
AWS Config & Audit Manager

Continuous compliance — resource config recorded, rules evaluated, evidence collected automatically.

Config organisation rules
Compliance pack deployment
Audit Manager framework configuration
Automated evidence collection
Why Symhas
AWS Expertise Built from Production Deployments.
Assessment Before ConfigurationEvery remediation is justified by a specific finding. No generic hardening checklists applied without understanding your environment.
GuardDuty Tuned, Not Just EnabledDefault GuardDuty produces noise. Symhas tunes suppression rules and finding routing — only actionable findings reach the security team.
Macie Runs Before Go-LivePHI in S3 is found by auditors, not security teams. Symhas runs Macie before migration completes — findings remediated before go-live, not after.
Audit Manager for Your Specific FrameworkGeneric Audit Manager does not map to your auditor controls. Symhas configures Audit Manager for SOC 2, HIPAA, or PCI DSS specifically.
SCPs Before Workloads ArriveSCPs cannot retroactively remove permissions in use. Symhas applies SCPs before migration — prohibited actions blocked structurally from day one.
Security Team Certified at HandoverBy handover your team triages Security Hub and investigates GuardDuty independently. Certified before the first live security event.
Next Step
Tell Us What Your Current AWS Security Posture Looks Like.
We Will Tell You Where the Gaps Are.
A 30-minute AWS security assessment with a Symhas cloud security architect. We will run a CIS benchmark against your environment and deliver a prioritised gap report before the engagement begins.No commitment. No pitch deck. An honest conversation about your AWS environment.