Overview
Reversec helped a gas distribution company secure its end-to-end cloud migration to AWS. We reviewed the AWS environment design before implementation and tested the live environment for critical attack paths that could expose the company to an unacceptable level of cyber risk.
Company
Gas distribution company
Industry
Energy
Our solution
We supported the client across two phases:
Phase 1: Design Review
We performed a security review of the client’s future-state AWS environment design. The goal was to strengthen the design early, minimizing the cost of future remediation.
Working closely with both the client and AWS, we ensured the design reflected expert knowledge of modern attack techniques and incorporated robust defense-in-depth principles. Threat modelling was used to identify assets, threats, and viable attack vectors. The review informed a subsequent risk-led technical assessment and helped ensure the environment was built to mitigate core risks.
Phase 2: Attack Path Mapping
Once the cloud environment was live, we conducted a risk-led technical assessment using our Attack Path Mapping (APM) methodology. This engagement revealed how an attacker with no access or with an arbitrary workstation within the on-premises environment, could pursue:
- Administrative access to the AWS cloud environment from the residual on-premises estate.
- Access to business-critical applications within the AWS cloud environment from the residual on-premises estate
- Disruption of operations either by impacting the availability or integrity of critical cloud services.
We provided several recommendations to mitigate these vulnerabilities and collaborated closely with the client throughout the migration, offering ongoing advice and guidance.
Outcome
Reversec supported to the client early in the design phase and post-deployment, ensuring that the environment was securely built and thoroughly tested. We identified significant vulnerabilities that would have exposed the client to high levels of cyber risk. Thanks to our recommendations, the client was able to mitigate these risks and feel confident in the security posture of its AWS environment.
The client’s CISO described the project as amongst the best work they had seen in their career.
Don’t be a stranger, let’s get in touch.
Our team of dedicated experts can help guide you in finding the right
solution for your unique issues. Complete the form and we are happy to
reach out as soon as possible to discuss more.
This site is protected by reCAPTCHA and the Google
Privacy Policy and Terms of Service apply.