← Back to Case Studies
Cloud Security & Zero Trust · Industrial Logistics

Multi-Cloud Hardening & Zero Trust Architecture

How a European industrial enterprise with 60+ AWS accounts and Azure tenants eliminated 94% of critical attack vectors using Wiz posture scanning, Terraform Landing Zones, and Okta Zero Trust conditional access.

94%
Critical Risks Resolved
60+
Cloud Accounts Hardened
Zero
IAM Permission Drift
6 Weeks
Remediation Sprint

Client Challenge

Following several corporate acquisitions, the client possessed an uncoordinated multi-cloud estate spanning 60+ AWS accounts, multiple Azure subscriptions, and unmanaged Kubernetes clusters.

Initial posture discovery revealed 1,400+ critical findings: publicly accessible S3 buckets, excessive administrative IAM role assumptions, unpatched container runtimes, and reliance on legacy perimeter VPNs with zero micro-segmentation.

Engineering Strategy & Automation

  • Agentless Cloud Visibility: Integrated Wiz and Tenable across all AWS Organizations and Azure Management Groups, providing continuous graph-based risk prioritization within 48 hours.
  • Terraform Landing Zones: Authored modular Terraform code implementing AWS Service Control Policies (SCPs) and Azure Policy initiatives that prevent public resource exposure at the API level.
  • Identity Threat Detection & Response (ITDR): Centralized user access into Okta with phishing-resistant FIDO2 WebAuthn authentication, enforcing session timeouts and device posture checks.
  • Container & Kubernetes Hardening: Configured Open Policy Agent (OPA) Gatekeeper rules in EKS and AKS clusters, preventing privileged containers from launching in production environments.

Results & Long-Term Governance

  • 94% Vulnerability Reduction: Critical and high risk findings dropped from 1,400+ to under 80 within 6 weeks.
  • Automated Guardrail Enforcement: Preventative SCPs permanently block non-compliant storage and open ingress rules before infrastructure merges.
  • Complete Audit Transparency: Created automated CIS Benchmark and NIS2 posture dashboards for executive board review.