Posture, spend & inventory
Overall posture
health score · vs. last month
Trading platform is reliable, but public storage exposure and legacy on-prem hosts are dragging the security grade down — prioritize those.
Why this grade: 3 critical and 2 high findings are the main drag — clearing the criticals lifts the grade fastest.
3 critical findings incl. public blob & GCS exposure.
Trading VMSS pinned to 1 instance; some VMs unbacked.
88% MFA; 24 privileged and 31 stale accounts to review.
SOC 2 certified; PCI DSS 64% for fuel-card payments.
Intune + CrowdStrike; a stale Win10 host and EDR gaps.
Azure is the largest spend; trending under last month.
EC2 instance querying a known crypto-mining domain
Critical CVE-2024-3094 (xz-utils backdoor) on settlement host · us-west-2
Not enterprise-ready
5
Spend (MTD)
$48,193
Cloud resources
150
Devices compliant
20%
Servers compliant
25%
Public-facing servers
3
Entra app hygiene — retiring what isn't used.
The highest-exposure findings, ranked by severity, internet reach, data sensitivity, privileged access & age.
Microsoft.Storage/storageAccounts · aegsettlementdocs · centralus
AWS::EC2::Instance · i-0aegsettlementec201 · us-west-2
Microsoft.Compute/virtualMachineScaleSets · aeg-trade-vmss · centralus
AWS::EC2::Volume · aeg-settlement-ec2-01 · us-west-2
AWS::Lambda::Function · settlement-processor · us-west-2
Audit readiness across the frameworks that matter to the business.
91/91 controls · audited Mar 15, 2026 · Annual renewal Mar 2027
162/254 controls · Target QSA assessment Q1 2027
47/114 controls · Risk treatment plan in review
79/110 controls · audited May 20, 2026
Who can get in, and how well that access is controlled.
Update posture across cloud services, user devices, and servers.
0 of 4servers assessed — Azure & on-prem via Update Manager (Arc), AWS via Systems Manager Patch Manager. 4 not yet assessed (enable a periodic assessment / patch baseline scan).
Can we get the business back if something fails?
Last successful backup Jun 27, 2026.
The human layer — training and phishing resilience.
Critical & high-severity alerts from endpoint security and watched Teams channels.
GuardDuty flagged aeg-trade-api-3 making repeated DNS lookups to a known cryptocurrency-mining pool — consistent with compromise. (GuardDuty).
🔴 P1: Trading portal p95 latency > 4s for 8 min; on-call paged — AEG NOC (Teams — #aeg-alerts).
Falcon detected suspicious LSASS access consistent with credential dumping on aeg-fin-04 (CrowdStrike Falcon). Host network-contained; IR engaged.
Encoded PowerShell spawned from Office on aeg-sales-11 — likely a macro-borne loader (CrowdStrike Falcon). Blocked; investigating delivery.
Falcon quarantined an Emotet-family binary on aeg-ops-02 (CrowdStrike Falcon). No lateral movement observed; monitoring for re-infection.
Tickets your team manages in AEGSD.
Monitored workloads and your key services — live uptime and vendor status pages.
Findings, spend & resources across connected clouds.
Inspector detected the compromised xz-utils build (CVE-2024-3094, CVSS 10.0) on aeg-settlement-ec2-01.
Fix: Patch xz-utils to a fixed release and rebuild the AMI (Amazon Inspector).
AWS::EC2::Instance · i-0aegsettlementec201 · us-west-2
since 2026-08-03
The settlement-processing Lambda has no reserved concurrency. Under load it competes for account concurrency and throttles, delaying settlements at peak.
Fix: Set reserved + provisioned concurrency sized to peak and add a DLQ for failed invocations.
AWS::Lambda::Function · settlement-processor · us-west-2
since 2026-06-03
Several EBS volumes on production hosts are unencrypted at rest — fails the encryption-everywhere baseline.
Fix: Snapshot, re-create as KMS-encrypted volumes, and enable EBS encryption-by-default on the account.
AWS::EC2::Volume · aeg-settlement-ec2-01 · us-west-2
since 2026-05-30
The fuel-trading portal scale set is pinned to a single instance with autoscale disabled — no horizontal scale and no resilience for a revenue-critical workload.
Fix: Enable autoscale (min 2 / max 6) across availability zones with CPU + queue-depth rules.
Microsoft.Compute/virtualMachineScaleSets · aeg-trade-vmss · centralus
since 2026-05-09
A storage account holding settlement documents permits anonymous public blob access — a data-exposure and compliance risk.
Fix: Disable public blob access, enforce private endpoints, and enable soft delete + immutability.
Microsoft.Storage/storageAccounts · aegsettlementdocs · centralus
since 2026-06-12
Two production VMs have no Recovery Services Vault backup policy — no restore point if a host is lost or corrupted.
Fix: Attach a daily backup policy with 30-day retention and test a restore.
Microsoft.Compute/virtualMachines · aeg-records-01 · centralus
since 2026-06-18
Active endpoints from Intune & Jamf (seen in the last 30 days), grouped by device class — encryption, EDR coverage, and patch status.
| Device | User | OS | MDM | Encrypted | EDR | Updated | Last seen |
|---|---|---|---|---|---|---|---|
AEG-WIN-FIN-038 9JK1120LMN | p.okoye@aegfuels.com | Windows 11 22H2 | Intune | BitLocker: yes BitLocker | EDR: yes CrowdStrike | Updated: no | 5d ago |
AEG-WIN-LEGAL-011 3RT5560WQP | d.reyes@aegfuels.com | Windows 10 22H2 | Intune | BitLocker: yes BitLocker | EDR: no | Updated: no | 21d ago |
AEG-WIN-OPS-076 7XY8821RTM | k.shah@aegfuels.com | Windows 11 23H2 | Intune | Encrypted: no | EDR: yes CrowdStrike | Updated: yes | 2d ago |
AEG-WIN-TRADE-112 5CD2419QPL | t.nguyen@aegfuels.com | Windows 11 23H2 | Intune | BitLocker: yes BitLocker | EDR: yes CrowdStrike | Updated: yes | today |
| Device | User | OS | MDM | Encrypted | EDR | Updated | Last seen |
|---|---|---|---|---|---|---|---|
AEG-IPHONE-ONCALL | shared-oncall@aegfuels.com | iOS 18.5 | Intune | Data Protection: yes Data Protection | EDR: unknown | Updated: yes | 8d ago |
Cloud & on-prem hosts by environment — encryption, EDR, patch status, and public exposure.
| Host | OS | Env | Encrypted | EDR | Updated | Public IP(s) |
|---|---|---|---|---|---|---|
aeg-bastion-01 us-west-2 | Amazon Linux 2023 | prod | EBS KMS: yes EBS KMS | EDR: yes CrowdStrike | Updated: no | 44.230.61.7 |
aeg-settlement-ec2-01 us-west-2 | Ubuntu 22.04 LTS | prod | Encrypted: no | EDR: yes CrowdStrike | Updated: yes | none |
| Host | OS | Env | Encrypted | EDR | Updated | Public IP(s) |
|---|---|---|---|---|---|---|
aeg-records-01 centralus | Windows Server 2019 | prod | Encrypted: no | EDR: no | Updated: no | 20.115.44.22 |
aeg-trade-vmss-0 centralus | Windows Server 2022 | prod | Azure Disk Encryption: yes Azure Disk Encryption | EDR: yes CrowdStrike | Updated: yes | 20.115.44.10 |
How each workload is wired across AWS, Azure & GCP — internet-facing entry points down to data services.