VeUP
← All case studies
Production Engagement · Anonymized
Rebuilding a 13-account Control Tower landing zone for a clean third-party security audit
Software & Internet (SaaS — AI meeting intelligence)
AWS Control TowerAWS Security HubCloudTrailIAM Identity Center
Security Competency · Control Tower Audit Readiness

An AI meeting-intelligence SaaS company

AWS-validated reference — full details available to AWS Partner Validation or on request. (Customer name held on file with VeUP.)

VeUP remediated and rebuilt the customer tainted AWS Control Tower landing zone across a 13-account AWS Organization — enabling Security Hub org-wide (FSBP + CIS), fixing CloudTrail logging, reconciling IAM Identity Center, and validating every account enrollment — to make the platform audit-ready ahead of a third-party security audit.

The challenge

the customer was preparing for a third-party security audit, but its AWS foundation was not ready. It ran a 13-account AWS Organization on a Control Tower landing zone (v4.0) that had become tainted — the landing zone had at one point been deleted, leaving accounts in an inconsistent governance state. A hands-on assessment (2026-03-02) surfaced gaps across the org: incomplete org-wide security monitoring, CloudTrail logging gaps, drifted account enrollments, and inconsistent guardrails. the customer needed a partner to remediate and rebuild its governance baseline so it could pass a governance and compliance audit cleanly and lay a foundation for later SOC 2 / PCI-DSS / HIPAA work.

The solution

A Phase 1 Control Tower Audit-Readiness engagement across three workstreams, preceded by a Well-Architected Review. (1) Security and compliance remediation — enabled AWS Security Hub organization-wide against AWS Foundational Security Best Practices (FSBP) and CIS, remediated CloudTrail logging coverage, reconciled IAM Identity Center, and hardened guardrails and Service Control Policies (SCPs) across the Organization. (2) Infrastructure validation and governance — cleaned up the Organizational Unit structure, validated all 13 member-account enrollments in Control Tower, verified AWS Config recording in every member account, deployed organization-wide AWS Backup policies, and checked StackSet drift; where the existing landing zone was too compromised to repair in place, accounts were migrated onto a fresh, untainted management root and Control Tower was rebuilt. (3) Compliance documentation and knowledge transfer — architecture diagrams, a compliance control mapping, an access-governance matrix, a Security Hub posture baseline, and a knowledge-transfer session.

Production outcomes

KPIResult
Production outcomesAWS Security Hub enabled organization-wide against FSBP and CIS; all 13 member accounts validated as enrolled and governed in Control Tower with AWS Config recording verified account-by-account; organization-wide AWS Backup policies deployed and SCP guardrails hardened; a complete compliance documentation set (architecture diagrams, control mapping, access-governance matrix, Security Hub posture baseline) handed to the customer for the auditor; a governance foundation explicitly built to support future SOC 2 / PCI-DSS / HIPAA work. The engagement re-established a defensible, auditable AWS governance baseline ahead of the third-party security audit.
Engagement window2026-03-02 (hands-on assessment); SOW Closed-Won 2026-03-12 → Phase 1 remediation/validation/documentation delivered; ongoing
Cost / TCO posturePhase 1 professional-services engagement (PS $15,000) under a managed-billing Ignite relationship (~$55K annual AWS spend). Remediation reused the existing Control Tower control plane where possible and rebuilt only where the landing zone was too compromised to repair in place, minimizing rework.
Lessons & continuationA deleted/tainted Control Tower landing zone cannot always be repaired in place — migrating accounts onto a fresh, untainted management root and rebuilding Control Tower is the reliable path. Account-by-account validation of Config recording and enrollment is what makes "13 accounts governed" an auditable claim rather than an assumption.
AWS services in production

AWS Control Tower · AWS Security Hub (FSBP + CIS) · AWS CloudTrail · AWS IAM Identity Center · AWS Config · AWS Backup · AWS Organizations · SCP guardrails

Architecture

A Well-Architected-annotated view of the previous drifted landing zone, the Phase 1 remediation, and the rebuilt, audit-ready governance baseline across the 13-account organization.

Previous state

Previous state: the tainted 13-account Control Tower v4.0 landing zone with documented governance gaps (Security Hub disabled, CloudTrail not recording, Config partial, no org-wide Backup, unchecked StackSet drift).

Target state on AWS

Target state on AWS: rebuilt Control Tower landing zone v4.0 on a fresh management root, with Security Hub, GuardDuty, Config, CloudTrail, IAM Identity Center, KMS, and org-wide Backup governing all 13 accounts around the clipr-prod serverless production workload.

Layer-by-layer build-up

Animated build-up of the target-state architecture layer by layer: network foundation, compute and application, data, and security and observability.

Full Well-Architected overview

AWS Well-Architected diagram: previous drifted Control Tower landing zone, Phase 1 remediation (Security Hub org-wide, CloudTrail centralization, IAM Identity Center reconciliation, Config and Backup hardening), and the rebuilt target-state 13-account governance baseline, with six Well-Architected pillar findings.