VeUP
← All case studies
Production Engagement · Anonymized
B2B SaaS contains 3 former-insider access events on AWS, app back same week
Software & Internet (B2B SaaS)
AWS IAMAWS CloudTrailIAM Identity Center
Security · Threat Detection & Response (anonymized)

A B2B SaaS platform

AWS-validated reference — full details available to AWS Partner Validation or on request. (Customer name held on file with VeUP.)

During an active former-insider access incident, VeUP delivered AWS-native incident response for a B2B SaaS platform — cross-app access revocation, AWS CloudTrail audit forensics, identity-tenant separation, and MFA-gated federation. Three access events contained, the app restored in week one.

The challenge

During onboarding, a B2B SaaS customer faced an active incident in which a former insider retained access across connected applications. The production application was taken offline, legitimate internal users had been deleted, and overlapping identity paths through a single shared production/staging tenant allowed access to be regained — requiring immediate containment, recovery, and durable identity hardening against recurrence.

The solution

AWS-native incident response delivered from day one of onboarding. VeUP revoked access across every connected application against a verified leaver list; ran AWS CloudTrail audit-log forensics and confirmed logging coverage across the AWS account; recreated legitimately deleted internal users and restored the offline application; separated the identity environment from one shared production/staging tenant into isolated production and staging tenants to eliminate the overlapping paths; and re-established MFA-enforced federated access (AWS IAM Identity Center / federation) as the durable control. Production compute on Amazon EC2 across multiple regions; AWS IAM, Amazon SNS, and cost allocation in support.

Production outcomes

KPIResult
Production outcomesThree separate former-insider access events contained over the engagement (initial takedown, an admin/staging push-path recurrence, and a staging-tenant compromise); the offline production application restored within the first week of onboarding with legitimate users recreated; the identity environment moved from one shared production/staging tenant to isolated production and staging tenants; AWS CloudTrail logging coverage confirmed; and MFA-gated federated access re-established as the durable control.
Engagement window2025-05-13 (incident response at onboarding) → 2025-07 (staging-tenant separation completed early July 2025); recurrence handled mid-June 2025
Cost / TCO postureNot a cost-optimization engagement — value is containment, same-week recovery, and durable identity hardening. AWS Cost Allocation was used in support; no realized-savings claim.
Lessons & continuationOverlapping production/staging identity paths are how revoked access gets regained — tenant separation is the durable fix, not just re-revocation; revoke against a verified leaver list across every connected application; confirm CloudTrail coverage and re-establish MFA-gated federation as the standing control.
AWS services in production

AWS IAM · AWS CloudTrail · AWS IAM Identity Center / federation · Amazon EC2 · Amazon SNS

Architecture

Well-Architected view of the incident-response engagement: the compromised, single shared production/staging identity tenant on the left, the remediated AWS target state on the right — isolated production and staging tenants, MFA-gated AWS IAM Identity Center federation, the cross-application access-revocation boundary, and AWS CloudTrail forensics — assessed against the six Well-Architected pillars.

Previous-state architecture: the compromised, single shared production/staging AWS identity tenant with a federated SSO layer (Auth0 / Google SSO) on AWS IAM, connected applications retaining former-insider access, and no cross-application revocation boundary.
Previous state — compromised, single shared production/staging identity tenant documented at onboarding.
Target-state AWS architecture: isolated production and staging tenants each running Amazon EC2, MFA-gated AWS IAM Identity Center federation, a cross-application access-revocation boundary spanning AWS IAM, the SSO layer, and the endpoint-protection console, AWS CloudTrail audit-log forensics, Amazon SNS notifications, and AWS Cost Allocation.
Target state on AWS (remediated) — isolated identity tenants, MFA-gated federation, and the cross-application revocation boundary.
Layer-by-layer build-up of the target-state AWS architecture: network foundation, compute and application, data, security and observability, and data/network paths.
Layer-by-layer build-up of the remediated AWS architecture.
Well-Architected diagram for an anonymized B2B SaaS incident-response engagement: previous-state single shared production/staging AWS identity tenant with a federated SSO layer (Auth0 / Google SSO) on AWS IAM vs. target-state isolated production and staging tenants each running Amazon EC2, MFA-gated AWS IAM Identity Center federation, a cross-application access-revocation boundary spanning AWS IAM, the SSO layer, and the endpoint-protection console, AWS CloudTrail audit-log forensics, Amazon SNS notifications, and AWS Cost Allocation, with a six-pillar Well-Architected Framework assessment.
Full Well-Architected overview. Customer anonymized; full detail held in the customer's AWS tenant per the standard AWS Partner Validation customer-reference channel.