A B2B SaaS platform
AWS-validated reference — full details available to AWS Partner Validation or on request. (Customer name held on file with VeUP.)
During an active former-insider access incident, VeUP delivered AWS-native incident response for a B2B SaaS platform — cross-app access revocation, AWS CloudTrail audit forensics, identity-tenant separation, and MFA-gated federation. Three access events contained, the app restored in week one.
The challenge
During onboarding, a B2B SaaS customer faced an active incident in which a former insider retained access across connected applications. The production application was taken offline, legitimate internal users had been deleted, and overlapping identity paths through a single shared production/staging tenant allowed access to be regained — requiring immediate containment, recovery, and durable identity hardening against recurrence.
The solution
AWS-native incident response delivered from day one of onboarding. VeUP revoked access across every connected application against a verified leaver list; ran AWS CloudTrail audit-log forensics and confirmed logging coverage across the AWS account; recreated legitimately deleted internal users and restored the offline application; separated the identity environment from one shared production/staging tenant into isolated production and staging tenants to eliminate the overlapping paths; and re-established MFA-enforced federated access (AWS IAM Identity Center / federation) as the durable control. Production compute on Amazon EC2 across multiple regions; AWS IAM, Amazon SNS, and cost allocation in support.
Production outcomes
| KPI | Result |
|---|---|
| Production outcomes | Three separate former-insider access events contained over the engagement (initial takedown, an admin/staging push-path recurrence, and a staging-tenant compromise); the offline production application restored within the first week of onboarding with legitimate users recreated; the identity environment moved from one shared production/staging tenant to isolated production and staging tenants; AWS CloudTrail logging coverage confirmed; and MFA-gated federated access re-established as the durable control. |
| Engagement window | 2025-05-13 (incident response at onboarding) → 2025-07 (staging-tenant separation completed early July 2025); recurrence handled mid-June 2025 |
| Cost / TCO posture | Not a cost-optimization engagement — value is containment, same-week recovery, and durable identity hardening. AWS Cost Allocation was used in support; no realized-savings claim. |
| Lessons & continuation | Overlapping production/staging identity paths are how revoked access gets regained — tenant separation is the durable fix, not just re-revocation; revoke against a verified leaver list across every connected application; confirm CloudTrail coverage and re-establish MFA-gated federation as the standing control. |
AWS IAM · AWS CloudTrail · AWS IAM Identity Center / federation · Amazon EC2 · Amazon SNS
Architecture
Well-Architected view of the incident-response engagement: the compromised, single shared production/staging identity tenant on the left, the remediated AWS target state on the right — isolated production and staging tenants, MFA-gated AWS IAM Identity Center federation, the cross-application access-revocation boundary, and AWS CloudTrail forensics — assessed against the six Well-Architected pillars.


