Skip to content
Back to Blog
·7 min read·guides

Case Study: Bengaluru SaaS Closed 47 AWS Misconfigs in 2 Weeks

A 45-person Bengaluru SaaS company on the path to SOC 2 had 47 AWS misconfigurations flagged in audit. Working with Bachao.AI, they closed 41 critical findings in 2 weeks and the remaining 6 in 6 weeks. Series B due diligence cleared.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Get Your Free VAPT Scan

What this means for your business

Indian SMBs without documented security controls face 3× higher breach costs (IBM Cost of a Data Breach 2024). This guide helps you close that gap.

The situation

A Bengaluru-based B2B SaaS company (we'll call them "AnalyticsCo") was deep in Series B due diligence when their investor's technical reviewer flagged "AWS security posture below acceptable threshold." The investor requested a formal security audit and remediation plan as a closing condition.

AnalyticsCo's profile:

    1. 45 employees, ~280 enterprise customers
    2. AWS-only, 3 accounts (prod, staging, dev)
    3. ~120 EC2 instances, 12 RDS, 47 S3 buckets, 4 Lambda functions
    4. No dedicated security engineer
    5. Series B closing target: 8 weeks
    6. Existing SOC 2 Type I from 18 months prior (Type II planned)
The CTO had a clear ask: clean audit + remediation evidence within 6 weeks.

The audit (Week 1)

The Bachao.AI 5-day audit ran the same week as the engagement letter signed. Results:

SeverityCount
Critical8
High14
Medium19
Low6
Total47
Sample Critical findings:
  1. IAM user with AdministratorAccess + no MFA — the original CTO's IAM user from company founding, still active, no MFA. (Resolved in 30 minutes of the audit briefing.)
  2. 3 S3 buckets publicly readable, 1 contained 6 months of customer support attachments — including some attachments with customer PII. (Resolved in 2 hours; data audit confirmed scope.)
  3. CloudTrail not enabled in 2 of 3 accounts — staging + dev accounts had no audit log retention. (Resolved in 4 hours.)
  4. Database service account with s3:* on all buckets — over-permissive, allowed lateral pivot if compromised. (Resolved in 6 hours after IAM policy refactor.)
  5. Default VPC still in use for production — production EC2 instances in default VPC alongside dev resources. (Required 2-week migration window.)
  6. Lambda function with PII data flow had no encryption + 90-day log retention only — DPDP Section 8(4) implication. (Resolved in 3 days.)
  7. Long-lived access keys (4+ years old) on 12 IAM users — including users who had left the company. (Resolved in 1 week with key rotation + IAM cleanup.)
  8. No GuardDuty enabled — no anomaly detection on AWS API calls. (Resolved in 2 hours.)

The 2-week sprint (Week 2-3)

Bachao.AI engineers worked alongside AnalyticsCo's DevOps lead for 2 weeks. Pattern:

Week 2 (Critical + 5 High closures):

    1. Day 8: All 8 Critical findings resolved
    2. Day 9–10: 5 of 14 High findings resolved (S3 bucket policies, security groups, KMS key rotation)
    3. Day 10–12: Default VPC migration planning
    4. Day 13–14: Default VPC migration executed (4 hours of partial-service window over a Sunday)
Week 3 (Remaining 9 High + 19 Medium):
    1. Day 15–17: 9 remaining High findings (CloudTrail enrichment, GuardDuty alert routing, RDS encryption, EBS volume encryption sweep)
    2. Day 18–21: 19 Medium findings (KMS key rotation, IMDSv2 enforcement, ECR image scanning, RDS deletion protection, etc.)
End of Week 3: 41 of 47 findings closed. Remaining: 6 Medium/Low findings requiring scheduled work (VPC peering cleanup, IAM cross-account audit, etc.) — closed Week 4–6.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

The investor's response (Week 7)

Bachao.AI delivered a closure evidence package to AnalyticsCo:

    1. Original audit report (47 findings)
    2. Closure log (47 findings closed/accepted with rationale)
    3. AWS Config dashboard screenshot showing compliance posture
    4. Updated security policy documents (Acceptable Use, Access Control, Data Classification)
The investor's technical reviewer accepted the package in Week 7. Series B closing condition cleared. Series B closed Week 8.

What it cost

Line itemCost
Bachao.AI AWS audit (multi-account)₹4L
Bachao.AI remediation sprint (2 weeks)₹8L
Bachao.AI evidence package + investor coordination₹2L
AnalyticsCo DevOps lead time (2 weeks intensive)~₹4L opportunity cost
Total cloud security work₹14L direct + 4L internal = ₹18L
AnalyticsCo's CFO calculated the investor diligence delay would have cost ~₹1.5 Cr if the round had slipped a quarter. The ₹18L cleared the path.

What AnalyticsCo's CTO said

"We had 'AWS security' on our to-do list for 8 months. We never had the bandwidth. Bachao came in, found 47 things we didn't know we'd done wrong, and fixed 41 of them in 2 weeks alongside our DevOps lead. The reason it worked: Bachao engineers wrote the actual IAM policy changes and Terraform — they didn't just write a report and walk away. We retained them on a quarterly review cadence after Series B closed."

Pattern this engagement followed

This is a common shape for Bachao.AI cloud security engagements:

  1. Triggering event (investor diligence, SOC 2 audit, customer questionnaire, regulator)
  2. Existing AWS footprint that's grown organically without security review
  3. No dedicated security engineer on the customer side
  4. Time pressure aligning with the audit + remediation
If your team is in a similar place:

Schedule the AWS audit scoping call →


Related: AWS Security Audit Methodology · Cloud Security for Indian Fintech

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Ex-enterprise architect turned cybersecurity founder. Built systems for Fortune 500s, now making enterprise-grade security accessible to every Indian business. Writes about threats targeting Indian SMBs, practical defenses, and the DPDP Act.

Connect on LinkedIn

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

Know your vulnerabilities before attackers do

Free automated scan — risk score in under 2 hours. No credit card required.

Get Your Free VAPT Scan
Find your vulnerabilitiesStart free scan →