Cloud Cost and Posture
What is running, what it costs, and what is exposed. These turn out to be one question.
Cloud estates do not get expensive through one bad decision. They get expensive through an absence of ownership: resources nobody turned off, sizing chosen on launch day and never revisited, and architectures that made sense at a tenth of the current scale. Every one of those is also a security finding, because a resource nobody can account for is not being patched or monitored either.
Doing cost and posture as one engagement is not a bundle. It is that both answers come from the same inventory, and building that inventory is most of the work.
What this covers
What is actually running
A real inventory across accounts and subscriptions, including the things provisioned by people who have since left. This is the step that gets skipped and the step everything else depends on.
What nothing is using
Established from production traffic and logs rather than from what anybody believes. The cheapest security work available is turning off what is not needed, and it happens to be the cheapest cost work too.
Sizing and shape
What was sized for launch day, what has grown past its architecture, and where the spend is buying headroom nobody uses.
Exposure
What is reachable from the internet and whether it should be, identity and key material in the estate, storage that is more public than anybody realizes, and the network paths that exist because something needed to work quickly.
The shared responsibility line
Which controls are yours and which are the provider’s, stated explicitly. A provider’s compliance certificate covers the provider, not your configuration of it.
Keeping it from happening again
Tagging and ownership, budget alerting that reaches somebody who can act, and a review cadence. Without these the estate returns to its current state in about a year.
This is not a rate negotiation and it is not a licensing audit. Committed-use discounts are worth having and your account team will sell them to you without my help. The money here is in what should not be running at all.
What usually brings people here
The cloud bill is growing faster than the business and nobody can say why.
An audit or a customer has asked what is exposed and the answer took a week to assemble.
The people who provisioned the estate have left.
You are about to model costs at a much larger scale and would rather not extrapolate from a number containing waste.
How the engagement runs
Fixed-price with a defined scope and an end date. The output is the inventory, a prioritized list of what to turn off, resize or re-architect with the saving attached to each, and the exposure findings with the same treatment.
The changes themselves can be done by your team from that plan, or by me, and it is worth deciding which before starting.
This sits inside the fractional CTO side of the practice. If what you need is ongoing ownership rather than a defined piece of work, start there instead.
Questions I get asked first
Why cost and security in one engagement?
Because they are the same inventory problem. The resource nobody can account for is both a line on the bill and an unpatched, unmonitored thing with an address. Doing the two separately means building the same picture of the estate twice and acting on it once.
Is this a negotiation with our cloud provider?
No. Committed-use discounts are worth having and your account team will sell them to you without my help. The money is in what is running that should not be, what was sized on launch day and never revisited, and what made sense at a tenth of the current scale.
Will this break something in production?
Not if it is done in the right order. What is genuinely in use is established from production traffic and logs rather than from what people believe, and things are retired with a way back. The alternative, which is leaving everything on because nobody is sure, is how estates reach this state.
Do we need to be on a particular cloud?
No. The shape of the problem is the same everywhere: unowned inventory, sizing set once, and architectures that outgrew their assumptions.
Written on this
Start with a conversation
Tell me what’s going on. If this is the right piece of work I will scope it. If it is not, I will say what is.
Bring your architecture problem, stalled project, cloud bill, or diligence deadline.
Not ready for a call? Send a message instead.
For companies looking to engage BATO. Vendors, please email.