VeUP
← All case studies
Security Competency · Control Tower Audit Readiness
An AI meeting-intelligence SaaS companyIdentity protected

CLIPr: remediating a 13-account Control Tower landing zone for a clean security audit

Well-Architected ReviewLanding zone remediationPreventive controlsMulti-account segmentationCentralized workforce identityCentralized immutable audit loggingAudit-readiness evidence packDay-2 runbooks & team enablementHigh-risk-issue remediation roadmapResilience-gap assessment (RTO/RPO)Observability-gap assessmentAdvisory
13/13
accounts validated and governed in Control Tower
Audit-ready
complete evidence set for the third-party audit
Built to carry
SOC 2, PCI-DSS, and HIPAA work ahead
AWS Control TowerAWS Security HubCloudTrailIAM Identity Center

Shared anonymously — the customer’s name is held by VeUP and available on request.

VeUP remediated the customer's drifted AWS Control Tower landing zone across a 13-account AWS Organization — enabling Security Hub org-wide (FSBP + CIS), fixing CloudTrail logging, reconciling IAM Identity Center, and validating every account enrollment — to make the platform audit-ready ahead of a third-party security audit.

The challenge

The customer was preparing for a third-party security audit, but its AWS foundation was not ready. It ran a 13-account AWS Organization on a Control Tower landing zone (v4.0) that had drifted badly — the customer had at one point deleted and re-established the foundation — leaving accounts in an inconsistent governance state. A hands-on assessment in early March 2026 surfaced gaps across the org: incomplete org-wide security monitoring, CloudTrail logging gaps, drifted account enrollments, and inconsistent guardrails. The customer needed a partner to remediate its governance baseline so it could pass the audit cleanly and lay a foundation for later SOC 2 / PCI-DSS / HIPAA work.

The solution

A Phase 1 Control Tower Audit-Readiness engagement across three workstreams, built on the March 2026 hands-on assessment. (1) Security and compliance remediation — enabled AWS Security Hub organization-wide against AWS Foundational Security Best Practices (FSBP) and CIS, remediated CloudTrail logging coverage, reconciled IAM Identity Center, and hardened guardrails and Service Control Policies (SCPs) across the Organization. (2) Infrastructure validation and governance — cleaned up the Organizational Unit structure, validated all 13 member-account enrollments in Control Tower, verified AWS Config recording in every member account, deployed organization-wide AWS Backup policies, and checked StackSet drift. A from-scratch rebuild of the landing zone was considered and rejected: the assessment showed the existing foundation could be completed and trusted. (3) Compliance documentation and knowledge transfer — VeUP left the team with architecture diagrams, a compliance control mapping, an access-governance matrix, and a Security Hub posture baseline, then walked them through all of it.

Production outcomes

KPIResult
Production outcomesAll 13 accounts now sit enrolled and governed in Control Tower, with Security Hub watching the whole organization against FSBP and CIS and Config recording checked account by account. Org-wide AWS Backup policies and hardened SCP guardrails round out the baseline, and the customer walked into its third-party audit with a complete documentation set — architecture diagrams, control mapping, access-governance matrix, Security Hub posture baseline — and a governance foundation built to carry SOC 2, PCI-DSS, and HIPAA work later.
Engagement windowA hands-on assessment in early March 2026 turned into a signed engagement within days. Phase 1 remediation, validation, and documentation are delivered, and the work continues.
Cost / TCO postureRemediation worked with the existing Control Tower control plane throughout — completing and hardening it rather than rebuilding — keeping rework, and cost, to a minimum.
Lessons & continuationA drifted Control Tower landing zone does not automatically mean a rebuild — a hands-on drift assessment shows which controls can be trusted and which must be re-established, so the remediate-or-rebuild call is made on evidence. Account-by-account validation of Config recording and enrollment is what makes "13 accounts governed" an auditable claim rather than an assumption.
AWS services in production
AWS Control TowerAWS Security Hub (FSBP + CIS)AWS CloudTrailAWS IAM Identity CenterAWS ConfigAWS BackupAWS OrganizationsSCP guardrails

Architecture

From the drifted landing zone to the remediated, audit-ready governance baseline across the 13-account organization.

The remediated governance baseline

Target state on AWS: remediated Control Tower landing zone v4.0, with Security Hub, GuardDuty, Config, CloudTrail, IAM Identity Center, KMS, and org-wide Backup governing all 13 accounts around the serverless production workload.
The landing zone remediated end to end — all 13 accounts governed, watched, and backed up.

Where it started

Assessed baseline · landing-zone assessmentAI meeting-intelligence SaaS · AWS Organization — 13 accounts · assessed March 2026
Starting point
13 accounts, inconsistently governed

Management, production, audit, and ten further member accounts under Control Tower v4.0 — IN_SYNC at assessment, with two stale OUs left undecommissioned.

Gap
Detection switched off

Security Hub not enabled in any region, and the organization CloudTrail existed but was not recording.

Gap
Partial guardrails

AWS Config recording in the management account only; 21 SCP controls plus 2 custom — partial coverage, with StackSet drift unchecked.

Gap
No org-wide backup policy

AWS Backup had no organization-wide policies configured.

Starting point
Ad hoc networking

No Transit Gateway or centralized networking — VPC peering arranged case by case.

The baseline as assessed by a hands-on landing-zone assessment of the live AWS Organization.