• Blogs
  • Improving AWS Security Governance for EHS Tools

Improving AWS Security Governance for EHS Tools

18th May Case Study Posts (1)
Case Studies calender-icon Jun 11, 2026
ACE ID: 617734733590
Industry: Oil & Gas Industry
Country: Malaysia

Executive Summary

EHS Tools is a Malaysia-based technology provider serving customers in the oil and gas and energy sector through business-critical applications hosted on AWS. As part of its growth strategy and commitment to ISO 27001-aligned security practices, EHS Tools engaged Atomic Computing to assess and strengthen the security posture of its AWS environment.

The engagement began with a comprehensive AWS Well-Architected Framework Review (WAFR), which identified several security, governance, and operational risks, including excessive administrative access, long-lived credentials, public infrastructure exposure, limited environment isolation, and inconsistent access management practices.

Atomic Computing designed and implemented a security-focused modernization program that improved identity governance, reduced attack surface, strengthened infrastructure security, enhanced developer access controls, and established long-term governance standards. The engagement also delivered significant operational and financial benefits, including an estimated 35–45% reduction in monthly AWS costs while improving overall security posture and audit readiness.

Customer Overview

EHS Tools provides digital solutions and operational tooling for organizations in the oil and gas and energy industry. The company’s platform supports business-critical workloads and serves enterprise customers primarily within Malaysia.

The AWS environment consisted of multiple AWS accounts supporting development and production workloads, Amazon ECS clusters, Amazon EC2 instances, Amazon RDS databases, Amazon S3 storage, and supporting cloud-native services. As the platform expanded, EHS Tools required a more structured approach to security, governance, and operational management.

Business Challenge

Atomic Computing’s engagement began with an AWS Well-Architected Framework Review (WAFR) focused on security, operational excellence, and governance.

The review identified approximately 33 high-risk issues across the environment, including:

  • Excessive administrative privileges across engineering teams
  • Long-lived IAM access keys and credential sprawl
  • Human access managed through both IAM users and IAM Identity Center
  • Shared SSH keys and direct server access
  • Publicly accessible infrastructure components
  • Developers with broad access to production resources
  • Limited separation between development and production environments
  • Inconsistent identity and access management practices
  • Lack of standardized governance controls and onboarding processes
  • Opportunities to improve encryption, monitoring, and audit readiness

The customer required a solution that would improve security while maintaining developer productivity and supporting future growth.

Solution Architecture

Identity and Access Governance

Atomic Computing redesigned the customer’s identity and access model to align with AWS security best practices and least-privilege principles.

AWS IAM Identity Center was standardized as the primary method for workforce access, replacing reliance on direct IAM user access. Permission sets were redesigned and aligned with job responsibilities, administrative access was reduced, and MFA enforcement was standardized across the organization.

Custom Service Control Policies (SCPs) were implemented through AWS Organizations to reduce administrative blast radius and restrict access to approved AWS services. Prefix-based and tag-based governance models were also introduced to improve consistency and scalability across environments.

As a result, administrative access was reduced from six users to two, approximately six active access keys were removed, and human access was centralized through Identity Center.

Secure Developer Access

A major objective of the engagement was to modernize developer access while reducing exposure to common attack vectors.

Atomic Computing replaced traditional VPN and SSH-based access methods with AWS Systems Manager Session Manager. Shared SSH keys were eliminated, inbound port 22 access was closed, and secure Session Manager-based access workflows were implemented for developers.

Database access was further secured using Session Manager port forwarding, allowing engineers to connect to private RDS instances without exposing database endpoints publicly.

This approach reduced attack surface, simplified access management, and eliminated the operational burden associated with managing VPN infrastructure and SSH credentials.

Multi-Account Security Architecture

To improve isolation and governance, Atomic Computing helped restructure the AWS environment using a multi-account strategy.

Development and production workloads were separated into dedicated AWS accounts, reducing risk associated with shared environments and aligning the architecture more closely with AWS Security Reference Architecture recommendations.

Cross-account IAM role architecture was implemented to support secure workload communication and administrative operations while maintaining clear security boundaries. Human access was centralized through IAM Identity Center, reducing reliance on local account identities and simplifying governance.

Infrastructure Governance and Automation

Atomic Computing established a governance framework designed to improve consistency, reduce configuration drift, and support future scalability.

The framework included:

  • Standardized naming conventions
  • Mandatory environment tagging
  • Prefix-based governance controls
  • Terraform deployment standards
  • Environment-specific access controls
  • Standardized onboarding procedures for users and workloads

These controls provided a repeatable model for securely deploying and managing infrastructure across multiple AWS accounts.

Secure CI/CD and Container Security

As part of the ongoing engagement, Atomic Computing also worked with EHS Tools to strengthen software delivery security.

Security controls were introduced into CI/CD workflows, including container image scanning, code quality validation through linting, and vulnerability assessment capabilities within Amazon ECR.

These enhancements introduced shift-left security practices into the software delivery lifecycle and improved visibility into application security risks before deployment to production environments.

AWS Services Used

The engagement leveraged several AWS-native security and governance services, including:

  • AWS Organizations
  • AWS IAM Identity Center
  • AWS Identity and Access Management (IAM)
  • AWS Systems Manager Session Manager
  • AWS CloudTrail
  • AWS Access Analyzer
  • AWS Key Management Service (KMS)
  • AWS Secrets Manager
  • AWS Security Hub
  • AWS Config
  • Amazon EC2
  • Amazon ECS
  • Amazon RDS
  • Amazon S3
  • Amazon ECR
  • Amazon CloudWatch
  • AWS Well-Architected Tool

People and Process Transformation

In addition to technical implementation, Atomic Computing worked closely with the EHS Tools engineering team to improve security processes and operational practices.

Multiple security review workshops were conducted to review findings, prioritize remediation activities, and align stakeholders on implementation priorities.

New onboarding standards were introduced for both workforce identities and machine identities. Human access is now provisioned through IAM Identity Center using standardized permission sets, while workloads are encouraged to use IAM roles instead of long-lived credentials.

The engagement also introduced governance standards covering infrastructure deployment, tagging, access management, and environment separation, helping establish a more sustainable operating model.

Results and Business Outcomes

The engagement delivered measurable improvements across security, governance, operational efficiency, and cost optimization.

Security Improvements

  • Administrative users reduced from six to two
  • Approximately six long-lived access keys removed
  • Shared SSH key usage eliminated
  • Direct SSH access removed from workloads
  • Human access centralized through IAM Identity Center
  • Improved production and development environment isolation
  • Reduced attack surface through Session Manager adoption
  • Improved audit readiness supporting ISO 27001 objectives

Well-Architected Outcomes

  • Approximately 33 high-risk issues identified during the WAFR
  • More than 65% of identified findings remediated during the engagement
  • Ongoing remediation tracking process established

Governance Improvements

  • Standardized IAM governance model implemented
  • SCP-based guardrails introduced
  • Multi-account security architecture strengthened
  • Terraform governance standards established
  • Standardized onboarding processes introduced

Operational Benefits

  • VPN infrastructure eliminated
  • Simplified developer access workflows
  • Reduced operational overhead associated with access management
  • Improved consistency across AWS environments

TCO Analysis

As part of the engagement, Atomic Computing conducted a Total Cost of Ownership (TCO) assessment alongside the Well-Architected review.

The assessment identified opportunities to improve infrastructure efficiency while strengthening security controls. Recommendations included infrastructure optimization, storage governance improvements, elimination of VPN-related costs, and improved operational practices.

Prior to the engagement, AWS spend averaged approximately $1,100 USD per month. Following implementation of the recommended security, governance, and optimization initiatives, projected monthly AWS spend was reduced to approximately $700 USD per month.

This represented an estimated cost reduction of approximately 35–45% while simultaneously improving the security posture and operational maturity of the environment.

Lessons Learned

The engagement reinforced several important lessons regarding cloud security and governance.

Early implementation of centralized identity governance significantly reduces long-term security and operational risk. Eliminating long-lived credentials and shared SSH access can dramatically reduce attack surface while improving auditability. Secure access solutions such as Session Manager can improve both security and operational efficiency. Finally, multi-account governance, standardized infrastructure controls, and structured Well-Architected reviews provide a strong foundation for long-term security success.

Conclusion

Through a security-first modernization initiative, Atomic Computing helped EHS Tools transform its AWS security posture, improve governance, modernize developer access, strengthen environment isolation, and establish a scalable operating model aligned with AWS best practices.

The engagement demonstrates how a structured approach combining technical remediation, governance transformation, and process improvement can significantly reduce risk while improving operational efficiency, developer productivity, and overall business outcomes.