Skip to main content
    Scalexa — Senior Engineering & AI Solutions
    AWS Security & DevOps

    Legal Legends — AWS Security Hardening & DevOps Stabilisation

    Project Overview

    Legal Legends engaged Scalexa to urgently review and lock down AWS access, reduce risk, and bring clarity to an inherited AWS environment. The work quickly expanded into broader DevOps stabilisation, governance improvements, and ongoing advisory support. This was a live production SaaS platform with multiple historical developers and administrators who had access over time—creating unclear ownership of IAM users, access keys, repositories, and deployment workflows.

    Legal Legends — AWS Security Hardening & DevOps Stabilisation project screenshot

    The Challenge

    Legal Legends had grown organically over time, with various developers and administrators granted access to AWS, Bitbucket, and other infrastructure. As the company evolved, it became unclear which accounts were still needed, which credentials were in use by services, and who actually owned what. The team needed to regain control without breaking production.

    • Numerous IAM users and access keys with unclear ownership or purpose
    • Some accounts had not been used for years, others were still active
    • Risk that credentials might still be in use by internal AWS services or legacy automation
    • No clear policy for deactivating, rotating, or deleting credentials
    • Uncertainty around Bitbucket ownership and deployment control
    • Desire to simplify AWS usage, improve security posture, and reduce unnecessary cost
    • Need for pragmatic advice, not theoretical best practices

    What We Did

    We took a calm, methodical approach to untangling the environment. Rather than making sweeping changes that could disrupt production, we audited, categorised, and then acted incrementally—giving the platform time to surface any dependencies before permanent removal.

    • Performed a full IAM audit: console vs access-key users, last-used timestamps, and scope of permissions
    • Categorised accounts into: active and required, inactive but potentially recoverable, obsolete and safe to retire
    • Recommended and implemented a phased lockdown approach: disable unused access keys, remove console access where no longer required, observe for issues before permanent deletion
    • Established a 30-day decommissioning policy for inactive users
    • Took control of project management and remediation work via Asana
    • Reviewed broader AWS setup and flagged opportunities for simplification, cost reduction, and improved governance
    • Advised on source control and deployment ownership, including Bitbucket access and permissions

    Operating Model

    Rather than a fixed architecture, we established an operating model that would scale with the team and remain clear as personnel changed over time.

    • Cloud platform: AWS with clearly documented infrastructure
    • Identity & access: IAM with defined users, access keys, and console permissions
    • Governance: Usage tracking, last-used reviews, staged deactivation
    • DevOps: Centralised ownership of repositories and deployment flows
    • Project coordination: Asana-based task tracking and prioritisation

    Technical Approach

    Our approach reflected years of experience working with inherited environments. We focused on practical risk reduction rather than over-engineered solutions.

    • Practical IAM audits in live production environments
    • Risk-reduction without service disruption
    • Clear policies for access key rotation and removal
    • Terraform adoption for codifying infrastructure state and preventing configuration drift
    • Calm handling of inherited technical debt
    • Security improvements without over-engineering
    • Advisory input spanning AWS, DevOps, and deployment workflows

    Security and Reliability

    Security hardening in a live environment requires care. We applied a least-privilege mindset incrementally, ensuring each change was observed before the next was made.

    • Least-privilege mindset applied incrementally
    • Controlled deactivation to avoid breaking services
    • Ongoing visibility into access usage
    • Governance patterns that scale as teams change

    Outcomes

    • AWS access significantly tightened and clarified
    • Reduced risk from stale credentials and unknown admin users
    • Clearer ownership of infrastructure and repositories
    • Improved confidence in the platform's security posture
    • Foundation laid for cost optimisation and further simplification

    Why It Matters

    This engagement demonstrated the value of a calm, senior approach to cloud security. Rather than panic or over-react, we methodically reduced risk while keeping production stable. Legal Legends now has a clear picture of their AWS environment, a governance model that will scale, and a foundation for ongoing improvements.

    "The Scalexa team was fantastic, and communicated clearly throughout in what was a high-pressure environment with a strict deadline. They went above and beyond at all opportunities."

    NW
    Nick Watson
    Founder, Legal Legends
    Get Started

    Ready to Get Started?

    Book a free 30-minute discovery session with our senior engineers to identify quick wins and show you what's possible.

    View Our Work