AWSCIO BriefingsRetrospectives

CIO Brief: Who Outside Your Company Can Reach Your AWS Resources?

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.

The short version: Companies routinely share cloud resources with vendors and partners. Over time, nobody remembers who has access to what. AWS released a tool in 2019 that answers that question automatically — and it often finds surprises.

Why outside access needs regular review

Vendors change, contracts end, projects finish — but cloud permissions granted to outside parties often stay. Each forgotten grant is a door someone outside your company could use, legitimately or not.

The business impact

  • Data exposure through access granted to former vendors or mistakes.
  • Audit findings when you cannot explain who has access.
  • Contract compliance: you may promise customers that only approved parties can access their data.

Questions to ask your team

  • Which outside companies can access our AWS resources today?
  • Is there a list of approved vendors with cloud access, and does it match reality?
  • How quickly do we remove access when a vendor contract ends?

What good looks like

Automated detection of any resource shared outside the company, a maintained list of approved vendor access, quarterly reviews, and access removed as part of vendor offboarding.

The decision

Ask for a list of every external party with access to your cloud environment. If it takes more than a day to produce, automated analysis should be your next step.

iam access analyzer impactIAM Access Analyzer2019

More on this story