CIO Brief: Who Outside Your Company Can Reach Your AWS Resources?
Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.
The short version: Companies routinely share cloud resources with vendors and partners. Over time, nobody remembers who has access to what. AWS released a tool in 2019 that answers that question automatically — and it often finds surprises.
Why outside access needs regular review
Vendors change, contracts end, projects finish — but cloud permissions granted to outside parties often stay. Each forgotten grant is a door someone outside your company could use, legitimately or not.
The business impact
- Data exposure through access granted to former vendors or mistakes.
- Audit findings when you cannot explain who has access.
- Contract compliance: you may promise customers that only approved parties can access their data.
Questions to ask your team
- Which outside companies can access our AWS resources today?
- Is there a list of approved vendors with cloud access, and does it match reality?
- How quickly do we remove access when a vendor contract ends?
What good looks like
Automated detection of any resource shared outside the company, a maintained list of approved vendor access, quarterly reviews, and access removed as part of vendor offboarding.
The decision
Ask for a list of every external party with access to your cloud environment. If it takes more than a day to produce, automated analysis should be your next step.
- IAM Access Analyzer Launches (Dec 2019): Finding Unintended Public and Cross-Account Access Platform Changes
- How to Use IAM Access Analyzer to Find Unused and External Access How-To & Hardening
- Quarterly External Access Review Checklist for AWS How-To & Hardening