Overview
Fresh off the platform rebuild, Lumen & Co faced an enterprise security review as a contract gate. They had good instincts but no evidence: scattered secrets, broad IAM roles, and dependencies nobody had inventoried.
The challenge
Four weeks to close the deal. The audit had to find real issues without derailing the roadmap — and every finding needed a fix, an owner, and a date before the buyer's review.
Approach
Code, dependencies, cloud accounts, and secrets — the map before the mission.
Twenty-three findings triaged into four criticals, not two hundred equal alarms.
Paired remediation with Lumen's engineers — secrets rotation, least-privilege IAM, dependency upgrades.
Deliverables & outcome
- ✓Full audit report with ranked, evidenced findings
- ✓All criticals remediated and re-tested in-engagement
- ✓Secrets management and least-privilege IAM rolled out
- ✓Compliance review passed on the first attempt; deal signed