PCI audit ready across 400+ AWS accounts, on deadline, no gaps in firewall coverage
A global fintech leader facing an imminent PCI compliance audit needed to scan cardholder data across 400+ AWS accounts and ensure every in-scope application had adequate firewall protections. Presidio delivered both on deadline, with automated detection and enforcement the company owns going forward.
THE OUTCOME
A global fintech leader facing an imminent PCI compliance audit needed to scan cardholder data across 400+ AWS accounts and ensure every in-scope application had adequate firewall protections. Presidio delivered both on deadline, with automated detection and enforcement the company owns going forward.
HOW THEY GOT THERE
Presidio ran two workstreams in parallel. For cardholder data detection: an automated scanning solution using Amazon Macie with Python Lambda functions pushing to DynamoDB and S3 across every region and account, refreshed by EventBridge every 24 hours. For firewall coverage: WAF Classic policies audited and upgraded to WAFv2, centralized through AWS Firewall Manager with Fortinet managed rule sets.
WHY IT WORKED
Compliance audits against environments this large fail when coverage is inconsistent. Manual processes miss accounts. Firewall policies drift. Presidio automated both detection and enforcement, so the company could prove, not just claim, controls were in place across every account.