Skip to main content
Back
Customer story
DateRead1 min

Veterinary Service Provider Cuts AWS Attack Surface by 70%

About

A veterinary service provider used Native to enforce least privilege through AWS-native controls across 100+ locations, blocking hundreds of destructive actions and cutting its attack surface by more than 70% with no workload disruption.

Challenge

The veterinary service provider runs 24-hour emergency pet care across more than 100 locations, handling billing and patient information across its national footprint, which carries real regulatory and operational risk. A small security and platform team owned cloud security alongside many unrelated responsibilities, which pushed them into reacting to issues one at a time instead of reducing attack surface and setting safe baselines for new service adoption.

Solution

The veterinary service provider expresses its least-privilege requirements as plain-language intent, and Native compiles them into AWS-native controls (SCPs and RCPs) across the organization: blocking usage of unused AWS services to reduce attack surface, and requiring security reviews for new services so applications leverage secure-by-design controls. Native reads real usage patterns from CloudTrail (combined with Resource Manager and Billing API activity) to simulate every policy against historical activity before enforcing, so no identity that legitimately needs access is caught by surprise. Enforcement runs through AWS Organizations with a managed rollout that follows the org tree from test to staging to production, and CloudWatch, CloudTrail, and SNS close the loop by showing both security teams and developers exactly which actions a policy blocked and why.

Results
reduction in attack surface by restricting cloud usage to approved services and regions
70%+
of attempts to create resources in unapproved locations or perform destructive actions were prevented outright
Hundreds

INDUSTRY: Veterinary emergency healthcare

REGION: United States (100+ locations)

NATIVE PLATFORM: Organization Intelligence, Intent Translation, Impact Simulation, Integrated Enforcement Feedback, Exception Management

USE CASES: Built-In Prevention, Secure cloud services adoption, least privilege enforcement, AI guardrails

CLOUD PLATFORM: AWS

AWS SERVICES: AWS Organizations (SCPs, RCPs), IAM, CloudTrail, CloudWatch, SNS

Lessons Learned

Simulating against real historical CloudTrail activity before enforcing avoided surprising any identity that legitimately needed access. Rolling out along the organizational tree (test to staging to production) with full visibility into every blocked action and a clean exception path is what gave a stretched team the confidence to enforce in production.


Ready to enforce secure-by-design?