Case Study

Valpak Closes a Ten-Account Vulnerability Gap with ATG Managed Services

Challenge

Valpak runs consumer-facing and analytics workloads, including Clipp.com and mylocalinsights.ai, across ten AWS accounts. These workloads run on a mix of EC2 instances, container images, serverless functions, and application source code. Without continuous vulnerability assessment across all of those layers, Valpak had limited visibility into risk in its running workloads and no reliable way to catch vulnerabilities before they reached production through the build pipeline. Valpak needed to secure and stabilize its AWS environment so its internal team could focus on higher-value work.

Solution

Aligned Technology Group onboarded Valpak onto its managed services program. ATG then deployed continuous, cross-layer vulnerability assessment across Valpak’s ten-account, SRA-aligned AWS organization. The solution extends coverage from source code through to running workloads. It adds automated patching and layered threat detection, plus a self-service dashboard that gives Valpak’s leadership direct visibility into spend and security. By relying on AWS-native tooling instead of third-party products, ATG met Valpak’s security requirements at lower cost and with no additional agents to deploy or manage.

Key Components

  • Enabled Amazon Inspector across all five supported resource types (EC2, ECR, Lambda, Lambda code, and connected code repositories) for unbroken assessment from source code to runtime
  • Deployed AWS Security Hub with Foundational Security Best Practices and CIS standards, alongside Amazon GuardDuty for threat detection
  • Established a 25-rule AWS Config baseline and 8 preventive service control policies across the organization
  • Automated server patching using AWS Systems Manager
  • Protected the public Clipp.com platform with AWS WAF
  • Configured 15 CIS metric-filter alarms in Amazon CloudWatch for detective controls
  • Used ATG Ignite to track Inspector coverage per account and correlate findings into attack-path chains, so remediation is prioritized by exploitability
  • Delivered a login-protected spend-and-security dashboard for leadership self-service visibility
  • Provided ongoing 24/7 managed operations, monitoring, backups, and FinOps oversight

AWS Services Used

  • Amazon Inspector – Continuous vulnerability assessment from code to runtime
  • AWS Security Hub – Centralized security findings and compliance standards
  • Amazon GuardDuty – Intelligent threat detection
  • AWS Config – Configuration management and compliance tracking
  • AWS Systems Manager – Automated patching and operations management
  • AWS WAF – Web application protection
  • AWS CloudTrail – Audit logging and activity monitoring
  • AWS Organizations – Multi-account governance and service control policies
  • AWS Backup – Backup and disaster recovery management
  • Amazon CloudWatch – Monitoring, alarms, and observability
  • AWS KMS – Encryption key management

Business Outcomes

  • Unbroken vulnerability assessment across all five Amazon Inspector resource types, from connected code repositories to running workloads
  • 21 of 23 running EC2 instances brought under automated patching with AWS Systems Manager
  • Two compliance standards (FSBP and CIS) evaluated continuously across ten accounts
  • Stronger preventive and detective controls through 8 SCPs and 15 CIS alarms
  • Public consumer platform protected by AWS WAF
  • Self-service leadership visibility into spend and security through a dedicated dashboard
  • Lower security tooling costs by using AWS-native services instead of third-party products

Strategic Impact

By partnering with ATG for managed services, Valpak moved from inconsistent, layer-by-layer vulnerability checks to continuous, organization-wide assessment backed by automated patching and layered detection. ATG’s operating experience turns a large volume of findings into a prioritized remediation cadence that Valpak’s team can act on. Alerting is tuned to separate real issues from routine autoscaling and staging noise. The result is a more secure, stable AWS foundation that frees Valpak’s internal team to focus on the business, with leadership keeping clear, self-service visibility into the environment.

Powered by AWS Partnership

AWS Badge

Time to Get Sh*t Done

Cut the noise. Keep the results.