UPDATED 09:00 EDT / JULY 30 2025

SECURITY

ZEST Security adds AWS Service Control Policies to expand cloud risk mitigation

Cloud risk resolution platform startup ZEST Security Inc. today announced the addition of Amazon Web Services Service Control Policies as part of its exposure resolution offering to allow security teams to proactively block attacker activity.

ZEST claims the new integration is a first, saying that until now, no solution has fully operationalized SCPs as a mitigation pathway within a broader cloud vulnerability and exposure management program. ZEST Security turns SCPs into an active defense that security teams can instantly enforce to reduce cloud exposure.

AWS SCPs are a type of organization-wide policy in AWS that defines the maximum available permissions for accounts within an AWS organization. SCPs allow administrators to restrict or govern access to AWS services and actions, ensuring accounts only perform approved operations, regardless of the permissions granted in individual identity access management roles or users.

ZEST Security’s mitigation pathways, now including AWS SCPs, offer a fast and reliable way to mitigate exposure, prevent exploitation and disrupt attacks at every stage, without waiting for patches, code changes or other teams to deliver full remediation.

The integration mobilizes SCPs as a mitigation pathway to allow security teams to block common and advanced attack techniques by controlling access to sensitive resources, encryption settings and public exposure. Doing so reduces the risk of exploitation and helps prevent key attack stages such as reconnaissance, privilege escalation, and data encryption.

The ZEST platform leverages artificial intelligence agents to map vulnerabilities and misconfigurations identified by cloud security posture management and vulnerability management solutions to remediation and mitigation pathways. ZEST’s resolution engine then analyzes all available options including code and infrastructure as code fixes, patches, upgrades, policies and cloud guardrails to identify the most direct and impactful path to reduce cloud exposure at scale, even in scenarios when remediation isn’t immediately possible.

The company says that though the SCPs represent its latest mitigation pathway, the company also provides a broader mitigation offering. It mobilizes other controls and services such as web application firewalls, virtual private cloud and GuardDuty to harden configurations, enforce stricter policies and create customized protection rules when code changes or upgrades aren’t possible.

ZEST Security is a venture capital-backed startup that has raised a single round of $5 million in July 2024. Investors in the company include Hanaco Venture Capital Ltd. and Silvertech Ventures LP.

Image: ZEST Security

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.