Earlier quoted context omitted.
I prepared so much for our audit and the only thing this guy cared for in a 5 developer company was the fact that I had root access on all environments. He didn't care about Aws having 2fa configured about our vlan ipsec Tunnel, etc I even took the liberty to fix the md5 Passwort shit with bcrypt just before the audit...
That guy is completely right. I wouldn’t look at anything else either as that is already the security worst case scenario.
Are you serious?
What would be your suggestion then?