The biggest security hole for every organisation is its remote work from home workers. I'd be interested to hear how this Monzo bank addresses the problem of someone walking in the home of one of their programmers and lifting access keys to AWS whilst that person is at the supermarket, and leaving with no-one the wiser. Or installing a keylogger USB device onto their keyboard cable.
If you have AWS keys on staff laptops at home, you've already failed.
We don't allow any code at all on local machines.