Connect an AWS account (cloud feed)
A one-click, read-only CloudFormation template — no agents, nothing installed on servers.
- 1In the portal, go to the Connections page (portal sidebar) and click Connect next to AWS.
- 2You'll be taken to the AWS CloudFormation console (log into the AWS account you want monitored) with our template pre-loaded. Review it — it creates one IAM role with AWS-managed read-only permissions and a trust policy that lets Cybermatic assume it. It cannot change, delete, or create anything in your account.
- 3Check the acknowledgment box and click Create stack. It finishes in about a minute.
- 4Copy the Role ARN: on the stack's Resources tab (CloudFormation → Stacks → CybermaticAccess → Resources), click CybermaticReadOnly under Physical ID and copy the ARN from the role page.
- 5Paste the Role ARN into the Cybermatic portal and click Connect. Your first scan starts immediately — assets and findings appear on the Assets and Risk Analysis pages within a few minutes.
- 6Need a fresh scan later? Press Scan now (on the Assets page or in the Connections page (portal sidebar)). Your first scan is always available instantly; after that, Scan now follows your plan's schedule.
Tip: Have multiple AWS accounts (prod, dev, billing)? Connect each one — risks in forgotten dev accounts are one of the most common findings.