AWS's shared responsibility model means the misconfigurations are on you — and they're common.
AWS secures the infrastructure; you secure what you build on top of it. That's where most real-world AWS breaches happen: a public S3 bucket, a security group left open to the internet, a management console or database port that should never have been internet-facing. A generic network scan won't catch most of this — it takes someone who knows AWS's service landscape testing your external footprint directly. That's what this engagement does.