Cloud bills rarely grow because of one big mistake. They grow through a handful of small defaults that nobody revisits. The same issues show up in account after account. Here is where to look first.
Before you start: open Cost Explorer and group the last three months by service, then by usage type. The usage type view shows exactly what you are paying for (hours, gigabytes processed, gigabytes stored), which makes most of the items below easy to spot.
1. NAT gateways processing traffic that could go around them
A NAT gateway charges by the hour and for every gigabyte it processes. A common pattern is private workloads pulling large amounts of data from S3 or DynamoDB through the NAT gateway. Gateway VPC endpoints for S3 and DynamoDB route that traffic privately at no charge, and often remove the largest line on the bill in one change.
2. Idle and oversized compute
Instances and databases are often sized for a launch-day guess and never revisited. Look at a month of CPU and memory usage. Anything consistently low is a candidate for a smaller size, and ARM-based (Graviton) instance types are usually cheaper for the same work when your software supports them.
3. Unattached volumes and forgotten snapshots
Terminating an instance does not always delete its disks, and automated snapshots pile up for years. Both keep billing quietly. List volumes in the available state and snapshots older than your retention policy, confirm nothing depends on them, and delete them.
4. Older volume types
EBS gp3 volumes cost less per gigabyte than gp2 and include a baseline of IOPS and throughput that is independent of size. For most workloads, switching is an online change with no downtime.
5. Logs that never expire
CloudWatch log groups keep data forever by default, and debug-level logging left on in production multiplies the volume. Set a retention period on every log group, and check which applications are the noisiest.
6. Non-production running around the clock
Development and test environments typically run 168 hours a week and get used for maybe 50. Scheduling them to stop overnight and at weekends, or scaling them to zero, cuts their cost dramatically.
7. Data transfer you did not plan for
Traffic between availability zones, and traffic out to the internet, are both billed per gigabyte. Chatty services spread across zones, or large downloads served directly from origin servers, add up. Keeping chatty components together and putting a CDN in front of public content both help.
8. Paying on-demand prices for steady usage
If a workload runs all day, every day, paying the on-demand rate is paying for flexibility you do not use. Savings Plans and reservations trade a one- or three-year commitment for a lower rate. Fix items 1 to 7 first, then commit to what remains.
Keep it from creeping back
- Tag everything by product, team and environment, and enforce it in your infrastructure code.
- Set budgets with alerts so an unexpected jump shows up in days, not at month end.
- Review the bill monthly, grouped by usage type, as a standing fifteen-minute habit.
Want someone to go through your account line by line? That is exactly what our cloud cost and security review does, or try the free self-assessment first.