back_to_insights

// CASE STUDY · CLOUD EXCELLENCE

Remediating an existing cloud platform for a global media organisation

A global media organisation with one of the world’s largest cloud bills had let its internal platforms grow unsupervised. We reviewed three critical services, raised over 200 observations, and led the remediation.

IMAGE: PHOTO BY TAYLOR VICK ON UNSPLASH

A global media organisation with one of the world’s highest cloud bills had asked its existing supply chain to build the platforms behind its major internal services. Mature cloud standards existed in the organisation, but the attention had gone to customer-facing digital products. Internal infrastructure had been built largely unsupervised.

With infrastructure cost reduction a board-level priority and major new services about to launch, we were asked to review those implementations: did they follow good practice, and were they fit to host business-critical services?

// WHAT WE DIDA detailed implementation review

We reviewed the existing cloud platforms behind three critical internal services against three reference points: industry good practice, the AWS Well-Architected Framework, and the client’s own architecture and security policies.

Alongside the manual review, we ran a toolchain across the estate so the findings were evidenced rather than asserted.

Security monitoring and compliance
Prisma Cloud, AWS Security Hub, AWS GuardDuty.
Cost optimisation
The client’s internal cloud cost efficiency tool, AWS Cost Explorer, volumetric models.
Security guardrails
AWS Service Control Policies (preventative), AWS Config Rules (detective).
Good practice review
Cloud build standards (CI/CD, IaC), architectural patterns for immutability, auto-scaling and self-healing.
Resilience and recovery
Landing zone and vending automation, AWS Backup (BCDR review), AWS Well-Architected Review across all six pillars.

We presented the findings back to the client, then took responsibility for driving the remediation with the resolver groups involved — including the client’s own supply chain partners.

// WHAT WE FOUNDOver 200 observations

The review raised more than 200 observations. They ranged from material architectural considerations and cost optimisation opportunities through to high-priority security vulnerabilities at a detailed technical level — open ports on the internet, missing encryption.

The central finding was structural. The platforms had been built from manually created images, with no elasticity and no infrastructure-as-code for rapid environment deployment. Without auto-scaling, compute had been vastly over-provisioned — and the DR estate over-provisioned at the same rate, doubling the waste.

Compounding it, there were no clear retention policies for snapshots and images, and disk IOPS had been over-specified. Cost was accumulating in places nobody was looking.

"Over-provisioned compute, mirrored faithfully into an over-provisioned DR estate. The inefficiency had been paid for twice."

// RESULTSWhat remediation delivered

The review completed in October 2022. The figures below are the position a month later, with the remainder of the programme in flight.

Security
A significant proportion of issues remediated, including open ports on the internet — down from 195 to 24 outstanding.
Cost optimisation
Annual cost reduced by around 25% through deleting redundant images and snapshots and configuring AWS agents, with a plan to reach 50%.
Standards compliance
Over 5,000 AWS resources identified as non-compliant with client policies, with remediation underway; 30% of Well-Architected findings already closed.
Infrastructure-as-code
Patterns and an implementation approach for immutable, version-controlled image builds agreed with the third party and scheduled — the route to auto-scaling and to removing the costly DR provision.
Ransomware mitigation
Patterns to safeguard backups and key material against insider threat vectors provided and prioritised for implementation.

The cost reduction is worth reading carefully: it was achieved before infrastructure-as-code and auto-scaling landed. The structural fix was still ahead of it.

// BEYOND THE REVIEWNew standards for the organisation

As well as identifying issues, we proposed new backup patterns to protect against ransomware and cypher-shredding attacks. The client adopted them as the organisation’s standard going forward — so the work outlived the three services it started on.

"The differentiator was the breadth and depth of knowledge of AWS services the Axiologik team demonstrated, providing the client with advice on building highly secure, scalable, cloud-native services on AWS using best practice. This thought leadership was instrumental to remediating numerous high impact concerns."

— GLOBAL AWS ACCOUNT LEAD FOR THE CLIENT

// THE LESSONStandards are not the same as compliance

This organisation had good cloud standards. What it lacked was supervision of the platforms nobody was watching — the internal ones, built by partners, hosting services that would soon be critical.

An independent review is the cheapest way to find that out. It is considerably cheaper than discovering it from an incident, or from the invoice.

// PRODUCT · AWS WELL-ARCHITECTED FRAMEWORK REVIEW

The same framework, applied to your estate.

Our cloud maturity assessment is built around the AWS Well-Architected Framework Review — the structured, expert-led evaluation we used on this engagement. It runs in four hours, at no cost to you.

You get your workloads assessed against all six pillars, the high-risk findings called out plainly, and a prioritised improvement plan. Where it makes sense, we go further — the deeper security, cost and standards review this case study describes, and the leadership to see the remediation through.

THE SIX PILLARS WE ASSESS

01
Operational excellence

How you run and observe workloads, and how you improve them.

02
Security

Guardrails, identity, encryption and what is currently getting past them.

03
Reliability

Elasticity, self-healing and whether recovery has ever been proven.

04
Performance efficiency

Right service choices, scaling strategy and where the design is fighting you.

05
Cost optimisation

Over-provisioning, retention, storage tiers and data transfer.

06
Sustainability

Efficient resource use, and the waste that scaling patterns hide.

// LET'S TALK

Ready to talk about your challenge?

However complex your estate, we'll help you get more from cloud — cost, performance and pace. Start with a conversation.