Case Studies | SaaS B2B

Hardening a live AWS workload with a Well-Architected Review

Well Architected Review

About

A SaaS B2B business working with Cloud Combinator on AWS. The client is anonymised at their request.

Challenge

The review surfaced findings across four focus areas, each of which became a workstream in the remediation plan.

Security posture

Access to the environment relied on IP whitelisting rather than a managed VPN, multi-factor authentication was not enforced, and core AWS security tooling was not yet in place. These gaps widened the attack surface and made access harder to control as the team grew.

Backup and recovery

Backups existed but restoration had not been tested end to end, so there was no proven, timed path to recover the workload if something went wrong. Reliable recovery needed to be demonstrated, not assumed.

Cost visibility

There were no budgets, alerts or tagging strategy in place, which made it difficult to attribute and monitor spend across the environment as usage scaled.

Operational governance

The workload lacked a documented set of operational and security policies, and a clear view of responsibilities between the client and Cloud Combinator, both of which are needed to run a platform reliably over time.

Solution

£4,050

AWS credits returned, reducing the client's net cost to £130

8

High-priority remediation actions agreed and actioned

84%

Of the agreed remediation plan completed

By the numbers:

  • £4,050 - AWS credits returned, reducing the client's net cost to £130
  • 8 - High-priority remediation actions agreed and actioned
  • 84% - Of the agreed remediation plan completed
Changes

All the priority actions agreed from the review were delivered, with the bulk of the remediation plan completed. The workload moved from an ad hoc security and operations posture to one built on AWS best practice.

  • Security hardenedA managed VPN connection replaced IP whitelisting, MFA was enforced, and a password storage and credential key-rotation policy were introduced. AWS Security Hub, AWS Config, Amazon GuardDuty and AWS CloudTrail were all activated to give continuous security monitoring.
  • Recovery provenSnapshots were automated on a schedule, and an end-to-end restore from an image-level copy of the instance was completed, with rollback capability and timing demonstrated back to the client.
  • Cost brought under controlCost Explorer alerts and reports were created and a tagging strategy was implemented to attribute and monitor spend across the environment.
  • Governance in placeA standard set of policy documents, covering incident management, security tickets, IAM, VPN and cost, was produced, alongside a partner-led scorecard delivered to the client.
  • HandoverOngoing responsibilities were confirmed between the client and Cloud Combinator, with day-to-day operational tasks such as VPN management and snapshot auditing set to be owned internally going forward.

A number of items were deliberately scoped out for a planned re-architecture of the platform. With a hardened, well-documented baseline now in place, the client is set up to take that redesign forward on solid foundations rather than firefighting risks along the way.

AWS Stack

AWS Well-Architected Framework

For a structured review of the workload across the Security, Reliability, Operational Excellence and Cost Optimisation pillars.

AWS Identity

And Access Management for enforced MFA, least-privilege access and credential rotation.

AWS Security

Hub, AWS Config, Amazon GuardDuty and AWS CloudTrail for continuous security posture management, monitoring and audit.

Amazon EC2

And Amazon RDS for the application front end and database backend under review.

Amazon EBS

Snapshots for automated, image-level backups and tested recovery.

AWS Cost Explorer

And AWS Budgets for cost visibility, alerting and tagging-based cost attribution.

YOU MIGHT LIKE

Related success stories

View all case studies

Case Studies | Insights

Utilising Language Recognition, Speed, and Enhanced Security to Make Social Media a Force for Good

  • Here, we take a detailed look at how the Cloud Combinator team collaborated with another cutting-edge AI service provider that provides intelligent systems to “make social media more social” for brands and users alike.
  • Arwen AI is a UK-based startup specialising in AI solutions to manage and enhance brands’ social media interactions. Founded in 2020 by Matt McGrory, Dr. David Cole, and Joel Bailey, Arwen. AI focuses on using AI to automatically detect and remove spam, toxic comments, and other unwanted content from social media platforms.
  • The team at Arwen have three core products. ‘Moderate’ is focused on identifying and removing toxic content from social media channels. ‘Engage’ helps brands identify and engage with meaningful conversations on social media, and ‘Customize’ allows brands to apply bespoke algorithms to their channels - creating an even more effective moderation and engagement.
Read more
CONTACT US

Ready to turn AI into impact?

We'll help you spot the highest-value opportunities, reduce risk around your first AI initiative, and define a clear path to results from day one.

Why talk to us:

Outcome-driven recommendations

AWS-recognised delivery expertise

Risk-aware AI adoption

Clear next step, not a sales pitch

Start with a focused 20-minute conversation about your goals — no pressure, no commitment.

This website uses cookies to enhance user experience and to analyze performance and traffic on our website.

See our Privacy Policy for details.