Case Studies | Healthcare & Life Sciences

Hardening an AWS environment after a security incident

Well-Architected Framework Review

About

A Healthcare & Life Sciences business working with Cloud Combinator on AWS. The client is anonymised at their request.

Challenge

The review concentrated on three focus areas drawn from the Well-Architected pillars.

Closing security exposure

The environment showed classic high-risk patterns: daily use of the root account, a RDS database reachable over the public internet, and permissive security groups. These had to be addressed with strong identity controls, network restriction and continuous threat detection, some immediately and some through a deeper re-architecture.

Building in reliability and recovery

There was no defined disaster recovery strategy, limited automatic scaling and a single-location deployment. The review set out how to add

Gaining operational visibility

The environment lacked centralised monitoring and a defined incident management process. The plan introduces CloudWatch dashboards and alarms, actionable alerting, and documented, tested incident response playbooks.

Solution

Cloud Combinator sequenced the work so the most urgent protections were in place first, the review actions came next, and the deeper architectural changes were planned as a clear follow-on, each item rated by severity and effort.

4

Well-Architected pillars reviewed

Post-incident

Root and edge protections enabled immediately

3

Phase roadmap, each action severity-rated and estimated

By the numbers:

  • 4 - Well-Architected pillars reviewed
  • Post-incident - Root and edge protections enabled immediately
  • 3 - Phase roadmap, each action severity-rated and estimated
Changes

The review gave the client a full picture of its AWS posture across four pillars, with the immediate incident-response protections already in place and everything else laid out as a prioritised, severity-rated roadmap. The engagement turned a security incident into a structured programme of improvement rather than an one-off fix.

  • Immediate protectionMFA on root, a separate IAM identity, WAF managed rulesets on the load balancers, and GuardDuty and IAM Access Analyzer enabled straight away.
  • Stronger identityA path to centralised SSO through IAM Identity Center, least-privilege permission sets, a break-glass process and credential rotation in Secrets Manager.
  • Reliability and DRAuto-scaling for the ECS workloads, CloudWatch monitoring with SNS alarms, and a tested disaster recovery strategy with defined recovery objectives.
  • Prioritised and quantifiedEvery action carries a severity rating and a time estimate, so the client can tackle the highest-risk items first, including making RDS private and redesigning the VPC.
  • HandoverA clear technical executive summary that leaves the client with the reasoning behind each recommendation and an ordered plan to work through.

With the urgent gaps closed and a severity-rated roadmap in hand, the client moved from reacting to an incident to running its AWS environment to a best-practice standard, with Cloud Combinator continuing to support the platform.

AWS Stack

AWS WAF

For managed-ruleset protection on the load balancers, blocking harmful requests at the edge.

Amazon GuardDuty

And IAM Access Analyzer for continuous threat detection and external access review.

AWS IAM Identity Center

And AWS Secrets Manager for centralised SSO, least-privilege access and credential rotation.

Amazon CloudWatch

With Amazon SNS for centralised monitoring, dashboards and availability alarms.

Amazon Inspector

And Amazon ECR for scanning container images before they are deployed to ECS.

Amazon RDS

And Amazon VPC redesign, plus tested backups, for a private, resilient and recoverable data tier.

YOU MIGHT LIKE

Related success stories

View all case studies

Case Studies | Insights

Utilising Language Recognition, Speed, and Enhanced Security to Make Social Media a Force for Good

  • Here, we take a detailed look at how the Cloud Combinator team collaborated with another cutting-edge AI service provider that provides intelligent systems to “make social media more social” for brands and users alike.
  • Arwen AI is a UK-based startup specialising in AI solutions to manage and enhance brands’ social media interactions. Founded in 2020 by Matt McGrory, Dr. David Cole, and Joel Bailey, Arwen. AI focuses on using AI to automatically detect and remove spam, toxic comments, and other unwanted content from social media platforms.
  • The team at Arwen have three core products. ‘Moderate’ is focused on identifying and removing toxic content from social media channels. ‘Engage’ helps brands identify and engage with meaningful conversations on social media, and ‘Customize’ allows brands to apply bespoke algorithms to their channels - creating an even more effective moderation and engagement.
Read more
CONTACT US

Ready to turn AI into impact?

We'll help you spot the highest-value opportunities, reduce risk around your first AI initiative, and define a clear path to results from day one.

Why talk to us:

Outcome-driven recommendations

AWS-recognised delivery expertise

Risk-aware AI adoption

Clear next step, not a sales pitch

Start with a focused 20-minute conversation about your goals — no pressure, no commitment.

This website uses cookies to enhance user experience and to analyze performance and traffic on our website.

See our Privacy Policy for details.