A global media organisation with one of the world’s highest cloud bills had asked its existing supply chain to build the platforms behind its major internal services. Mature cloud standards existed in the organisation, but the attention had gone to customer-facing digital products. Internal infrastructure had been built largely unsupervised.
With infrastructure cost reduction a board-level priority and major new services about to launch, we were asked to review those implementations: did they follow good practice, and were they fit to host business-critical services?
// WHAT WE DIDA detailed implementation review
We reviewed the existing cloud platforms behind three critical internal services against three reference points: industry good practice, the AWS Well-Architected Framework, and the client’s own architecture and security policies.
Alongside the manual review, we ran a toolchain across the estate so the findings were evidenced rather than asserted.
We presented the findings back to the client, then took responsibility for driving the remediation with the resolver groups involved — including the client’s own supply chain partners.
// WHAT WE FOUNDOver 200 observations
The review raised more than 200 observations. They ranged from material architectural considerations and cost optimisation opportunities through to high-priority security vulnerabilities at a detailed technical level — open ports on the internet, missing encryption.
The central finding was structural. The platforms had been built from manually created images, with no elasticity and no infrastructure-as-code for rapid environment deployment. Without auto-scaling, compute had been vastly over-provisioned — and the DR estate over-provisioned at the same rate, doubling the waste.
Compounding it, there were no clear retention policies for snapshots and images, and disk IOPS had been over-specified. Cost was accumulating in places nobody was looking.
"Over-provisioned compute, mirrored faithfully into an over-provisioned DR estate. The inefficiency had been paid for twice."
// RESULTSWhat remediation delivered
The review completed in October 2022. The figures below are the position a month later, with the remainder of the programme in flight.
The cost reduction is worth reading carefully: it was achieved before infrastructure-as-code and auto-scaling landed. The structural fix was still ahead of it.
// BEYOND THE REVIEWNew standards for the organisation
As well as identifying issues, we proposed new backup patterns to protect against ransomware and cypher-shredding attacks. The client adopted them as the organisation’s standard going forward — so the work outlived the three services it started on.
"The differentiator was the breadth and depth of knowledge of AWS services the Axiologik team demonstrated, providing the client with advice on building highly secure, scalable, cloud-native services on AWS using best practice. This thought leadership was instrumental to remediating numerous high impact concerns."
— GLOBAL AWS ACCOUNT LEAD FOR THE CLIENT
// THE LESSONStandards are not the same as compliance
This organisation had good cloud standards. What it lacked was supervision of the platforms nobody was watching — the internal ones, built by partners, hosting services that would soon be critical.
An independent review is the cheapest way to find that out. It is considerably cheaper than discovering it from an incident, or from the invoice.