The client
An SMB running production workloads on AWS (the client is not named on the original case study).
Findings, area by area
Security Limited controls; audit readiness needed
→Dedicated VPC, private subnets, restricted security groups, controlled SSH
Monitoring Limited visibility into system health
→CloudWatch alarms for CPU, memory and disk
Backups Inconsistent backup practices
→Automated backups with monitoring and retention checks
Audit trail No central record of activity
→CloudTrail and VPC Flow Logs, centralised logging
Cost Rising cloud costs
→Reserved Instances, dev servers off after hours, storage lifecycle: about 25–35% lower
What we did
- 1Discovery
reviewed infrastructure and workload patterns, network and access exposure, backup, monitoring and logging gaps, and cost drivers.
- 2Architecture
a dedicated VPC with public and private subnets, restricted security groups and controlled SSH access, automated backups for EC2 and managed databases.
- 3Operations
CloudWatch alarms for CPU, memory and disk; centralised logging and audit trails with CloudTrail and VPC Flow Logs; backup monitoring and retention checks.
- 4Cost
Reserved Instances for steady production workloads, development servers stopped outside business hours, storage lifecycle policies to cheaper tiers.
The architecture
- VPC
- EC2
- CloudWatch
- CloudTrail
- VPC Flow Logs
- Reserved Instances
The result
Security posture significantly improved.
Proactive monitoring and stronger backup and audit readiness.
AWS costs reduced by approximately 25–35%.
The environment aligned with AWS Well-Architected best practices.
Want the same for your AWS setup?
Book a 20-minute review. An engineer looks at your setup and tells you what we would fix first.









