Case study 3 of 12 · /resources/case-studies/smb-optimisation

Audit report design

A review-and-fix engagement, so it reads like an audit report: five areas moving from gap to fixed, a findings table and a sticky cost result.

For review: SEO and checks (not shown to visitors)
SEO title
SMB on AWS Case Study | DevOps TechLab (38 characters)
Meta description
Better security, monitoring and backups, and an AWS bill about 25–35% lower. How DevOps TechLab built it on AWS. (112 characters)
URL
/resources/case-studies/smb-optimisation
Keywords
VPC, EC2, CloudWatch, CloudTrail
Check before publishing
  • Rewritten from the case study on devopstechlab.com (PDF supplied 1 Oct 2026). No figures added beyond the original page.
  • Client has agreed to be named on the new site (confirmed 1 Oct 2026).
  • PENDING: original diagram file from the team, to replace the crop from the PDF.
  • Client not named on the original page. If they agree to be named, add the name.
  1. Home
  2. Resources
  3. Case studies
  4. SMB on AWS
Cost & securityAWSClient story

SMB on AWS

AWS infrastructure, security and cost optimisation for an SMB workload

Better security, monitoring and backups, and an AWS bill about 25–35% lower.

Told by a Cloud Cost Optimisation Specialist from DevOps TechLabSMB production workload2 min read

The client

An SMB running production workloads on AWS (the client is not named on the original case study).

Findings, area by area

What we foundWhat we put in place
  • Security Limited controls; audit readiness needed

    Dedicated VPC, private subnets, restricted security groups, controlled SSH

  • Monitoring Limited visibility into system health

    CloudWatch alarms for CPU, memory and disk

  • Backups Inconsistent backup practices

    Automated backups with monitoring and retention checks

  • Audit trail No central record of activity

    CloudTrail and VPC Flow Logs, centralised logging

  • Cost Rising cloud costs

    Reserved Instances, dev servers off after hours, storage lifecycle: about 25–35% lower

What we did

  1. 1Discovery

    reviewed infrastructure and workload patterns, network and access exposure, backup, monitoring and logging gaps, and cost drivers.

  2. 2Architecture

    a dedicated VPC with public and private subnets, restricted security groups and controlled SSH access, automated backups for EC2 and managed databases.

  3. 3Operations

    CloudWatch alarms for CPU, memory and disk; centralised logging and audit trails with CloudTrail and VPC Flow Logs; backup monitoring and retention checks.

  4. 4Cost

    Reserved Instances for steady production workloads, development servers stopped outside business hours, storage lifecycle policies to cheaper tiers.

The architecture

Architecture as built
  • VPC
  • EC2
  • CloudWatch
  • CloudTrail
  • VPC Flow Logs
  • Reserved Instances

The result

  • Security posture significantly improved.

  • Proactive monitoring and stronger backup and audit readiness.

  • AWS costs reduced by approximately 25–35%.

  • The environment aligned with AWS Well-Architected best practices.

Want the same for your AWS setup?

Book a 20-minute review. An engineer looks at your setup and tells you what we would fix first.

Next story · MigrationDevine Globe: From managed hosting to a secure, production-ready AWS environmentMoving day design · 2 min read