Where they started
AWS accounts were created one by one, each with its root account handed straight to the team and its own payment card. No central organisation, no least privilege, no visibility on costs. For a financial institution, the security posture was untenable.
The challenge
The technology was not the hardest part. Above all, we had to:
- get everyone aligned: security, identity and application teams, each with their own priorities;
- take over what existed: bring standalone accounts into the organisation and make applications compliant, with as little downtime as possible.
What we delivered
As AWS architect for the landing zone, we turned the institution’s security requirements into rules that apply automatically:
- Structure: AWS Organizations, Control Tower and Account Factory, all described in Terraform.
- Identity: IAM Identity Center connected to the corporate SSO. No more shared root accounts.
- Guardrails (SCPs and controls): allowed regions and resource types, mandatory KMS encryption, no public resources, mandatory tagging.
- FinOps: automated cost reports, with an alert when forecasts drift.
Outcome
- Security: the institution’s posture changed completely.
- A cloud account is no longer a blank cheque: every new account is born inside a governed framework, with its rules already in place.
- Scale: the landing zone became the cloud foundation of the whole organisation, and keeps welcoming new services.

