The challenge
A regional telco was running 47 AWS accounts across BSS, OSS, analytics and product teams with no landing zone, no IaC, no FinOps. Cloud spend was growing 18% QoQ with no accountability, and the security team had no consistent baseline.
What we delivered
- 01AWS Control Tower landing zone with SCP guardrails, IAM Identity Center, central log archive.
- 02Terraform IaC for 48 accounts across dev / staging / prod.
- 03EKS for BSS microservices with Karpenter autoscaling, Istio service mesh.
- 04ArgoCD GitOps, Backstage IDP, golden paths for new services.
- 05FinOps dashboard with showback / chargeback per product line.
Outcomes
- −32% Annual cloud spend in year one.
- 48 Standardized AWS accounts.
- 100% New services onboarded via Backstage golden paths.
- SOC 2 Evidence collection automated end-to-end.
“We finally have an AWS estate that the security team trusts and finance can read.”
— Group CTO, Regional Telco