MAGC Book a call
Proof

Case Studies

Selected engagements and the results they delivered.

Discuss your project

Securing a global investment bank's
use of public cloud

Designing and implementing a cloud SOC with a single detect-and-respond capability across every public cloud service the bank uses.

The challenge

The bank ran workloads across AWS and four Azure tenants, with an M365 rollout starting. Logging existed in each platform, but there was no security monitoring and no SIEM, and central logging sat in a US region that conflicted with the bank's data residency requirements. As a systemically important bank operating across Switzerland, the EU, the UK, the US and Asia Pacific, it faced overlapping regulatory obligations (FINMA, GDPR and DORA, FCA and PRA, NYDFS, MAS and APRA among them) that all assume security event logging, continuous monitoring and central correlation. It needed one authoritative security data set feeding a resilient SIEM, held in an approved region and owned by Cyber.

What we did

  • Designed and implemented a new cloud SOC on Microsoft Sentinel, with a single central Log Analytics workspace as the one destination for logs and security alerts from every cloud platform the bank uses.
  • Moved central logging out of the US into a European region, replicated across three availability zones, keeping client-identifying log data inside the required jurisdiction.
  • Brought all four Azure tenants and their M365 tenants (including Purview), the full AWS Organisation, Zoom and further SaaS applications into scope, with policy-driven log enablement.
  • Stood up a separate development SOC subscription for proof-of-concept work and change validation, kept lean with non-persistent log sources.
  • Rebuilt Sentinel analytical rules, automation, playbooks and reporting workbooks against the consolidated data set, with MITRE ATT&CK coverage mapped through to incident tickets.
  • Integrated bi-directionally with ServiceNow Security Incident Response, adapted the bank's incident response process for cloud, and recorded the implementation as configuration as code so the environment can be rebuilt rapidly.
  • Trained and documented the platform as part of handover to the bank's Cyber Security function, in partnership with Cloud Platform Engineering.

The outcome

Monitoring and protection across all public cloud services, meeting the bank's regulatory obligations. Analysts query Azure, AWS, M365 and SaaS activity together, with the consolidated data set feeding machine learning, threat hunting and UEBA. Duplicate log collection was removed, responders get ATT&CK context at the point of triage, automation flags expiring credentials before they break ingestion, and the security-as-code record means the environment can be rebuilt at speed.

Transforming infrastructure delivery
for a global investment bank

Replacing disparate regional request systems with one standardised, self-service ordering platform.

The challenge

Infrastructure requests ran through a number of disparate systems with regional variations. A complex mix of OS builds, service levels and bespoke design pushed CAPEX and OPEX up with every request, and ordering, approval and fulfilment were spread across separate tools and CMDBs with no single view of applications, capacity or cost. A virtual server took 8 to 10 weeks to deliver and a physical server 12 to 14, and access requests ran separately, so teams often received infrastructure they could not log in to. Some functions, such as low-latency trading, had splintered into shadow IT. Self-service infrastructure was a key deliverable of the bank's next-generation compute hosting platform, and the existing process could not support it.

What we did

  • Consolidated the CMDB and data model into one source for applications and ownership, OS builds, VM sizes, physical BOMs, storage products, service levels, network granularity and data centre locations.
  • Standardised the offering: fixed VM sizes and physical BOMs with layered service levels, delivered as product templates in place of bespoke configuration.
  • Built end-to-end ordering in ServiceNow: catalogue, granular approval, automated capacity placement, orchestration and downstream fulfilment for virtual and physical builds, plus decommission.
  • Integrated IAM requests into the ordering flow, so access arrives with the infrastructure it belongs to.
  • Kept a separate design-tool track for bespoke requests, consuming the same reference data and standards.
  • Built service management in: central logging across the request path, automated incident and change tickets, a task chase engine, and cost, utilisation and SLA reporting by application, region and OS.
  • Documented and handed over to the ServiceNow and infrastructure operations teams, with reporting tooling and exception management.

The outcome

Virtual server delivery fell from 8 to 10 weeks to 1 to 5 days, and physical delivery from 12 to 14 weeks to 2 to 3 weeks, with access ready on arrival. Standardisation simplified procurement, approval and environment management, and made capacity planning forecastable rather than reactive. Consumers order, manage and decommission their estate through one portal with monthly, annual and historic run costs against it, utilisation reporting drives reclamation of idle resources, and the portal's native ServiceNow build keeps upgrade paths clean.