Search:

Akbank Case Study

akbank-case-round

As a major finance player in the industry, having a focus on innovation, Akbank agreed to onboard AWS to create a playground for the technologies being evaluated internally.

In this process, Akbank wanted to strengthen the working areas of its IT teams and started the AWS Migration Acceleration program by partnering with kloia.


Problem

AWS MAP projects provide customers with the development, applications or environments they want to test on AWS. AWS aims to eliminate many problems with MAP projects. The most important starting point is; the customer wants to get maximum efficiency from AWS during this transition.

The main goal of Akbank's apply to AWS Migration Program and the start of the program is the difficulty of managing multiple accounts and the gaps that need to be closed in terms of security.
The need for a centralized log management and automation of the setup processes of environments and accounts arose using AWS services.

Client: Akbank

Project type: Migration to AWS

Solution

By using the Control Tower service on AWS, we have provided the opportunity to manage their environments and teams more effectively. AWS Control Tower provides the easiest way to set up and govern a secure, multi-account AWS environment, called a landing zone. It creates your landing zone using AWS Organizations.

Quickly set up and configure a new AWS Accounts with Control Tower

Akbank wanted to create separate environments for both its applications and users. Creating and configuring new accounts for each user would have been much work. Therefore, with AWS's Control Tower service, environments can be created quickly and they will be facilitated through Organizations with SCP (Service Control Policies) for authorizations.

Access to services and access to accounts were restricted using SSO service with Control Tower.

Cost Optimization - Automation for unused resources

When we looked at Akbank’s infrastructure, we  observed that the unused resources created too much cost. So, to avoid any cost for unused resources, Lambda functions were used to follow certain Cloudwatch parameters and these resources were stopped as needed.

Centralized Log Management & Security

By using the Control Tower service, we have eliminated the problems that may occur in terms of Centralized Log Management and Security. 

- Security : We checked the probes that may occur in terms of Security over a common Account. At this point, AWS GuardDuty and AWS Config services were enabled in the Security Account, and a security layer was created for auditing and threat detection.

- Log Management : A Log Management Account was created at the bottom by creating the Core Organizational Unit. The reason for this was to manage the logs of the transactions performed by the user and account owners from a single place using the CloudTrail service.

Akbank Architecture Diagram1
akbank-casestudy-results

Results

  • Multi-account management

  • Automated setup of all Organization Accounts Configuration with Control Tower

  • Central Security and Logging mechanisms

  • Cost optimization for unused resources

Contact