Customer Stories / Financial Services / United Kingdom

2023
Chetwood Financial Logo

Standardizing Security after an Acquisition Using AWS Shield with Chetwood Financial

Learn how Chetwood Financial, a UK-based digital bank, secured its perimeter using AWS Shield.

3x boost

in InfoSec team productivity

Delivered

unified security insights

Boosted confidence

in perimeter security

Advanced security culture

organization-wide

Automated

security and compliance tasks

Overview

When digital banking innovator Chetwood Financial Ltd. (Chetwood Financial) acquired core banking provider Yobota in 2022, the bank needed the latest approach to cybersecurity. It wanted to gain unified visibility across its numerous Amazon Web Services (AWS) accounts to meet stringent security and compliance requirements. However, it was difficult for teams to govern two separate technical estates. Using AWS, Chetwood Financial standardized and unified its security posture by creating a comprehensive security operations framework that is scalable and future proof. “Combining these organizations was helpful for us because it gave us a single source of truth for security and compliance,” says Harry Carr, lead security engineer at Chetwood Financial.

City, phone, and hands post on social media connected to internet with a website notification outdoors. News, digital and man online typing or texting on a social networking app and searching content

Opportunity | Using AWS to Build a Unified Security Framework for Chetwood Financial

Founded in 2016, Chetwood Financial is on a mission to challenge every aspect of how financial services firms operate. The bank focuses on launching consumer-led propositions designed for underserved market segments, such as innovative savings and loan products. When Chetwood Financial acquired Yobota, its information security (InfoSec) team was challenged to deliver a unified governance initiative across both technology estates—a sizable challenge. “The initiative was the most significant security investment in the bank’s history. It was bold and ambitious,” says Abdul Khader, security subject matter expert at Chetwood Financial.

The digital bank, which is cloud native and all in on AWS, decided to design and implement its unified governance initiative using a suite of AWS services. “We evaluate alternative market products, and choosing AWS is almost always a no-brainer for us to deliver quickly and effectively,” says Sean McKeown, head of InfoSec at Chetwood Financial. Before implementing any service, the InfoSec team deliberated on the best way to redesign Chetwood Financial’s security posture and deliver business and security value as early as possible. The bank then drew on a combination of specialists in Chetwood Financial’s engineering department—along with external partners and its proactive engagement with the AWS team—to discuss proposals, collaboratively refine architecture, and verify that the solution followed AWS best practices.

kr_quotemark

This project on AWS was a game changer. Instead of fighting to tread water, we’re now proactively delivering leading-edge security capabilities across all security domains to the business.”

Sean McKeown
Head of Information Security, Chetwood Financial Ltd.

Solution | Increasing InfoSec Productivity by 3x Using Managed Services on AWS

Chetwood Financial set out to mature its security capability incrementally and continuously, working to improve security from the perimeter in. On its perimeter, the bank implemented AWS Shield, which provides near-real-time visibility and powers the mitigation of sophisticated distributed denial of service events. It also set up managed rules for AWS Web Application Firewall (AWS WAF), a service for protecting against common web exploits and bots. Chetwood Financial also boosted productivity by using infrastructure as code and centralized shared modules that are deployed for each of its workloads, thereby unlocking scalability. “Using AWS WAF and AWS Shield, we have increased confidence in our perimeter security,” says Khader.

Chetwood Financial used other AWS services in unison to automate security checks and boost efficiency for the InfoSec team. On AWS Security Hub—a service to automate AWS security checks and centralize security alerts—Chetwood Financial gains a unified source of insight into all security events across its estate. With greater visibility into current compliance levels across all of Chetwood Financial’s AWS accounts, internal engineering teams are empowered to deliver better reporting, prioritize high-value tasks, and protect assets. With enhanced visibility, the bank can also more efficiently comply with relevant legislation and regulatory requirements, including General Data Protection Regulation rules. “Now, we’re doing compliance evaluations in a consistent and automated way with minimal overhead using out-of-the-box services from AWS,” says Khader.

“Using AWS Security Hub turned out to be a game changer for us,” says McKeown. “With it, we gained a single-pane view into our compliance posture. By consolidating findings from various AWS security services, using AWS Security Hub made it simpler for our security team to identify and rectify potential risks promptly.”

To automate its security controls and deploy controls across both organizations, Chetwood Financial uses AWS Control Tower, which orchestrates multiple AWS services. The bank has significantly reduced the workload for its InfoSec team by automating processes, including saving an estimated 40 hours per month because the team no longer needs to manually generate a compliance report. Using automation, Chetwood Financial also reduced the time it takes to provision accounts from half a day to 5–10 minutes. In addition to saving time, automation minimizes the risk of human error to the company’s security posture. “Now, our controls are automatically deployed to both organizations,” says Carr. “The management workload and overhead is drastically smaller when automated, internally-defined security baselines are consistently deployed across all AWS accounts.”

As a result of these changes, the InfoSec team has shifted from a reactive to a proactive approach when it comes to dealing with security events, including using key performance indicator monitoring, key risk indicator monitoring, and threat modeling to prevent issues. “This initiative has embedded a culture of security by creating awareness about the estate for the wider team and stakeholders,” says Khader. By rolling out its unified governance initiative, Chetwood Financial has greatly enhanced communication between its InfoSec and engineering disciplines, meaning they can surface and address problems effectively. Team members are now focused on building new features to improve the bank’s security posture, such as preventive controls that will keep new projects compliant from the get-go. “We’re tackling leading-edge initiatives that seemed years away before we implemented this project, and we only delivered it in early 2023,” says McKeown.

Architecture Diagram

Outcome | Continuing to Mature Cybersecurity Using AWS

Chetwood Financial isn’t done yet. The bank plans to mature its InfoSec capability further by refining its use of AWS services combined with modern DevSecOps approaches. “Now, we’re introducing a combination of detective, preventive, and corrective controls to enhance the compliance of operations across Chetwood Financial,” says Khader.

The bank is ready to take the next steps in its growth with comprehensive security operations on AWS. “This project on AWS was a game changer,” says McKeown. “Instead of fighting to tread water, we’re now proactively delivering leading-edge security capabilities across all security domains to the business.”

About Chetwood Financial Ltd.

Chetwood Financial Ltd. is a digital bank that advances financial products for underserved market segments. For example, the bank offers a loan that rewards customers for credit score improvements with a reduced interest rate.

AWS Services Used

AWS WAF

AWS Web Application Firewall (AWS WAF) helps you protect against common web exploits and bots that can affect availability, compromise security, or consume excessive resources.

Learn more »

AWS Security Hub

Use AWS Security Hub to automate security best practice checks, aggregate security alerts into a single place and format, and understand your overall security posture across all of your AWS accounts.

Learn more »

AWS Shield

AWS Shield is a managed DDoS protection service that safeguards applications running on AWS.

Learn more »

AWS Control Tower

Use AWS Control Tower to set up and operate your multi-account AWS environment with prescriptive controls designed to accelerate your cloud journey.

Learn more »

More Financial Services Customer Stories

Showing results: 5-8
Total results: 506

no items found 

  • United States

    Affirm Reduces Manual Security Response Efforts by 50% with AWS Partner Expel

    Affirm is a payment network that empowers consumers and helps merchants drive growth through flexible and transparent financing options. The company wanted to streamline its security operations program to address manual triage, decentralized tooling, and increasing alert fatigue. AWS Partner Expel offered a managed detection and response (MDR) service that integrated seamlessly with Affirm’s Amazon Web Services (AWS) environment. Expel MDRTM centralizes monitoring, automates routine tasks, and enhances detection and response workflows Expel reduced the volume of security alerts fielded by engineers by 50 percent and helped Affirm scale the foundations of its security operations program efficiently.

    2025
  • United States

    MarketReader Launches Its Real-Time Market Analysis Platform and AI Newsletter in Eight Months Using Nasdaq® and AWS

    MarketReader is an artificial intelligence (AI) analytics platform providing the financial sector with data-driven explanations of real-time asset movement. During development, MarketReader experienced delays in data delivery and received incomplete datasets from its initial data provider—which reduced the quality of the platform’s insights. To launch its differentiated product, the MarketReader team moved to cloud-based data solutions from AWS Partner Nasdaq, hosted on Amazon Web Services (AWS), to obtain direct access to high-quality, real-time market data for all US-listed securities. This approach elevated MarketReader’s US market coverage, increased data delivery time by 98 percent, and helped the platform go live within eight months. MarketReader now delivers timely, accurate insights. It publishes a daily newsletter in only seven minutes, driving customer engagement and expanding the newsletter’s reach up to 400 percent beyond MarketReader’s current client base.

    2025
  • United States

    Transforming Payments with AWS and Visa Cloud Connect

    Moov, a payment processor with direct connections to major card networks and payment systems, ensures scalability and availability for high-demand scenarios, from political campaigns to exclusive product drops. With AWS as the backbone, Moov’s solutions connect seamlessly, enabling faster and more scalable money movement across its network. Thanks to AWS Partner Visa and Visa Cloud Connect on AWS, Moov eliminated the need for traditional data centers and infrastructure, streamlining access to payment networks. This innovation delivers immediate transaction insights to customers already on AWS, enhancing the end-user experience and redefining payment processing.

    2025
  • United Kingdom

    Mortgage Advice Bureau and BJSS Accelerate Complaints Process Using AWS

    Mortgage Advice Bureau (MAB) is an established, multi-award winning, UK mortgage intermediary that provides advice, both through its own branded brokers and through other brokers. It processes about 12,000 mortgages a month and receives around 400 complaints per year. Those complaints, however, are a serious matter, because MAB is regulated by the UK’s Financial Conduct Authority (FCA), whose Financial Ombudsman is the last resort for disputes. MAB wanted to ensure that it could resolve complaints in a timely manner and before they were escalated to the Financial Ombudsman. It engaged AWS Partner BJSS to help build a solution using AI on Amazon Web Services (AWS) to speed up the processing of complaints, reducing initial response times by 75 percent.

    2025
1 127

Get Started

Organizations of all sizes across all industries are transforming their businesses and delivering on their missions every day using AWS. Contact our experts and start your own AWS journey today.