Customer Stories / Financial Services / United Kingdom

2023
Chetwood Financial Logo

Standardizing Security after an Acquisition Using AWS Shield with Chetwood Financial

Learn how Chetwood Financial, a UK-based digital bank, secured its perimeter using AWS Shield.

3x boost

in InfoSec team productivity

Delivered

unified security insights

Boosted confidence

in perimeter security

Advanced security culture

organization-wide

Automated

security and compliance tasks

Overview

When digital banking innovator Chetwood Financial Ltd. (Chetwood Financial) acquired core banking provider Yobota in 2022, the bank needed the latest approach to cybersecurity. It wanted to gain unified visibility across its numerous Amazon Web Services (AWS) accounts to meet stringent security and compliance requirements. However, it was difficult for teams to govern two separate technical estates. Using AWS, Chetwood Financial standardized and unified its security posture by creating a comprehensive security operations framework that is scalable and future proof. “Combining these organizations was helpful for us because it gave us a single source of truth for security and compliance,” says Harry Carr, lead security engineer at Chetwood Financial.

City, phone, and hands post on social media connected to internet with a website notification outdoors. News, digital and man online typing or texting on a social networking app and searching content

Opportunity | Using AWS to Build a Unified Security Framework for Chetwood Financial

Founded in 2016, Chetwood Financial is on a mission to challenge every aspect of how financial services firms operate. The bank focuses on launching consumer-led propositions designed for underserved market segments, such as innovative savings and loan products. When Chetwood Financial acquired Yobota, its information security (InfoSec) team was challenged to deliver a unified governance initiative across both technology estates—a sizable challenge. “The initiative was the most significant security investment in the bank’s history. It was bold and ambitious,” says Abdul Khader, security subject matter expert at Chetwood Financial.

The digital bank, which is cloud native and all in on AWS, decided to design and implement its unified governance initiative using a suite of AWS services. “We evaluate alternative market products, and choosing AWS is almost always a no-brainer for us to deliver quickly and effectively,” says Sean McKeown, head of InfoSec at Chetwood Financial. Before implementing any service, the InfoSec team deliberated on the best way to redesign Chetwood Financial’s security posture and deliver business and security value as early as possible. The bank then drew on a combination of specialists in Chetwood Financial’s engineering department—along with external partners and its proactive engagement with the AWS team—to discuss proposals, collaboratively refine architecture, and verify that the solution followed AWS best practices.

kr_quotemark

This project on AWS was a game changer. Instead of fighting to tread water, we’re now proactively delivering leading-edge security capabilities across all security domains to the business.”

Sean McKeown
Head of Information Security, Chetwood Financial Ltd.

Solution | Increasing InfoSec Productivity by 3x Using Managed Services on AWS

Chetwood Financial set out to mature its security capability incrementally and continuously, working to improve security from the perimeter in. On its perimeter, the bank implemented AWS Shield, which provides near-real-time visibility and powers the mitigation of sophisticated distributed denial of service events. It also set up managed rules for AWS Web Application Firewall (AWS WAF), a service for protecting against common web exploits and bots. Chetwood Financial also boosted productivity by using infrastructure as code and centralized shared modules that are deployed for each of its workloads, thereby unlocking scalability. “Using AWS WAF and AWS Shield, we have increased confidence in our perimeter security,” says Khader.

Chetwood Financial used other AWS services in unison to automate security checks and boost efficiency for the InfoSec team. On AWS Security Hub—a service to automate AWS security checks and centralize security alerts—Chetwood Financial gains a unified source of insight into all security events across its estate. With greater visibility into current compliance levels across all of Chetwood Financial’s AWS accounts, internal engineering teams are empowered to deliver better reporting, prioritize high-value tasks, and protect assets. With enhanced visibility, the bank can also more efficiently comply with relevant legislation and regulatory requirements, including General Data Protection Regulation rules. “Now, we’re doing compliance evaluations in a consistent and automated way with minimal overhead using out-of-the-box services from AWS,” says Khader.

“Using AWS Security Hub turned out to be a game changer for us,” says McKeown. “With it, we gained a single-pane view into our compliance posture. By consolidating findings from various AWS security services, using AWS Security Hub made it simpler for our security team to identify and rectify potential risks promptly.”

To automate its security controls and deploy controls across both organizations, Chetwood Financial uses AWS Control Tower, which orchestrates multiple AWS services. The bank has significantly reduced the workload for its InfoSec team by automating processes, including saving an estimated 40 hours per month because the team no longer needs to manually generate a compliance report. Using automation, Chetwood Financial also reduced the time it takes to provision accounts from half a day to 5–10 minutes. In addition to saving time, automation minimizes the risk of human error to the company’s security posture. “Now, our controls are automatically deployed to both organizations,” says Carr. “The management workload and overhead is drastically smaller when automated, internally-defined security baselines are consistently deployed across all AWS accounts.”

As a result of these changes, the InfoSec team has shifted from a reactive to a proactive approach when it comes to dealing with security events, including using key performance indicator monitoring, key risk indicator monitoring, and threat modeling to prevent issues. “This initiative has embedded a culture of security by creating awareness about the estate for the wider team and stakeholders,” says Khader. By rolling out its unified governance initiative, Chetwood Financial has greatly enhanced communication between its InfoSec and engineering disciplines, meaning they can surface and address problems effectively. Team members are now focused on building new features to improve the bank’s security posture, such as preventive controls that will keep new projects compliant from the get-go. “We’re tackling leading-edge initiatives that seemed years away before we implemented this project, and we only delivered it in early 2023,” says McKeown.

Architecture Diagram

Outcome | Continuing to Mature Cybersecurity Using AWS

Chetwood Financial isn’t done yet. The bank plans to mature its InfoSec capability further by refining its use of AWS services combined with modern DevSecOps approaches. “Now, we’re introducing a combination of detective, preventive, and corrective controls to enhance the compliance of operations across Chetwood Financial,” says Khader.

The bank is ready to take the next steps in its growth with comprehensive security operations on AWS. “This project on AWS was a game changer,” says McKeown. “Instead of fighting to tread water, we’re now proactively delivering leading-edge security capabilities across all security domains to the business.”

About Chetwood Financial Ltd.

Chetwood Financial Ltd. is a digital bank that advances financial products for underserved market segments. For example, the bank offers a loan that rewards customers for credit score improvements with a reduced interest rate.

AWS Services Used

AWS WAF

AWS Web Application Firewall (AWS WAF) helps you protect against common web exploits and bots that can affect availability, compromise security, or consume excessive resources.

Learn more »

AWS Security Hub

Use AWS Security Hub to automate security best practice checks, aggregate security alerts into a single place and format, and understand your overall security posture across all of your AWS accounts.

Learn more »

AWS Shield

AWS Shield is a managed DDoS protection service that safeguards applications running on AWS.

Learn more »

AWS Control Tower

Use AWS Control Tower to set up and operate your multi-account AWS environment with prescriptive controls designed to accelerate your cloud journey.

Learn more »

More Financial Services Customer Stories

Showing results: 21-24
Total results: 506

no items found 

  • Vietnam

    TymeX Accelerates Clean Coding by 40% by Implementing Generative AI on AWS

    TymeX improved developer productivity with Amazon CodeWhisperer and Amazon Q, automating tasks across the software development lifecycle while using real-time AI assistants to troubleshoot errors.
    2024
  • Japan

    SBI Life Insurance develops a document search solution with Amazon Kendra and generative AI, and streamlines call centers with a selfbot

    Using generative artificial intelligence (AI) capabilities from Amazon Web Services (AWS), the company built a document search solution to retrieve procedural documents on their insurance products and policies, launching the solution at its call centers.
    2024
  • India

    Protium drives innovation in the cloud with AWS

    This case study highlights how Protium, a renewable energy company, used AWS to build a cloud-based platform that helps manage and optimize their energy assets.
    2023
  • Europe, Middle East, & Africa

    TP ICAP on AWS

    Liquidity and data solutions specialist TP ICAP is trusted by clients worldwide for its market intelligence, data and analytics, and broking services. The company has moved 50 percent of its IT estate to Amazon Web Services, giving it the scale and security to run critical financial trading platforms as well as accelerating decarbonization and supporting its commitment to sustainability. By using the latest generative artificial intelligence solutions such as Amazon Bedrock, TP ICAP’s Parameta Solutions is transforming how its teams put new ideas into action.
    2024
1 127

Get Started

Organizations of all sizes across all industries are transforming their businesses and delivering on their missions every day using AWS. Contact our experts and start your own AWS journey today.