How IC transitioned to a policy-driven network model using AWS
Learn how global brokerage IC migrated to a centralized global network with zero downtime using AWS Cloud WAN.
Benefits
- reduction in mean time to recovery
- 90%
- VPC peering connections cut to 1 policy
- 40+
Overview
At IC, trades are measured in milliseconds, so network performance is a competitive concern. As the company opened offices in new markets, it connected each one to its global network individually, leaving engineers with no central place to monitor traffic or locate the source of a fault. Using Amazon Web Services (AWS), the brokerage replaced that legacy architecture with a centralized, policy-driven global network. Now, network incidents are investigated automatically, and the resulting reports reach the responsible regional team within minutes.
About IC
IC (formerly IC Markets) is a global online brokerage offering foreign exchange, commodities, currencies, and digital asset trading for more than 120,000 active traders each month across around 10 regulated entities.
Opportunity | Using AWS to simplify global networking for IC
IC’s organization spans 12 offices worldwide, with trading running 24 hours a day. When the brokerage opened offices in new markets, engineers linked each new environment to the last. By the end of 2024, that approach had produced a web of more than 40 Amazon Virtual Private Cloud (Amazon VPC) (which gives full control over virtual networking environments) peering connections spanning six AWS Regions.
The design connected environments but offered no central point to inspect traffic or trace a fault. When a link degraded, teams in different time zones could spend hours identifying the cause. A network fault could delay orders reaching the market and take internal systems offline immediately for an entire office.
IC has run its infrastructure on AWS since 2021, drawing on a portfolio of enterprise-grade compute, storage, and networking services. “Our company’s motto is that if you want to be the best, you have to be with the best,” says Sachin Daniel, head of cloud and infrastructure at IC. “That’s the main reason we adopted AWS as our technology stack for infrastructure.”
With that foundation already in place, IC looked to AWS networking services to consolidate its global connectivity under a single managed architecture. The brokerage raised the idea with AWS Enterprise Support, which helps organizations accelerate innovation and cloud operations with AI-powered capabilities. IC’s technical account manager scoped what a consolidated design would involve before the work began.
Solution | Building a policy-driven network using AWS Cloud WAN
IC found a solution in AWS Cloud WAN, a service used to build, manage, and monitor global wide area networks. “VPC peering became so complex that it was very difficult to manage,” says Daniel. “That’s why we migrated to AWS Cloud WAN. Analyze your use case and come up with a better approach, and you’ll have peace of mind in the longer term.”
IC migrated in three phases with the help of its AWS Enterprise Support team, keeping every office and trading application online throughout. In the first phase, IC deployed AWS Cloud WAN across all six active AWS Regions and grouped its workloads into network segments, separating traffic by the role it serves. A central policy determines which segments and AWS Regions each one can reach, so engineers set connectivity rules once for a group of workloads. In the second phase, IC used AWS Direct Connect, which creates a dedicated network connection to AWS, to establish a dedicated, low-latency connectivity for its trading infrastructure.
In the third phase, IC connected its offices using AWS Site-to-Site VPN, a service that extends on-premises networks to the cloud, for internal applications. The company then added AWS Network Firewall—which deploys advanced network firewall security across Amazon VPCs—as a central inspection point for east–west traffic moving between segments. Throughout onboarding, IC’s technical account manager coordinated design reviews and connected IC’s engineers with AWS networking specialists to settle architectural questions.
With all three phases carrying live traffic, IC retired its legacy peering connections inside a 48-hour cutover window. This was followed by a 2-week observation period during which system administrators and network engineers verified every path before the project was considered complete.
The architecture has kept evolving. In early 2026, IC adopted AWS DevOps Agent, a frontier agent for release management and production operations. IC uses the service to investigate network issues autonomously, so diagnostic work is underway before engineers pick up an issue.
Outcome | Resolving incidents in minutes across six AWS Regions
IC completed the migration with zero downtime, replacing more than 40 VPC peering connections with a single policy document. Engineers have also been freed from manual diagnosis: An investigation report now reaches the responsible regional team automatically, without pulling in colleagues across time zones.
The architecture also provides a central place to trace faults, which has accelerated service restoration. “Using AWS Cloud WAN plus AWS DevOps Agent helped us decrease mean time to recovery to under 10–15 minutes—a reduction of about 90 percent,” says Daniel.
IC is now extending AI across its infrastructure, including an agent that will inspect network traffic and report to its security engineers. With a network that it can manage through policy rather than maintenance, the brokerage has the foundation to keep building.
IC’s AWS Cloud WAN and AWS Direct Connect Architecture
Using AWS Cloud WAN plus AWS DevOps Agent helped us decrease mean time to recovery to under 10–15 minutes—a reduction of about 90 percent.
Sachin Daniel
Head of Cloud and Infrastructure, ICAWS Services Used
More Customer Stories
Did you find what you were looking for today?
Let us know so we can improve the quality of the content on our pages