Velliv Completes Secure, Compliant Migration Using AWS
Operating in the highly regulated financial services industry, Velliv is one of Denmark’s largest pension companies, with more than 360,000 customers. When it separated from its parent company, Nordea, in 2018, Velliv had a chance to build a completely new, independent IT infrastructure.
Velliv chose AWS because it had the maturity to provide the cloud environment it needed. “Working with AWS helped us get wiser,” says Martin Eggert, applications architect at Velliv. “When I heard our big monolithic application was going on AWS, I thought that would be a challenge. However, Velliv enterprise architects, with guidance from our AWS Partner Cognizant, demonstrated that migrating to AWS was achievable. We completed the migration in only 1 year. It’s a great success that we got there in that time.”
The transparency of the AWS Management Console is very helpful to auditors. We can show them everything we have very quickly. AWS was very forthcoming to help us achieve the necessary security and compliance approvals, and in finalizing the documents.”
Head of IT Operations, Velliv
Moving On-Premises Legacy IT to the Cloud in One Year
The corporate reorganization away from Nordea meant that for data protection and compliance reasons, Velliv was not permitted to have access to its parent company’s core systems. That meant Velliv had to migrate all its existing IT—including Java applications, monolithic .NET applications running on Windows SQL server, file shares, its integration platform, and classical mainframe.
With support from AWS, Velliv was able to lift and shift its on-premises IT stack to take full advantage of a 100 percent cloud environment.
It started by moving familiar applications into the cloud, which ensured a simple transition to AWS. “The reliability and comfort of seeing something that was recognizable meant we could move out of on premises without having to transform everything,” says Peter Hvedstrup, head of IT operations at Velliv. “If that hadn’t been possible, we’d still be in Nordea for another 10–15 years at least. We were able to start small, lifting simple applications into similar IT infrastructure, and evolved from there.”
Meeting High Security Standards and Complying with Regulatory Requirements
Using AWS, Velliv delivered the high standard of security required by the Danish Financial Authority, which was confirmed by external audits. This allowed the company to meet all of the regulatory requirements for its data.
Data sovereignty was key to proving compliance. “The transparency of the AWS Management Console is very helpful to auditors,” says Hvedstrup. “We can show them everything we have very quickly. AWS was very forthcoming to help us achieve the necessary security and compliance approvals, and in finalizing the documents.”
Before its move to the cloud, Velliv had limited visibility into the cost breakdown of its IT systems, which made it difficult to budget for improvements. That’s no longer the case. “We can look at our AWS cost breakdown in great detail,” says Hvedstrup. “So we can start using the Swiss Army knife of new services and features because we can see exactly how much things cost.”
Using AWS has also given Velliv more insight into what’s going on in its systems through centralized log management using the Elasticsearch, Logstash and Kibana (ELK) stack on AWS. “We know the amount of traffic, types of traffic, and how to scale,” says Eggert. “We simply didn’t have this knowledge before, and were totally blind in some areas. This new world, with more insight, has helped us a lot. Nobody wants to go back to the old world in the basement.”
Velliv is now working on innovative high-level design solutions and learning directly from AWS architects how to create microservices based on fully managed AWS services such as Amazon Simple Queue Service (SQS), AWS Lambda, Amazon DynamoDB, and Amazon API Gateway. “If not for AWS, we’d need to get this advice from consultants, which is very expensive,” Eggert says. “So we’re growing our AWS knowledge.”
Trying Out New Hardware and Attracting New Talent with the Flexibility of Cloud
Velliv can now spin up production environments for exploratory testing of more powerful hardware, such as an updated SQL server, to see if that’s a viable route. “If we’d bought it and found out it wasn’t viable, we’d be stuck,” Eggert says. “We can react very quickly. Before AWS, it would have taken us half a year to plan and execute a hardware upgrade of the SQL server. Using AWS, an exploratory upgrade took a weekend.”
Velliv is now exploring microservices and event-driven architecture. “Recently, we’ve been solely focused on the migration,” Hvedstrup says. “But now we have more time to start exploring new capabilities—such as using more infrastructure as code to deploy new architecture—to benefit ourselves in the future. We’d never be able to do that on premises. Our testing is reliable too, because our cloud environments are consistent. In the old days, there were always differences.”
Velliv’s new cloud environment is also making recruitment easier. “It’s more fun in the cloud,” says Eggert. “It’s easier to recruit new talent. Good developers are attracted by DevOps culture, and the possibilities that AWS can offer. We’re playing in a sandbox.”
Velliv is one of Denmark’s largest pension companies, with more than 360,000 customers. It has been awarded Best Commercial Pension Fund of the Year in Denmark by FinansWatch and EY in 2018, 2020, and 2021.
Benefits of AWS
- Company can scale proactively to business needs
- System meets high standards of security
- Developers spend less time on infrastructure tasks
- Better visibility into IT costs and usage
- Faster time-to-market using managed AWS services
AWS Services Used
Amazon Simple Queue Service
Amazon Simple Queue Service (SQS) is a fully managed message queuing service that enables you to decouple and scale microservices, distributed systems, and serverless applications.
AWS Lambda is a serverless, event-driven compute service that lets you run code for virtually any type of application or backend service without provisioning or managing servers. You can trigger Lambda from over 200 AWS services and software as a service (SaaS) applications, and only pay for what you use.
Amazon DynamoDB is a fully managed, serverless, key-value NoSQL database designed to run high-performance applications at any scale. DynamoDB offers built-in security, continuous backups, automated multi-Region replication, in-memory caching, and data export tools.
Amazon API Gateway
Amazon API Gateway is a fully managed service that makes it easy for developers to create, publish, maintain, monitor, and secure APIs at any scale. APIs act as the "front door" for applications to access data, business logic, or functionality from your backend services.
Organizations of all sizes across all industries are transforming their businesses and delivering on their missions every day using AWS. Learn more about leveraging AWS's years of experience in building your organizational, operational, and technical capabilities, so that you can gain business benefits faster.