Selected work · Financial services · Azure, AWS, GCP · 2022—2026

Rebuilding cloud posture management for a GCC bank

A regulated multi-cloud estate with no shared definition of risk. We built one — automated assessment, an agreed severity model, and a remediation cadence the regulator could follow.

The situation

A leading GCC bank had grown into Azure, AWS and GCP through separate delivery teams and separate assumptions. Each cloud was defensible on its own terms; none of them shared a definition of what a high-risk misconfiguration was. Regulatory reporting asked one question the estate could not answer: what is the current security posture, and is it improving?

What we changed

We built continuous configuration assessment across all three clouds and mapped every finding to CIS Benchmarks and the bank's own control catalogue, so a finding in GCP and a finding in Azure carried the same meaning. Severity was agreed with risk and audit before automation went live — the model came first, the tooling second.

Remediation ran on a cadence rather than a campaign. High-risk misconfigurations had owners, deadlines and an escalation path; recurring findings triggered a change to the landing zone baseline rather than another ticket. Where the same drift appeared twice, it became a guardrail in the pipeline.

Alongside the posture work

Zero Trust was extended across identity, data and workloads — Conditional Access, privileged access paths, and segmentation designed to limit lateral movement. Microsoft Purview and AIP gave data classification a shape the business could act on, and HSM ownership brought key custody under the same governance. Reference architectures were written to SABSA and TOGAF so future projects inherited the decisions instead of relitigating them.

What it produced

A measurable posture baseline, sustained reduction in high-risk misconfiguration, and a security architecture that could be explained to a regulator in one narrative rather than three. The most durable outcome was cultural: cloud teams began treating baseline drift as a defect in the platform, not a security team complaint.