VeUP
← All case studies
Financial Services · FinServ Well-Architected review
A regulated U.S. credit unionIdentity protected

A credit union migrates an ~800 GB core-banking database to AWS behind five gates

Well-Architected ReviewAdvisoryHigh-risk-issue remediation roadmapResilience-gap assessment (RTO/RPO)Observability-gap assessmentIncident-response program designRegulator-defensible risk evidenceCore-banking platform migrationPhased cutover with parity validationPreventive controlsInfrastructure-as-code foundationDay-2 runbooks & team enablementCost-optimization deep divePrivate connectivity & network isolationManaged billing & resellBlast-radius & tenancy isolation review
~800 GB
core-banking database migrated, reconciled, restore-tested
License retired
SQL Server Enterprise renewal avoided
Gated
no member traffic moves until five gates pass
Amazon ECS / FargateAmazon RDSAWS GlueGuardDuty + Security Hub

Anonymized production engagement — the customer’s name is held on file with VeUP and available on request.

VeUP delivered a six-pillar AWS Well-Architected Review for the credit union, surfacing five HIGH-risk findings (IR, DR, IAM, deployment readiness, observability) mapped to specific WA questions, plus a phased 90-day remediation roadmap and a 3-tier Security Accelerator with the Tier 1 security foundation delivered.

The challenge

As a regulated credit union, the customer operates under heightened expectations for data protection, business continuity, and operational resilience. Its containerized AWS estate had grown without an independent, framework-driven assessment; with only two people actively managing AWS it carried key-person dependency and limited capacity to formalize incident response, disaster recovery, and operational readiness. For a financial institution handling member financial data, undocumented gaps in IR, DR, and observability are compliance and member-trust exposure, not just technical debt.

The solution

VeUP ran a full AWS Well-Architected Framework Review across all six pillars — a structured, multi-session engagement in March 2026 built on the AWS Well-Architected Tool question set — producing an executive findings report and a phased 90-day remediation roadmap: Immediate (0–30 days), Short-term (30–60), Medium-term (60–90). The review took the estate as it actually ran: Amazon RDS, two production applications on Amazon ECS with AWS Fargate, scaled AWS Glue ETL, Amazon QuickSight, Amazon VPC with NAT Gateway, and Amazon CloudWatch, fronted by SSO/IdP-backed IAM across segmented production and workload VPCs. The roadmap then charted what a regulated institution should add: Amazon GuardDuty with AWS Security Hub, AWS Backup with cross-region replication, AWS IAM Identity Center with IAM Access Analyzer, AWS Organizations SCPs, and AWS X-Ray with CloudWatch Container Insights. A separate Jack Henry SQL Server database migration into AWS was delivered alongside the review.

Production outcomes

KPIResult
Production outcomesFull six-pillar Well-Architected Review delivered; five HIGH-risk findings identified and prioritized, each mapped to specific WA questions — SEC10 (no IR program), REL13 (absent DR strategy), SEC02/SEC03 (IAM deficiencies), OPS06/OPS07 (deployment & operational-readiness gaps), OPS04/REL06 (insufficient observability) — with concrete AWS-native remediations; a phased 90-day remediation roadmap; and the review’s architecture risks — single-AZ RDS, single NAT Gateway, ~50% IaC coverage, reactive-only monitoring — turned into a tracked backlog. A 3-tier Security Accelerator was delivered with Tier 1 — the highest-priority security foundation — live, establishing the base for phases 2 and 3.
Engagement windowOnboarded in January 2026; the multi-session Well-Architected Review ran through March, with the executive report landing in late March. Security Accelerator Tier 1 went live from April; the Jack Henry database migration was delivered in 2026; and the phased migration program continues under gated cutover governance.
Cost / TCO postureThe Jack Henry SQL Server migration was cost-comparison driven: SQL Server Enterprise license renewal avoided via the license-included SQL Server 2022 Standard path, compute right-sized against the measured workload, and AWS Budgets plus Cost Anomaly Detection standing guard on the production account.
Lessons & continuationFor a small-team regulated institution, the WAFR’s highest-leverage output is a sequenced 90-day roadmap that starts with credential rotation, AWS Backup cross-region replication, and GuardDuty + Security Hub enablement; map every finding to a specific WA question and a NIST SP 800-61-aligned IR plan to make the risk posture defensible to regulators.
AWS services in production
AWS Well-Architected ToolAmazon ECS / AWS FargateAmazon RDSAWS GlueAmazon QuickSightAmazon VPC + NAT GatewayAmazon GuardDutyAWS Security HubAWS BackupIAM Identity CenterAWS X-Ray