Challenge
Buckeye State Bank, a community bank based in Columbus, Ohio, needed to move off a legacy hosting provider that was reaching end of life and would no longer be supported. As a regulated institution, the bank’s technology controls are subject to examiner scrutiny, but its lean internal IT team couldn’t staff 24/7 cloud security monitoring, patch governance, or backup oversight. Without a governed foundation, the bank had no way to demonstrate segregation of duties between who could make a change and who could audit it, and no proof it could recover critical systems and data after an incident. The bank also needed a partner that could make the work auditable, producing regular patching and security verification reports it could present directly to its board.
Solution
Aligned Technology Group designed and deployed an AWS Landing Zone Accelerator foundation for Buckeye State Bank, built around the governance examiners expect. The bank’s public website was then migrated onto that foundation with no downtime. ATG coordinated directly with the bank’s web design vendor so site changes landed alongside the infrastructure move. The landing zone and website migration were completed in about two weeks. ATG has provided 24/7 managed services since deployment, extending monitoring, security posture management, and backup oversight to each new workload as the bank moves more into the cloud.
Key Components
- Deployed a 10-account AWS Landing Zone Accelerator structure, separating workload accounts from governance accounts
- Isolated Audit, Log Archive, Backup Admin, and Central Backup accounts from Development, UAT, Production, Web, and Network accounts
- Enforced 12 preventive service control policies to maintain segregation of duties
- Configured 40 AWS Backup plans across production, UAT, development, and public web accounts
- Routed 100% of landing zone changes through AWS CodePipeline for a full audit trail
- Migrated the bank’s public website to Amazon Lightsail with Amazon CloudFront and AWS WAF, with zero downtime
- Established 24/7 security monitoring against FSBP and CIS benchmarks
- Delivered regular patching and security verification reports for board-level governance reporting
- Provided ongoing managed cloud operations that extend to each new workload
AWS Services Used
- AWS Control Tower / Landing Zone Accelerator – Governed multi-account foundation
- AWS Organizations – Account structure and service control policies
- AWS IAM – Identity and access management
- AWS Security Hub – Continuous security monitoring against FSBP and CIS benchmarks
- Amazon GuardDuty – Threat detection
- Amazon Inspector – Vulnerability management
- AWS Config – Configuration management and compliance tracking
- AWS CloudTrail – Audit logging and activity monitoring
- AWS KMS – Encryption key management
- AWS Backup – Centralized backup and recovery management
- AWS Transit Gateway – Centralized network connectivity
- AWS CodePipeline – Auditable change deployment
- Amazon Lightsail – Web compute and load balancing
- Amazon CloudFront – Global content delivery
- AWS WAF – Web application protection
Business Outcomes
- Examiner-ready segregation of duties, where previously none existed
- Documented backup and recovery coverage across every critical environment
- A complete audit trail for every infrastructure change
- 24/7 security monitoring without adding in-house security headcount
- Board-ready patching and security reports that give IT a documented governance trail
- A zero-downtime move off an end-of-life hosting provider in about two weeks
Strategic Impact
By building on a governed AWS landing zone and a managed services model, Buckeye State Bank replaced an unsupported hosting setup with a foundation designed for regulatory scrutiny. Its lean IT team now has the round-the-clock monitoring, recoverability, and audit evidence examiners and the board expect, without having to staff it internally. Because every new workload comes under the same governance and managed services umbrella, the bank can keep moving customer-facing services to AWS with confidence.