Concept 06
A cloud estate rebuilt to answer the questions an auditor asks.
- Sector
- Financial technology
- Disciplines
- IT Consulting, Cloud, Security
- Year
- 2025
- Status
- Concept project
The premise
A fintech scale-up has infrastructure in three accounts, provisioned by four generations of engineers, half of it by hand. Cloud spend rises every quarter without a matching rise in usage, and an enterprise security review is now blocking a major deal.
How we would approach it
- 01
Map what exists before proposing what should
Automated inventory across accounts, tagged to owners and workloads, so the conversation starts from evidence rather than memory.
- 02
Codify the estate
Everything that survives is expressed as infrastructure-as-code with review and rollback. Manual resources are either adopted or retired.
- 03
Make compliance a by-product
Identity, logging, encryption and network boundaries designed so that evidence for a security questionnaire is generated continuously, not assembled in a panic.
- 04
Attach cost to a team
Spend allocated to workloads and owners, with anomaly alerting, so cost becomes a decision instead of a monthly surprise.
What we would build
Multi-account inventory and risk register
Terraform baseline and landing zone
Continuous compliance evidence pipeline
Cost allocation and anomaly alerting
What it is meant to prove
Concept goal: make security review a repeatable export rather than a project, and turn cloud cost into an owned, attributable number.
Stated as an objective, not an outcome. This concept has not been delivered for a client, so there is no measured result to report — and we will not invent one.
Next concept
Meridian
Start a project
A first conversation is a conversation, not a pitch. Bring the problem in whatever shape it is currently in — we will tell you honestly whether we are the right people for it.
- Typical first engagement
- 2–3 weeks
- Working model
- Embedded, in your tools
- Reporting
- Weekly demo, monthly review
- Handover
- Documented, always