About the Company
A leading financial solutions provider in Indonesia, offers a range of services including consumer financing. Established in 1989 the company has expanded its presence across the nation, committed to delivering innovative and customer-centric financial solutions that empower business growth.
The Challenges
In 2023, the company faced the critical challenge of migrating their core system to the cloud. Key objectives included ensuring flexibility in resource management and addressing security needs with various products available on cloud marketplaces. The cloud migration was not just about operational flexibility but also about enhancing cybersecurity in a rapidly evolving digital environment. One of the core challenges was ensuring that the newly deployed cloud infrastructure was resilient against modern cyber threats.
Furthermore, the company needed had to comply with regulatory standards related to data protection, ensuring the safety of sensitive customer information. This included implementing secure data handling practices, incident response protocols, and disaster recovery mechanisms, all while migrating to a new environment. The challenge was ensuring that these cybersecurity controls were seamlessly integrated into the cloud infrastructure.
“Our primary focus was to ensure regulatory compliance, including incident response protocols, establishing clear Standard Operating Procedures (SOPs), and performing regular disaster recovery (DR) drills. The challenge here was ensuring that these essential security practices were in place from the start of the migration while keeping pace with the project’s rapid deployment”, said the company’s IT Infrastructure Manager.
CDT Proposed Solutions
To address the the company’s cybersecurity challenges during their cloud migration, CDT provided several solutions focused on ensuring robust security and compliance, with a strong focus on preventing cyberattacks that is AWS Web Application Firewall (WAF). With AWS WAF, the company was able to monitor and control HTTP(S) requests to their web applications. AWS WAF enabled custom rule creation for filtering traffic based on IP addresses, URI strings, and other customizable parameters.
In addition to WAF, CDT also conducted a Well-Architected Review (WAR) to evaluate the company cloud infrastructure’s security posture. This review categorized risks as high, medium, or low, allowing the company to prioritize and address vulnerabilities accordingly. The WAR also helped identify areas where security could be improved and provided guidance on how to maintain a secure environment moving forward.
Results and Benefits
The deployment of AWS WAF successfully met the company’s primary goal of preventing common cyberattacks. By using custom filtering rules, the company effectively mitigating the risks associated with threats identified in the Open Web Application Security Project (OWASP) Top 10. With WAF, they can manage to lay a strong foundation for more advanced security measures in the future.
They successfully passed audits, proving that their security and compliance measures were effective. Notably, no security incidents occurred in previous years, highlighting the robustness of their current approach. CDT’s role as partner, conducting assessments and offering remediation ensured that the security measures remained balanced and efficient. The partnership also helped establish a long-term IT Security Roadmap, ensuring the company continues to improve and mitigate risks proactively sustain long-term protection while adapting to evolving threats.