VeUP
← All case studies
AWS Control Tower Service Delivery · Well-Architected Framework Review
An energy-sector fibre-optic-sensing technology companyIdentity protected

Energy-sensing platform: a 57-question WAR maps a Top-5 AWS remediation roadmap

Well-Architected ReviewAdvisoryHigh-risk-issue remediation roadmapResilience-gap assessment (RTO/RPO)Observability-gap assessmentBlast-radius & tenancy isolation reviewCost-optimization deep diveTarget-state architecture design & costed POCManaged billing & resellRightsizing & instance-family modernizationCommitment & RI optimizationStorage tiering & lifecycle policiesStanding cost-optimization mechanism
Accepted
Top-5 remediation roadmap adopted by the customer
~$700/mo
savings surfaced in the Cost Deep Dive
57
review questions answered across all six pillars
AWS Control TowerAWS Well-Architected ToolAmazon CloudFrontAWS Savings Plans

Shared anonymously — the customer’s name is held by VeUP and available on request.

VeUP put the customer’s fibre-optic-sensing workload — monitoring critical energy infrastructure — through a full 57-question AWS Well-Architected Framework Review, distilled 43 high-risk and 14 medium-risk findings into a Top-5 roadmap the customer accepted, proposed an AWS Control Tower landing zone, and found ~$700/mo of savings in a Cost Deep Dive.

The challenge

The customer runs a fibre-optic-sensing workload on AWS that grew up in a single account and a single Region. Production, staging, and development shared one AWS account and VPC with overlapping CIDR ranges and no traffic inspection; there was no disaster-recovery plan and data lived in one Region with no replication or S3 backups; monitoring was reactive (the team often learned of problems from client complaints); components were tightly coupled with no auto-scaling; and encryption, data-classification, and least-privilege controls had gaps. The company needed a clear-eyed assessment and a prioritized plan to mature its operations without over-spending.

The solution

VeUP took the customer's entire AWS estate through the full Well-Architected Framework Review — 57 questions answered, surfacing 43 high-risk and 14 medium-risk issues — and distilled the findings into Top-5 Strategic Priorities: isolate environments and secure the network boundary; establish disaster recovery and encrypted backups; add proactive monitoring and a formal incident-response framework; build workload resilience and high availability through loose coupling and auto-scaling; and enforce data protection with centralized identity, least privilege, and an encryption mandate. To execute the isolation priority, VeUP proposed an AWS Control Tower landing zone for multi-account governance, separating prod/staging/dev into dedicated accounts and discrete VPCs to shrink the blast radius. A Cost Optimization Deep Dive reviewed Savings Plans coverage gaps on T-class/CPU-credit instances, right-sizing of P3 (GPU) instances used for an MLOps experimentation environment, Amazon S3 Intelligent-Tiering, snapshot hygiene, and outbound-traffic economics — including moving data-out through Amazon CloudFront rather than direct egress.

Production outcomes

KPIResult
Production outcomesA complete Well-Architected Framework Review — 57 questions answered, 43 high-risk and 14 medium-risk findings — distilled into a Top-5 remediation roadmap that the customer accepted; an AWS Control Tower landing-zone proposal to establish multi-account isolation and governance; and a Cost Optimization Deep Dive that surfaced an estimated ~$700/month saving by routing outbound traffic through Amazon CloudFront instead of direct egress, plus per-instance right-sizing and S3 Intelligent-Tiering reductions. The customer's AWS environment stayed healthy throughout.
Engagement windowThe advisory cadence began in November 2025. By late February 2026 the customer had the full review, an accepted Top-5 roadmap, the Control Tower proposal, and the Cost Deep Dive in hand — and the relationship continues.
Cost / TCO postureThe Cost Optimization Deep Dive surfaced ~$700/month from a CloudFront-vs-direct outbound-traffic move (CloudFront materially cheaper data-out), plus per-instance right-sizing (e.g. ~$0.50/day per instance moving off T-class to an M6a instance), Savings Plans coverage gaps on CPU-credit/T3 instances, P3 (GPU) right-sizing for the MLOps environment, and S3 Intelligent-Tiering reductions. All figures are itemized estimates from the deep dive.
Lessons & continuationFor a workload that grew up in one account and one Region, the highest-leverage move is environment isolation via a Control Tower landing zone (dedicated prod/staging/dev accounts and VPCs) to shrink the blast radius. VeUP is tracking with the customer which Top-5 remediations have landed and what the realized total saving comes to.
AWS services in production
AWS Control TowerAWS Well-Architected ToolAmazon EC2Amazon RDSAmazon S3 Intelligent-TieringAmazon CloudFrontAWS Savings Plans

Architecture

The review's Top-5 remediations, drawn as one target architecture: an AWS Control Tower landing zone separating prod/staging/dev into dedicated accounts and VPCs, with centralized IAM least privilege, KMS encryption, Multi-Region DR and encrypted backups, EC2 Auto Scaling with RDS multi-AZ failover, proactive monitoring and incident response, and the Cost Optimization Deep Dive's CloudFront, Savings Plans, and S3 Intelligent-Tiering moves.

Target-state AWS architecture: an AWS Control Tower landing zone with AWS Organizations guardrails separating prod, staging, and dev accounts, AWS WAF at the network boundary, centralized least-privilege IAM, KMS encryption, S3 Intelligent-Tiering, a multi-Region DR target with AWS Backup, and a two-Availability-Zone VPC running the fibre-optic-sensing workload on auto-scaling EC2 with Multi-AZ RDS — ringed by proactive monitoring, an incident-response framework, CloudFront outbound routing, Savings Plans, and GPU right-sizing.
The Control Tower target state — dedicated accounts for prod, staging, and dev, with the review's Top-5 remediations built in.

What the review surfaced, pillar by pillar:

Operational Excellence
  • Proactive monitoring: KPI dashboards, alerts, runbooks
  • Formal incident response replaces client-complaint discovery
Security
  • The top-priority pillar — 43 high-risk findings tracked
  • WAF at the network boundary
  • Centralized least-privilege IAM; KMS encryption mandate
Reliability
  • Multi-region DR with defined RTO/RPO
  • Encrypted backups
  • Auto Scaling and RDS Multi-AZ end tight coupling
Performance Efficiency
  • Auto Scaling loosens compute coupling
  • GPU right-sizing for ML experimentation
Cost Optimization
  • Cost Deep Dive flagged a CloudFront outbound-route saving
  • Savings Plans gap and S3 Intelligent-Tiering
  • Per-instance right-sizing