
Landing zones that survive an audit
A pragmatic walkthrough of multi-account AWS landing zones built for SOC 2 and ISO 27001 — what to centralise, what to delegate, and where automation pays back fastest.
Most landing zones fail audit not because of missing controls, but because nobody can produce the evidence on demand. The fix is architectural: design so that evidence is a query, not a screenshot exercise.
Centralise the boring things
Identity, networking, logging and billing belong in dedicated accounts owned by a small platform team. Push everything else into workload accounts where teams move fast inside guardrails. This split is what makes both auditors and product engineers happy at the same time.
Treat guardrails as code
Service Control Policies, IAM permission boundaries, AWS Config rules and CloudTrail organization trails should all live in version control alongside the landing-zone Terraform. A pull request is the only legitimate way to change a guardrail — and the diff IS the audit trail.
Make evidence cheap
Aggregate CloudTrail, Config, GuardDuty and access-analyzer findings into a single security account with Athena or a SIEM on top. When the auditor asks 'show me every privileged role assumption in Q1', the answer is one query, not a six-person scramble.
Where automation pays back fastest
Account vending, baseline IAM, network attachment and break-glass paths. Each of these is high-friction when manual and high-risk when inconsistent. Automating them removes a class of human error and frees the platform team to work on the genuinely hard problems.
More insights
SLOs without the theatre
How to define error budgets that engineers actually use, and how to wire them into deployment decisions instead of quarterly slide decks.
Read SecurityZero-trust network design for hybrid estates
Identity-aware proxies, private service connect and short-lived credentials — a practical pattern set for organisations migrating off perimeter security.
Read AI infrastructureGPU platforms that pay back
Capacity, scheduling and cost controls for shared GPU estates running mixed training and inference workloads across teams.
ReadLet's talk
Ready to build a platform that scales?
Book a free 30-minute discovery call to review your infrastructure and map out clear recommendations.
- 30-minute discovery call, no obligation
- Architecture review with concrete clear recommendations
- Independent consultancy, direct, hands-on advice