AWS Environment Setup For Tonkin+Taylor​

AWS environment setup for Tonkin and Taylor enables secure multi-account architecture, compliance adherence, and seamless cloud migration. Discover scalable infrastructure, optimized performance, and cost-efficient foundation for digital transformation.

Technologies

AWS

Use Case

Cloud Consulting

Industries

Land Engineering Firms

Location

Employees

Project Time
3 Months
  • May 2024 – Project Initiation
  • Jun 2024 – AWS Setup & Implementation
  • Jul 2024 – Handover & Documentation
Executive Summary

AWS Control Tower environment implemented with structured organizational units and service control policies to establish a secure and governed cloud foundation. The solution integrated AWS Config and Security Hub for compliance and monitoring, along with secure site-to-site VPN connectivity. Detailed migration planning, risk mitigation strategies, and comprehensive documentation ensured a smooth transition and scalable infrastructure for future applications.

Results & Impact

700+

Active Users

Active Users

24-48 hrs → 2- 4 hrs

Faster Time to Report

Faster Mean Time to Investigate

99.95%

System Up Time

System Uptime

44%

Requests Reduced

Requests Reduced

About Client

AWS Environment Setup

Tonkin + Taylor is New Zealand’s leading environment and engineering consultancy with offices located globally. They shape interfaces between people and the environment which includes earth, water and air. They have won awards like Beaton Client Choice Award for Best Provider to Government and Community-2022 and IPWEA Award for Excellence in Water Projects for the Papakura Water Treatment Plan-2021.

Project Background

Tonkin + Taylor were embarking on the journey for launching a full suite of digital products and chose AWS as their cloud environment. They wanted to create new applications and migrate to cloud services to improve scalability, availability, latency, and cost efficiency. They also aimed to accelerate digital transformation and build SaaS-based offerings. To achieve this, an AWS Environment Setup was required following best practices and compliance standards to serve as a foundation for future applications.

Scope & Requirement

In the first phase of the AWS Environment Setup, implementation was discussed as follows:

  • Setting up AWS environment for multi-account, multi-environment setup.
  • Ensuring all AWS accounts follow consistent policies and comply with legal and regulatory requirements.
  • Setting up connectivity between AWS accounts and on-premise networks.
  • Setting up AWS Security Hub to provide a comprehensive security view.
  • On-premise to cloud migration to modernize infrastructure, reduce costs, improve scalability, enhance performance, and ensure business continuity through a secure and reliable cloud platform.

Implementation

AWS Environment Setup

Technology and Architecture

Read more on the key components which defined the Architecture for AWS Environment Setup for Tonkin + Taylor

Technology/ Services used
  • We used AWS services and helped them to setup below
  • Cloud: AWS
  • Organization setup: Control Tower
  • AWS SSO for authentication using existing AzureAD credentials
  • Policies setup: Created AWS service control policies
  • Templates created for using common AWS services
Security & Compliance
  • Tagging Policies
  • AWS config for compliance checks
  • NIST compliance
  • Guardrails
  • Security Hub
Network Architecture
  • Site to Site VPN Architecture using Transit Gateway
  • Distributed AWS Network Firewall
  • Monitoring with CloudWatch and VPC flow logs
Backup and Recovery

Cloud systems and components used followed AWS’s well-Architected framework and the resources were all Multi-zone availability with uptime of 99.99% or more.

Cost Optimization

Alerts and notifications are configured in the AWS cost

Code Management, Deployment

Cloudformation scripts for creating stacksets and scripts for generating AWS services was handed over to the client

Challenges of AWS Environment Setup

  • It was a bit of a challenge to ensure the new environment meets all of the compliance criteria and still remain cost effective.
  • As per best practices we need to have a set of Unique machines and each may need to have its own VPC but that may incur a cost to the client. So we discussed and agreed for a specific 75% to be achieved which would be deemed as acceptable.
  • We have some non compliance being generated by standard AWS services
  • We got feedback from AWS support stating that Control Tower managed artifacts may appear non-compliant in conformance packs, but these are expected and should not be modified or deleted. These are treated as exceptions.

Support

  • 1 month extended support
  • A template for CloudFormation stack to create more AWS resources using the available stacks
  • Screen sharing sessions with demo of how the services and new workloads can be deployed
  • Offer support during the initial transition phase post-migration
  • Provide ongoing technical support, monitoring, and optimization services

Next Phase

We are now looking at the next phase of the project which involves:

  • Launching new digital products with the help of AWS environments which have been set up
  • Any ad-hoc change requests for managing the cloud environment

Project Timeline

  • May 2024 – Project Initiation
  • Jun 2024 – AWS Setup & Implementation
  • Jul 2024 – Handover & Documentation

If You Are Looking For Similar Services?

Project Navigation

Project Info

Location

Status

Completed
Recent Home

Get A Quote





    Get In Touch

    Address

    1904, 75 Victoria Street West Auckland 1010

    Related Projects

    ×

    Table of Contents

    Sign-Up to Become a Partner with uKnowva

    Benefits for Partner

    Acquire new customers and earn Steady Monthly Revenues.

    Our commission system will provide you with Competitive Revenue Streams.

    Add value to your customer with world-class HRMS Solution.

    Leverage uKnowva – A One-Stop HR Portal by scaling to global Clientele.

    Deliver Automated HR Solutions for a holistic digital transformation of customer’s HR processes.

    Get Started