Executive Summary
A leading government-owned bank in Indonesia set out to build an AWS
environment that could scale on demand, meet strict security expectations, and be
stood up or torn down quickly to keep costs under control. Working alongside AWS
and PT Mastersystem Infotama Tbk, we designed and delivered an AWS Landing
Zone that provides the secure, well-governed foundation needed to meet those
goals. The outcome is an environment that is fast to provision, cost-efficient to
operate, and secure by design, ready for the Bank’s immediate testing needs while
laying the groundwork for its broader cloud journey. More than a one-off
deliverable, it gives the Bank a repeatable, policy-driven pattern for adopting AWS
safely as its needs grow.
Case Study
The Bank needed a secure, scalable, and cost-effective AWS environment to
support its evolving IT landscape. Its existing reliance on on-premise infrastructure
had become a constraint: capacity was tightly allocated to production workloads,
procurement cycles were long and poorly suited to short-term needs, and
resources could not be scaled up or down on demand. To move past these
limitations, the Bank began evaluating AWS as a future provider of computing
capacity. Such a move called for a strong security framework, one that could
integrate cleanly with the existing production environment and stand up to a rising
tide of cyber threats. Equally important was cost discipline: unlike on-premise
systems, where idle capacity still carries a cost, the chosen AWS solution had to
deliver on-demand scalability, efficient use of resources, and rigorous protection of
sensitive data, all while keeping testing operations running without interruption. In
short, the Bank wanted a foundation that could keep pace with its ambitions
without compromising the control expected of a regulated institution.
Solution
In response to this need, Mastersystem collaborated with Amazon Web Service to
create a secure, scalable, and cost-effective testing environment tailored to
customer needs.

In the initial phase, addressing the security imperative, the AWS Landing Zone was developed as a foundational element for security within the AWS Cloud. The AWS Landing Zone is constructed using multiple AWS Services, which are supporting services in its creation. Due to the use of multiple accounts in the creation of this landing zone, an AWS Organization is required as an account orchestrator. To ensure a secure environment, an AWS Service is employed to create access rights and grant these access rights to related users. This process utilizes the AWS IAM Identity Center. Additionally, a secure environment provides protection against activity logs in the environment. To address this, AWS CloudTrail Trail Log and VPC Flow Log are used, which are stored in Amazon S3. Regarding network security, AWS Network Firewall is employed to safeguard traffic traversing this environment. Amazon GuardDuty serves as an intelligent threat detection system, monitoring malicious and unauthorized activities in existing accounts and workloads. Beyond threat detection at the network and account level, application security plays an equally important role in protecting a banking environment. Amazon Inspector is integrated to perform continuous, automated vulnerability management across Amazon EC2 instances and container images running in the environment. Inspector continuously scans workloads for known software vulnerabilities and unintended network exposure, providing the security team with actionable findings that can be remediated before they pose a real risk. These findings are automatically aggregated and surfaced through AWS Security Hub, which acts as the centralized security posture management dashboard across all accounts in the Landing Zone. Rather than switching between accounts to review each alert individually, the bank’s security team gets a consolidated, prioritized view of security findings and compliance status from a single pane of glass. To round out this application security layer, AWS Config continuously tracks and evaluates AWS resource configurations against a set of predefined compliance rules. This ensures that any resource deployed across the environment remains aligned with the bank’s internal security policies and applicable regulatory requirements. Any configuration drift is detected and reported in near real-time, enabling the team to respond quickly. Together, Amazon Inspector, AWS Security Hub, and AWS Config form a cohesive application security framework that extends protection beyond the perimeter — covering vulnerability management, compliance monitoring, and centralized findings across all workloads and accounts. Following the establishment of the initial Landing Zone phase, the subsequent step involves the creation of a testing environment. This environment employs RedHat OpenShift on AWS, a platform that offers scalable resource availability through its integration with Amazon EC2, facilitating seamless scaling. This scaling utilizes all availability zones within a single region. ROSA employs a pay-as-you-use licensing model, which is advantageous for on-demand environments that are not operational 24/7. The cost is incurred only when the license is used and when the environment is turned off, there is no cost. The combination of ROSA and EC2 ensures cost-effectiveness and time-effectiveness, as they can be completely shut down and rebuilt in a relatively short time.
Project Timeline
This environment did not come together overnight; it was delivered over a focused twelve-month engagement that ran from 23 July 2024 to 23 July 2025. The opening months were spent on discovery and design, working side by side with the Bank to map the existing on-premise workloads, agree on the multi account structure, and translate the Bank’s security and regulatory obligations into a concrete Landing Zone blueprint. By the final quarter of 2024, the foundational accounts, the AWS Organization, and the IAM Identity Center had been provisioned, with the core guardrails of centralized logging, AWS Config rules, and network controls already in place and verified.
Through the first half of 2025, attention shifted to standing up the testing environment on RedHat OpenShift Service on AWS and Amazon EC2, embedding Amazon Inspector, AWS Security Hub, and Amazon GuardDuty into everyday operations, and rehearsing the build-and-teardown cycles that ultimately proved the cost model. The closing weeks, leading up to 23 July 2025, were reserved for knowledge transfer, documentation, and a joint review with the Bank’s security and infrastructure teams, so that ownership of the environment could be handed over with confidence.
Benefit and Result
Utilizing AWS Landing Zone, AWS Infrastructure, and AWS Managed Service provides the Bank with a secure, scalable, and cost-effective AWS environment. This combination offers the Bank several advantages that can help accelerate its business. The AWS multi-account approach, equipped with AWS Organization, offers the Bank several benefits, including the ability to more easily create new AWS accounts to separate workloads. In the past, creating a new AWS account was a time- consuming process that took hour. However, with AWS Organization, the same process is now completed in a matter of tens of minutes. This results in a time efficiency ratio of over 60%. The AWS Landing Zone, equipped with the AWS IAM Identity Center, offers a number of advantages. Previously, if users did not use the single sign-on method, at least five account passwords were required. With the IAM Identity Center, however, only one password is needed to access various AWS accounts with pre- adjusted access rights in the IAM Identity Center via the Permission Set.

