A start-up EV charging company, which was bought by a larger energy company as part of a major acquisition.

Securing Merged AWS Environments Post-Acquisition

As part of this acquisition, the companies AWS environments were merged into the larger corporate environment along with the existing development and support teams. However, the security status of the new systems was still largely unknown, but they were required to meet corporate security requirements. This created a risk which needed to be mitigated, so Hydras, a part of the Acora Group, were brought in to provide strategic security direction with the aim of highlighting security gaps along with a prioritised roadmap to close them.

Strategic Security Assurance

Hydras AWS Security Consultants worked directly with the company’s management and technical teams to meet the aim. Hydras followed its standard assurance process, which consisted of firstly performing a “discovery” phase, the aim of which is to understand the current state of the in-scope environment. This included identifying the technical environment, the organisation (people) and any associated security processes and procedures, as well as the corporate security requirements. Armed with this information, Hydras then proceeded into the review phase, the aim of which is to review the environment against corporate security requirements and understand the “as-is” and “to-be” states so that gaps can be identified and an improvement plan created. This was performed by creating several streams of work that included architectural deep dives, threat modelling, security vulnerability and posture scanning and DevSecOps reviews.

Hydras was able to understand the current state of the environment, review this against the desired state and highlight gaps and risks. Finally, a report was produced that highlighted all the security gaps along with strategic recommendations on how to resolve them, prioritised by security risk. Hydras were then engaged in a second piece of work to provide security assurance on the implementation of this strategy, ensuring that the desired outcome of meeting corporate security requirements was met.

Risk Reduction and Compliance in Merged Cloud Platforms

By analysing the current maturity of security within the EV company, Hydras was able to create and oversee a strategic security initiative to help reduce risk and meet corporate security requirements.