Skip to content
CLD

Cloud migration

Regulated workloads moved with residency, key custody and exit obligations designed in, not retrofitted.

  • AWS
  • Azure
  • Landing zones
  • Terraform
  • Data residency
  • FinOps
Code
CLD
Class
A · 12 months and over
Engagement
TYPICAL 6-12 MONTHS · WAVE-BASED DELIVERY
Stages
05
Deliverables
06
Sections
06

Overview

Lift-and-shift makes the same platform more expensive. A full rebuild takes too long to justify. We size the move per workload and are equally willing to tell you a system should stay where it is. The constraints that actually govern regulated migrations — data residency, sovereign key custody, an exit plan your regulator will accept — are settled in the first four weeks, because retrofitting them is the expensive version. Orrery Health’s clinical data platform moved into two UK regions under NHS DSPT and GDPR Article 9 constraints, with patient data never leaving the country.

Benefits

05 points
  • A disposition per workload — retire, replatform, refactor or retain — with the cost and risk of each written down before anything moves.

  • Landing zone, network, identity and key management delivered as Terraform in your repositories. No console-clicked infrastructure and no consultant-held state files.

  • Residency enforced by policy rather than convention: guardrails that make a non-compliant deployment fail, instead of relying on someone catching it in review.

  • A cost baseline taken before, and measured after. Kestrel Energy’s run rate came in 38% below their on-premise total cost of ownership across the first full year.

  • A documented exit plan — how you would leave, what it would cost, how long it would take — because most financial regulators now ask to see one.

Workflow

05 stages
  1. Workload assessment

    Every workload scored on data classification, dependency depth, licence portability and change frequency. The output is a disposition and an estimated cost delta for each, including the systems we recommend leaving on-premise.

  2. Landing zone

    Accounts and subscriptions, network topology, identity federation, key custody, logging and guardrail policy — all delivered as reviewed infrastructure-as-code before a single workload moves.

  3. Pilot migration

    One representative, non-trivial workload end to end. It proves the runbook, the cutover window and the rollback, and it is where the estimate for every later wave comes from.

  4. Wave execution

    Workloads move in dependency-ordered waves. Each wave has a rehearsed cutover, a defined rollback trigger and a post-move validation checklist signed by the service owner.

  5. Optimise and hand over

    Right-sizing, committed-use discounts and storage tiering once real usage data exists, plus a cost dashboard your finance team can read without us in the room.

Deliverables

06 items
  • Workload disposition register with cost, risk and residency notes for every system.
  • Landing zone as Terraform: networking, identity, key management, logging and guardrail policy.
  • Rehearsed cutover runbooks per wave, with rollback triggers and named decision-makers.
  • Policy-as-code guardrails that block non-compliant regions, unencrypted stores and public exposure at deploy time.
  • Cost baseline and post-migration dashboard, broken down by service owner.
  • Regulator-ready exit plan: dependencies, timescale and estimated cost of leaving.

Questions

04 entries
  • No, but it constrains region choice, key custody and which managed services you can use. We resolve those constraints in week one and let them drive the design. For Orrery Health that meant UK-only regions, customer-managed keys in a UK HSM, and three otherwise-attractive managed services ruled out before anyone built on them.

  • Not automatically, and anyone quoting a percentage before seeing your workloads is guessing. Lift-and-shift usually costs more. Savings come from retiring dead systems, right-sizing against measured usage, and moving off per-core licences. We baseline your current total cost of ownership first so the comparison afterwards is honest.

  • Whichever your existing licensing, identity estate and staff skills already point at — that usually decides it, and the engineering difference between the two is far smaller than the difference in your team’s ability to run either. We deliver into both, and into on-premise Kubernetes where residency ruled cloud out entirely.

  • They stay, and we connect them properly: hybrid networking, identity federation and integration that does not depend on a VPN somebody configured in 2014. That work usually overlaps with our systems integration practice, and we scope it jointly rather than twice.

Start a project

02 locations

Enterprise systems consultancy

  • Manchester, United Kingdom
  • Oslo, Norway