Home » Case Studies » UK Home Office

UK Home Office

AWSCloud PlatformObservabilityFinOpsDevOpsGovernanceAI

Engagement Overview: Product and Delivery Lead in a crucial cloud transformation programme focused on modernising and enhancing the infrastructure used by vital law enforcement agencies across the UK. Delivering key solutions within a multi-tenanted cloud hosting platform, with an emphasis on scalability, security, resilience, and cost optimisation, ultimately supporting improved policing outcomes.

£3.6M+Cloud cost reduction
4.3/5AWS Landing Zone Assessment
10% to 70%Tagging compliance uplift
1Unified Observability & Monitoring eco-system

FinOps

Problem

The platform’s cloud spend was accelerating with minimal visibility, an outdated charging model and no clear ownership of financial decisions across teams. This resulted in poor assessment ratings and a pressing need to regain control, stabilise costs, implement effective governance and embed a FinOps-by-Design operating model.

Outcome

Accelerated the programme’s FinOps maturity, ranking LECP among the highest-scoring Home Office cloud platforms in external assessments and achieving 4.3/5 in the AWS Landing Zone assessment.

Reduced platform spend by over £300,000 per month (£3.6M+ annually) through Re-artchitecting services, Licence management, Savings Plans and Reserved Instances for compute and databases, removing unused VPC endpoints and dormant accounts, migrating to Graviton, Instance Scheduling (cutting non-production costs by 60%) and automated EBS clean-ups. Increased cost visibility and transparency through QuickSuite dashboards with stakeholder buy-in.

Implemented a usage-based recharging model, replacing t-shirt sizing with fair, transparent allocation tied to actual consumption, making the platform cost-neutral and giving tenants clear ownership of their spend.

Managed a new tagging policy and drove platform-wide compliance through pipeline enforcement, change-process stage gates, Terraform fragments, CAB tagging controls and compliance dashboards. Achieving 100% compliance on newly deployed resources and raising overall team compliance from under 10% to 70%, giving a clearer view of cost allocation and security posture.

Defined and introduced Platform KPIs across Reliability, Cost Control, Security, Efficiency, Modernisation and Sustainability, reported through dashboards and governance packs to set baselines and target underperforming areas.

Integrated Claude via Amazon Bedrock into the platform with full cost controls: budgets, per-user consumption tracking, dashboards and alerting, enabling safe, governed AI adoption without runaway spend. Introduced ML-based anomaly detection and Amazon Q Developer as part of the modernisation roadmap.

Embedded cost governance throughout the lifecycle, including anomaly detection with end-to-end tracking into Jira, plus per-team and platform budget controls and applying a FinOps-by-Design approach from the earliest design stages.

Observability

Problem

Observability was fragmented, with teams building bespoke monitoring and alerting instead of adopting a shared, scalable approach. There was no unified alerting, limited automation, no obsolescence tracking or resilience checks, and a costly, resource-intensive Splunk estate. The team’s scope was too narrow to provide meaningful end-to-end visibility or governance.

Outcome

Defined a 24-month roadmap balancing critical monitoring gaps with modernisation and AI adoption (Amazon Q Developer, ML-based anomaly detection). Consolidated Operational and Protective Monitoring into a single team to strengthen scope, governance and visibility.

Delivered a shared Alert Manager that standardised alert ingestion from multiple sources, enriched and routed them into ServiceNow, Jira and email. This let teams and tenants deprecate their fragmented, unreliable in-house solutions in favour of a single scalable service, onboarding quickly, reducing operational risk and ensuring critical alerts were consistently captured and actioned.

Integrated AWS Health and Security Hub alerting into Alert Manager, routing health events and security findings directly into team Jira backlogs so they could be triaged and resolved as part of normal delivery.

Automated AWS Health and Security Hub reporting for senior leadership, platform and security teams, surfacing health scores by team and ownership, leaderboards, impact assessments, and vulnerability counts with clear owners, suppressions and addressable actions.

Built a Platform Health Dashboard as the single source of truth for current availability, live incidents and historic outage events.

Migrated Splunk to Home Office Central and replaced the legacy Monitoring-as-Code stack (Amazon Managed Grafana and Prometheus) with a cloud-native CloudWatch approach, providing a service wrapper and templates that empowered teams to define their own alarms and dashboards. This decommissioned duplicated infrastructure and licences for multi-million-pound savings (40% of current Splunk spend).

Product and Tech Consultancy
Dhanish Mahmood
Principal Consultant

Product strategy, cloud expertise and full-stack delivery for complex environments.

© 2026 productandtechconsultancy.com. All rights reserved. Available from July 2026