The context
Cloud adoption in the Kingdom now carries a constraint that did not shape earlier migrations: data residency and sovereignty requirements determine where workloads can sit, and regulatory expectation assumes an organisation can evidence what it operates and where. Most cloud estates cannot meet that second requirement, because they were built project by project rather than designed.
A services group had moved a meaningful share of its workloads to cloud infrastructure over two years, each project with its own delivery team. Security had been applied at project level. The result was two environments and two unrelated security models, with no way to answer a question about the whole estate.
The trigger was an internal audit finding, not an incident. The auditor had asked which internet-facing services the organisation operated. Producing the answer took nine days, and the final figure was understood to be approximate.
That uncertainty was the actual risk. Cloud estates rarely fail because a control was configured wrongly. They fail because a resource existed that nobody knew about, provisioned by someone with legitimate access, outside any review.
The approach
ITBuilders began with posture assessment across all cloud accounts, including several created for short-term projects and never closed. Findings included storage exposed publicly by a default setting, credentials embedded in deployment templates, and permission sets granting administrative rights far beyond their use.
Remediation was sequenced by exploitability rather than severity score, which changes the order substantially and closes real exposure faster.
Architecture followed. The controlling principle was one security model expressed in both environments — segmentation, inspection, identity and logging designed once and enforced consistently on-premises and in cloud, rather than each environment secured in its own idiom. Consistency is what makes a hybrid estate auditable; two correct but different models produce the nine-day answer. Residency requirements were designed into workload placement rather than handled as an exception afterwards.
Identity was consolidated. Cloud access had been granted through separate account structures and several standing administrative credentials shared between engineers. This moved to federated identity with role-based, time-bound elevation and full session logging.
Guardrails replaced review. Policy-as-code now prevents non-compliant resources from being created — public storage, unencrypted volumes, unrestricted security groups — rather than detecting them afterwards. Preventive controls survive delivery pressure in a way review processes reliably do not.
Logging was centralised across both environments into a single pipeline, so an investigation spanning on-premises and cloud is one query rather than two reconstructions.
ITBuilders holds the Fortinet Engage Partner Specialization in Cloud Security. Hybrid work is where security most often falls apart in practice, because it requires competence in two environments and a design that holds across both. The credential speaks to assessed capability rather than a claim of cloud experience.
What changed
The group can now produce a current, accurate inventory of its internet-facing services on demand. Non-compliant resources are blocked at creation. The audit question that took nine days is answered from a dashboard, and the answer is exact.
Continuity of operation
ITBuilders continues to operate posture monitoring, maintain the guardrail policy set as new services are adopted, and produce the evidence the group presents at audit. Cloud estates change weekly. A posture assessment describes a moment; only continuous operation describes a position.



