
When Security Became the Brake on a Bank's Transformation
A major UK bank was racing to modernise its cloud platform. Security was supposed to be part of the process. Instead it had become the problem.
About the customer
This is one of the UK's major high street banks, undertaking a significant multi-year programme to modernise its technology infrastructure. The programme involved migrating legacy services and building new cloud capabilities across more than 250 AWS accounts, with dozens of DevOps teams working simultaneously on shared platform components — encryption services, vulnerability management, data storage, analytics — that would underpin the bank's digital products for years to come. The stakes were high. Internal customers were watching closely. Strategic deadlines were set at board level.
The situation
Security was supposed to be built into the programme from the start. In practice, it had become the bottleneck nobody knew how to fix. New services were being blocked days before they were due to go live, with urgent security demands that appeared out of nowhere. Engineers were frustrated by last-minute requirements that had been entirely foreseeable but somehow went unaddressed until the final moment. Product owners were missing deadlines. Internal customers were losing faith in the promise of fast, agile cloud delivery. And underneath all of it was a risk register that nobody trusted, because nobody really had a clear view of where the risks were.
The turning point
We started with a full audit of the AWS environment. With around 60 accounts at that stage, it was a substantial exercise — we had it done within a week — and it gave both us and the bank a clear view of the infrastructure risk picture. That fed into a risk register exercise they were running and laid the groundwork for what came next: threat modeling.
The first threat model covered a single critical workload. That session did something that months of audits hadn't managed: it got engineers, product owners, risk managers and security leads in the same room, talking about the same thing, agreeing on what actually mattered. The output gave everyone the clarity they needed to make fast, confident decisions. It also revealed something that would prove important across the whole programme — around half the security work those teams were doing was addressing things that weren't real risks at all.
"The Threatplane threat model has given us a totally new level of insight into the security of our infrastructure and how it affects our business, something that thousands spent on other consultants never gave us."
Head of Cloud Security
Scaling the programme
That first model worked well enough that they asked us to keep going. We ran one threat model a week at peak velocity, covering the full range of workloads being built across the platform — shared infrastructure, business-critical services, compliance-sensitive systems. Over the following years we delivered more than 70 threat models across the bank's cloud estate. Each one reduced duplication, redirected effort toward genuine risks, and gave the teams involved a shared understanding of where the real boundaries were.
The result
The transformation programme started moving again. Services launched on schedule. The risk register began to reflect reality. Teams that had been stuck second-guessing themselves now had a clear picture of what the security position was and where the red lines sat. Security stopped being the thing that slowed everything down and became the thing that gave teams permission to move faster.
70+
threat models delivered across the cloud estate
3x
faster security assurance for development teams
50%
of security work redirected from low-value tasks
Customer Perspective
"Threatplane transformed our security approach from a brake on development into an accelerator. The threat modeling process gave our teams exactly the information they needed to make fast, confident security decisions."
Cloud Platform Security Lead
"The Threatplane threat model has given us a totally new level of insight into the security of our infrastructure and how it affects our business, something that thousands spent on other consultants never gave us."
Head of Cloud Security
"The attention to detail the Threatplane team has shown really sets the bar. We've never experienced an external team coming in and providing such swift results. Bravo!"
Product Owner
"We have used Threatplane for threat modeling over many years and they've been so, so fast and helpful in getting new applications through our governance."
Product Owner
Security that accelerates, not obstructs
We help engineering teams understand exactly where they can move fast and where they need to slow down. The result is development that goes faster, not slower.
