man holding children
Case Study

An Insurance Company's Governed AWS Foundation on Guidewire Cloud

Building a secure landing zone for fewer surprises

September 21, 2026

AWS

Insurance

The Claims Desk 

This specialty insurance group falls under the umbrella of a larger insurance group that serves commercial customers through an extensive service portfolio. As a longtime  Guidewire customer, the client needed to move its Guidewire policy and claims systems from on premises Guidewire Cloud to AWS. Its goal was to simplify IT, adapt to changing market demands, and create value for policyholders, agents, and brokers.

A Coverage Gap 

Core workloads and operations had to continue, even as infrastructure changed. 

Operational Stakes. The client’s existing Guidewire environment was on premises, but the target state was Guidewire Cloud on AWS. Before the migration could proceed, the client would first need a production-ready AWS foundation in place. 

Sensitive Workloads, Consistent Controls. Policy and claims environments require governance, centralized logging, encryption, and security monitoring. All of this would need to be available for the client in the new AWS environment. 

Connectivity Requirements. To succeed, the migration would also need a secure and performant path for a 600 GB Guidewire datastore, along with network architecture that could support multiple Availability Zones, Regions, and future workloads. 

Establishing Patterns. The migration was only the first step. Once this phase was completed, the client hoped to keep modernizing with repeatable account creation, workload onboarding, cost visibility, and operational management. 

Insurance knows how to evaluate a situation and determine how the odds stack up. In this case, multiple potential risks were in play: migration delays, disruptions to policy and claims processing, and inconsistent controls around sensitive insurance data. To account for all of this, the client needed a partner who could connect its cloud strategy to the practical work of networking, security, and day-to-day operations. 

A Better Policy 

This engagement aligned with three areas of AHEAD’s expertise. 

  • Platform & Workload Modernization: Designing and implementing a multi-account AWS foundation for hosting Guidewire Cloud and future insurance workloads. 
  • Secure & Resilient Architectures: Using AWS Control Tower, AWS Organizations, multi-Availability Zone, and more to design guardrails around regulated workloads. 
  • Operational Excellence: Creating a repeatable way to provision, validate, monitor, and extend the environment. 

The work unfolded across three phases: 

Advise 

AHEAD and the client began with a series of discovery and design workshops. Teams reviewed the current AWS environment, as well as its cloud standards, security requirements, and backup and recovery expectations. This helped establish the target architecture for Guidewire. The design included primary and secondary Regions, with governance for managing other Regions restricted through regional-deny controls. The network plan used a hub-and-spoke model with AWS Transit Gateway, with AWS Direct Connect selected for the intended database migration and connectivity workload. 

Why the Groundwork Mattered: By having the important conversations right at the start, the client was able to kick off its Guidewire migration with documentation in place around security, network, identity, and operational decisions. The strategy work also addressed cost-sensitive decisions early on, like organizing accounts or how identity should flow into AWS. 

Build 

AHEAD and the client then began translating the design into a production-grade AWS landing zone using AWS Control Tower and AWS Organizations. Dedicated Audit and Log Archive accounts provided centralized administration and logging, with workload accounts and organizational units creating boundaries around identity, shared services, production, non-production, and Guidewire-related resources. 

The client’s Okta enterprise federation was integrated with AWS IAM Identity Center using SCIM provisioning and AD-group mappings. Instead of relying on shared or long-lived IAM users, teams could use role-based permission sets that aligned to their responsibilities. Security and compliance capabilities were enabled as well through AWS Security Hub, Amazon GuardDuty, AWS Config, AWS CloudTrail, and AWS Key Management Service. CloudTrail activity was aggregated into the Log Archive account, with encryption keys separated by workload and environment.  

To safely migrate the 600 GB Guidewire datastore, AWS Backup was configured for organizational daily backup policy and 90-day retention. Additionally, Terraform Cloud and GitHub Actions automated provisioning and validation across bootstrap, governance, and security stacks. 

How It Came to Life: The landing zone was a governed, automated AWS platform with the connectivity, security, and infrastructure-as-code needed for the client’s workloads. 

Run 

With the repeatable operating model delivered, the client could now manage what was already in AWS while preparing to onboard what comes next. This can include tuning backup retention, cost thresholds, security controls, and disaster recovery requirements as both the Guidewire program and cloud strategy evolve. 

How It Kept Delivering: The model is intentionally extensible and built to support the client’s long-term aspirations to keep growing, without constant reinvention. 

Fully Covered 

The client is now well-positioned for current and future workload migrations. 

A Security Baseline. AWS Security Hub is enabled for the client’s full organization. Centralized Security Hub, GuardDuty, Config, and CloudTrail all provide visibility that’s organization-wide. And the new environment has recorded an initial CIS AWS Foundations Benchmark score of 37%, which means the client has a baseline for ongoing review and hardening. 

A Repeatable Way to Scale. Terraform Cloud, GitHub Actions, Account Factory, standardized tags, and centralized services give the client a pattern for provisioning and managing its accounts and workloads in AWS. Budget and cost concerns have been addressed with anomaly detection as an early warning system for excessive cloud consumption. Resources are also easier to identify, manage, and associate with ownership, thanks to standardized naming and tagging. 

A Stronger Migration Runway. Multi-Region governance, multi-Availability Zone design, Transit Gateway connectivity, and redundant Direct Connect circuits have each created the building blocks the client needs for continuing its Guidewire datastore migration and future workloads. 

What’s Next 

The client can continue modernization, while keeping governance, security, cost visibility, and operations controlled across its environment. Its next migration is already safer, more visible, and less improvised than the first wave. With each workflow, the client can redefine its recovery objectives, testing approach, and operational requirements. 

That's the payoff of a good landing zone: turning cloud modernization from a single migration event into a repeatable capability. For insurers struggling to balance legacy complexity with regulations, AHEAD brings the architectural discipline and hands-on engineering needed to build a foundation that holds up in practice. 


Case Study: Insurance Company AWS Foundation | AHEAD | AHEAD CMS