Case Study
DataNet Modernizes and Automates its AWS Environment with Secure Multi-Account Architecture
Industries
About DataNet
DataNet focuses on the operational side of data management, helping organizations bridge the gap between thousands of disparate, unstructured contracts and executive-level decision metrics. Founded by a team with deep roots in database and software development, DataNet helps organizations manage complex lease and contract portfolios across telecom, commercial real estate, energy, data centers, and transportation. With 25+ years working inside data-heavy, compliance-focused businesses, DataNet transforms scattered lease agreements, right-of-way contracts, and vendor obligations into structured, searchable systems. These systems support workflow automation, compliance, visibility, reporting, and financial optimization. Learn more at www.datanet.com.
Challenge
DataNet's Key Business Objectives
DataNet provides high-stakes infrastructure data management for the Telecom, Energy, and Transportation sectors. To deliver high-integrity insights for asset valuation, risk modeling, compliance, and lifecycle management, they required a modernized, automated, and secure AWS foundation. Their key goals included:
Establishing environment isolation by transitioning to a multi-account AWS architecture to ensure production stability and a contained blast radius.
Optimizing security and costs by replacing manual third-party appliances with AWS-native security to reduce overhead and improve high availability.
Accelerating deployment velocity through a full CI/CD pipeline, replacing manual “zip-and-transfer” releases with automated, minutes-long workflows.
Standardizing infrastructure provisioning and network governance across accounts using a hub-and-spoke AWS architecture managed through Terraform.
Key Amazon Web Services Used
- AWS Organizations
- AWS Transit Gateway
- AWS Network Firewall
- Amazon Virtual Private Cloud (VPC)
- Amazon VPC IP Address Manager (IPAM)
- Elastic Load Balancing
- Amazon Simple Storage Service (S3)
- AWS Identity and Access Management (IAM)
- Amazon CloudWatch
- AWS Client VPN
Third-Party Tools
- Terraform
- GitHub Actions
- DbUp/RoundhousE
- DatanetChangeScriptCombiner.exe (Legacy)
Solution
How Cloudelligent Accelerated DataNet’s Objectives
Cloudelligent designed and implemented a secure, automated, and cloud-native foundation for DataNet by transitioning their legacy, single-account Windows environment into a highly resilient, hub-and-spoke multi-account architecture on AWS.
1
Environment Isolation and Account Segregation
A hub-and-spoke multi-account architecture was implemented using AWS Organizations to separate Dev/UAT workloads into a dedicated spoke account away from Production. AWS Transit Gateway was deployed as the central routing hub, with custom pre-inspection and post-inspection route tables ensuring inter-environment traffic passes through centralized inspection before reaching its destination. East-west firewall rules explicitly block Dev-to-Prod and Prod-to-Dev traffic, creating hard network-level isolation between environments. Each spoke VPC was also designed without direct internet access, so all egress traffic routes through the Hub firewall and NAT Gateways, eliminating uncontrolled outbound paths.
2
AWS-Native Security and Centralized Traffic Inspection
With the account structure and routing model in place, DataNet’s security architecture was strengthened by replacing the Fortigate Marketplace appliance with AWS Network Firewall. This eliminated third-party licensing costs while providing native AWS integration, scalability, and managed availability. Firewall endpoints were deployed per Availability Zone to support high availability and consistent stateful traffic inspection. The firewall was configured with inbound, outbound, and east-west traffic policies, while centralized CloudWatch logging provides visibility across ALERT and FLOW logs for security monitoring, traffic analysis, and audit readiness.
3
Scalable Network and Traffic Governance
To support the new security model at scale, the architecture uses Amazon VPC IPAM in the Hub account for centralized IP address management and consistent CIDR allocation through AWS RAM. The Hub VPC was designed with dedicated subnet tiers for public ingress, firewall endpoints, Transit Gateway attachments, VPN, and shared services. Internal Network Load Balancers support application traffic within the spoke VPCs, while the planned centralized ALB will support inspected inbound traffic once enabled. Dedicated VPN subnets and firewall rules were also provisioned to support future AWS Client VPN access.
4
Deployment Automation and Repository Modernization
With the network and governance foundation established, DataNet’s application release process was improved through the partial implementation of a CI/CD pipeline that pushes compiled artifacts to Amazon S3, replacing parts of the manual file transfer process via RDP. The full automation strategy includes GitHub Actions with a self-hosted EC2 build agent to support MSBuild compilation, artifact packaging, automated testing, and blue-green deployment. Database versioning is planned through .NET-native migration tools such as DbUp or RoundhousE, while repository cleanup is also planned to remove binary artifacts, NuGet packages, and ZIP files from version control. Together, these improvements create a cleaner release path and a more manageable codebase.
Results & Benefits
Secure, Automated, and Cost-Optimized Infrastructure Modernization
Cloudelligent helped DataNet improve environment isolation, reduce firewall costs, and establish a more controlled foundation for infrastructure and deployment management. Key outcomes include:

Secure Environment Isolation
DataNet achieved network-level environment isolation between Dev/UAT and Production through multi-account segregation and AWS Transit Gateway routing. This structure reduced cross-environment impact risk and strengthened blast radius containment across its AWS application workloads.

AWS-Native Security and Cost Optimization
By replacing the Fortigate Marketplace appliance with AWS Network Firewall, DataNet reduced firewall-related infrastructure costs by an estimated 40–60%. This shift provided native AWS integration, high availability across multiple Availability Zones, and centralized logging without the overhead of third-party licensing.

Centralized Traffic Inspection and Control
All inter-VPC and internet-bound traffic now route through the Hub firewall for consistent inspection across environments. Explicit east-west isolation rules drop Dev-to-Prod traffic at the network level, helping maintain controlled communication paths.

Improved Deployment Efficiency
DataNet reduced manual release steps by implementing S3-based artifact storage as part of a partially automated CI/CD process. Once complete, the full CI/CD pipeline is projected to reduce deployment time from around 2 hours of manual work to under 10 minutes of automated pipeline execution.

Consistent Infrastructure Governance
Infrastructure as Code was established using Terraform for network and security infrastructure across accounts. This gives DataNet a repeatable, auditable, and version-controlled deployment model that supports more consistent infrastructure updates and stronger operational governance.

Future-Ready AWS Architecture
The architecture is now designed to support DataNet’s next phase of growth, with Prod spoke account integration, Client VPN, centralized ALB ingress, and domain-specific egress filtering already pre-provisioned. This gives DataNet a scalable foundation ready for secure expansion and future activation.
Why Amazon Web Services?
Why Cloudelligent?
Ready to Embark on an Epic Cloud-Native Journey?
ascend as an industry pioneer with Cloudelligent
right by your side.




