About Organization
Hamat
Hamat Holding is a leading commercial real estate company in Saudi Arabia, owning, developing, and operating some of the Kingdom’s finest shopping centers and commercial destinations. Founded in 2012, the company has grown to manage over 15 malls across Saudi Arabia, offering a full range of services including mall management, leasing, consultancy, and tenant experience. Aligned with the goals of Saudi Vision 2030, Hamat continues to invest in technology and digital transformation to deliver world-class retail and entertainment destinations across the Kingdom.
Deliver the right solutions on the leading cloud platform
Cloud Consultancy
Unmatched due to SUDO’s wide knowledge and experience with the top three public cloud providers: AWS, Microsoft Azure and Google Cloud, we provide cloud solutions that work uniquely in line with your business model. With our experienced professionals based in Dubai, UAE you’ll be able to gain deep insights into critical trends and opportunities in cloud technologies, access real-time data analytics, and modernize your entire infrastructure.
The Challenge
No Governance or Account Boundaries
Single flat account with no Control Tower, no OUs, and no IAM Identity Center. Everything shared one blast radius.
Every Workload Exposed to the Internet
Four EC2 instances with direct Elastic IPs, no ALB, no WAF, and no TLS termination.
Fragmented Regional Footprint
Workloads are split across us-west-1 and eu-central-1 with no clear strategy, adding latency for Saudi end users.
cPanel with Local MariaDB
Data siloed per instance with no managed backups and database scaling tied to each app.
Zero Security or Audit Visibility
No GuardDuty, Security Hub, WAF, CloudTrail, or AWS Config in place.
Migration Under Live Production Load
DNS hand-maintained in GoDaddy by a single individual with no defined server lifecycle.
Why Choose SUDO
SUDO is a trusted AWS Premier Tier Services Partner with deep expertise in cloud modernization, landing zone design, network security, and live workload migrations on AWS. SUDO brings strong experience re-platforming legacy infrastructure for enterprises operating in regulated and high-availability environments.
The Solution
SUDO built a clean, governed AWS environment in parallel and migrated all four applications with a controlled cutover, eliminating the flat account risk without disrupting live operations.
- Deployed a Control Tower landing zone in eu-central-1 with a Security OU covering Log Archive and CloudTrail admin, a Workloads OU covering Dev, QA, and Prod, plus Sandbox and Suspended OUs for future use
- Split workloads into dedicated accounts: hamat-dev, hamat-qa, and Hamatksa (prod), with IAM Identity Center SSO covering three groups (admins, developers, read-only) and six users, retiring all shared IAM users
- Built new 3-tier VPCs with non-overlapping CIDRs across two AZs, separating public, private app, and private DB subnets, with bastion hosts as the only administrative entry point
- Re-platformed all four applications off cPanel to Amazon Linux 2023 with PHP 8.2, Laravel, and Apache, relocated into private subnets and placed behind an ALB using an ACM wildcard cert for HTTPS with HTTP-to-HTTPS redirect and host-based routing. All Elastic IPs removed
- Consolidated the per-server MariaDB instances into a single managed RDS MariaDB 10.11 instance in the private DB subnet with credentials in Secrets Manager, and a mirrored dev RDS for lower environments
- Offloaded media to Amazon S3 with dedicated buckets and scoped IAM roles, removing all embedded access keys from the application
- Layered on AWS WAF with 16 rules covering geo-blocking, rate limiting, and sensitive file- path blocking, plus GuardDuty, Security Hub, AWS Config, centralized CloudTrail into the Log Archive account, and 10 CloudWatch alarms across EC2, RDS, ALB, and WAF routed to SNS
- Built the new stack in parallel, AMI-backed legacy servers before decommissioning, and repointed DNS in GoDaddy from Elastic IPs to ALB endpoints for a controlled cutover
Results & Benefits
The re-platforming delivered measurable improvements across security, availability, data resilience, and operational control for Hamat Holding.
- Auditable, Least-Privilege Foundation: Prod, QA, and dev are hard-isolated at the account level with SSO-based access, so a compromised credential or bad deploy can no longer reach every workload.
- Attack Surface Eliminated at the Edge: No application or database instance is reachable from the internet. All ingress terminates at the ALB behind a WAF, with TLS enforced end-to end and certificate renewal handled by ACM. Real Availability for the First Time: Workloads span two AZs behind ALB health checks, replacing four single-instance, single-EIP points of failure.
- Managed, Recoverable Data Layer: Automated backups, point-in-time recovery, and patching on RDS replaced hand-maintained local MariaDB installs, removing the largest data-loss risk in the source environment.
- Lower and More Predictable Run Cost: Right-sizing off oversized instances, decommissioning idle non-prod servers, and dropping cPanel licensing reduced spend while consolidating into one region.
- Proactive Detection Instead of Reactive Firefighting: GuardDuty, Security Hub, centralized CloudTrail, and 10 alarms wired to SNS mean the Hamat team is notified before users report an issue.
- A Safe Path to Release: Dev and QA accounts mirror prod’s architecture, so changes can be validated before reaching production, and the landing zone gives Hamat a repeatable pattern for onboarding future workloads.
