SlideShare una empresa de Scribd logo
1 de 20
Descargar para leer sin conexión
1
XINJABANKLTD2019
2
Xinja Bank:
AWS Journey
Greg Steel - CIO
AWS Taiwan October 2019
XINJABANKLTD2019
3
Xinja is an independent,
100% digital ‘neobank’.
Designed for mobile.
Made for people.
XINJABANKLTD2019
4
1. No dickheads… However good they may be. No dress code, but sometimes you need
to look smart :-). No power trips because of a hierarchy. Intellect, customer
experience and implementation is all that matters.
2. Everything is in the cloud.
3. We use real-time data to evaluate our business and we reward staff on a quarterly
basis with an entirely discretionary profit share. No one gets a share of the profit if
our investors aren’t making money and our customers aren’t happy.
4. We are here to make money, that’s why we exist, and we don’t screw people over to
do it. We don’t lie to our clients in person or in marketing. We don’t engage in
immoral lending; if our grandmother would think it was wrong, then it is. We aim to
make lots of money ethically and we are proud of it.
5. No one is entitled to work at Xinja. It is a huge honour to represent people’s hopes of
a new bank and we earn that honour every day.
Xinja’s 10 Golden Rules
XINJABANKLTD2019
5
6. We look after our people bloody well. We stand by them if they are in genuine need.
7. We are truthful and direct with each other. Everyone says what they think in a
robust, challenging, edgy environment. That means we won’t be the right place for
everyone to work, and that’s ok.
8. We only hire people better than us. We never, ever settle because we need a body.
We do psychometric testing to get the best people, every time.
9. About half our team, executive and board will be female, if they aren’t we aren’t
recruiting the best people. We actively seek all types of diversity combined with
brilliance.
10. If you discriminate against someone because of who they love/sleep with, you’re a
dickhead… Please see rule 1.
Xinja’s 10 Golden Rules
XINJABANKLTD2019
6
Xinja approach
XINJABANKLTD2019
7
Principle: Xinja is building a new bank to help
customers do better
Fact: Cloud is the answer for modernisation,
security, agility & cost
Xinja unleashes the power of our technology
suppliers like AWS
XINJABANKLTD2019
8
Xinja Overview
● Composed from many
world-class, modern, cloud-
based services
● Xinja Services layer is an
event-based microservices
architecture that provides
integration between all
services, and is where we
innovate
● Xinja Data layer is where we
aggregate all data and
deploy a range of data
pipelines
8
XINJABANKLTD2019
9
Why Cloud?
● Cost! Try building a new Bank in a Datacentre! The people-costs alone would be
devastating. Time factors would be unworkable.
● Skillsets. Traditional build requires Infrastructure Architects, Network Architects, Security
Architects, engineers, contracts, many suppliers, etc. At Xinja this was all done by one
architect, 2 devops staff, and help from key suppliers
● Agility. We did not know what the end-state would look like, we built our infrastructure,
networks and security through trial and error (and loads of testing). You simply cannot
do this with traditional infrastructure
● Automation. On the Cloud everything can be automated. Automation collateral is
managed like source code, it captures design, configuration and knowledge. We
automate everything!
XINJABANKLTD2019
10
Why AWS?
At Xinja we prioritised Speed-to-market, Security and Quality. We chose to embrace AWS,
taking full advantage of sophisticated services that provide:
● Great outcomes
especially when services are used the way they are designed to be used - AWS Best
Practices are Gold
● Strong Information Security
Xinja has been able to satisfy the Australian Regulator’s latest Cyber Security standard
CPS-234
We have also deployed a fully PCI-compliant solution using low-cost serverless
infrastructure
● Agility, Scalability and Robustness
Allowed us to meet unknown challenges
XINJABANKLTD2019
11
AWS Services that Xinja uses
XINJABANKLTD2019
12
AWS Services Used
● VPCs, Subnets, Security Groups, NACLs, Peering. We also overlay our AWS network
with Aviatrix Gateways for VPN and enhanced Peering
● EC2 and DynamoDB to build Kubernetes and Kafka clusters plus utility services.
Moving to Confluent (hosted Kafka) and EKS.
● Data Pipelines used to provide backup/recovery for Kafka and DynamoDB
● S3 and EC2 for SFTP Gateway, moving to Transfer
● Direct Connect to a Virtual Router service in Equinix to give us connectivity to the world
● Workspaces for our Virtual Desktop Infrastructure
● S3, Glue, Athena, QuickSight for Datalake, ETL, Data warehouse and BI. Experimenting
with Machine Learning
● Trusted Adviser, Config, CloudWatch, etc to provide monitoring information
XINJABANKLTD2019
13
Xinja’s innovation and business
differentiation supported by AWS
XINJABANKLTD2019
14
Innovation Goals
● Event-driven microservices banking architecture
○ Kafka clusters built scalable on EC2 supporting Event Sourcing pattern
○ EKS providing simple, robust, scalable container deployment
○ DynamoDB, a NoSQL DBaaS providing resilience, backup/recovery
● Artificial Intelligence to help customers
○ Data services built with EKS and DynamoDB provide highly available data to
support AI platforms
○ Machine Learning used to understand customers and support insights
○ Support Gamification of customer engagement to help customers do better
○ Support chat-based interaction using bots and humans
XINJABANKLTD2019
15
Innovation Goals
● Agile Data Pipelines
○ Xinja logs every raw Event to S3 Datalake. AWS Glue is used to transform data into
consumable form for reporting and analytics
○ Athena and Redshift used for Data Warehouse
○ Automated deployment tools (Cloud Formations and Terraform) used to rapidly
modify and evolve Data Pipelines
○ Glacier used to offload Datalake for long-term storage of events
○ Rapid deployment of Dashboards and Analytics via QuickSight
XINJABANKLTD2019
16
Information Security, Assurance
and Compliance
XINJABANKLTD2019
17
Banking Regulation is a large,
demanding landscape of
Standards, Guidance and
Legislation
Xinja develops comprehensive
Policies, Procedures and
Guidelines, overseen by strong
Governance
Cyber-Security Controls are
implemented to protect
Customers and Xinja
BankingStandardsandGuidance
Legislation
Xinja Policies,
Procedures and
Guidelines
Controls
XINJABANKLTD2019
18
Security and Assurance
● Standards
○ The Australian Prudential Regulation Authority (APRA) is an independent statutory
authority that supervises institutions across banking, insurance and
superannuation. APRA have established standards for Risk, Outsourcing, Business
Continuity and Information Security, along with detailed guidance
○ Australian Privacy Act 1988
○ Payment Card Industry Data Security Standard
● Cyber Security Strategy
○ Xinja uses a NIST-based framework to define target maturity across a wide range of
Information Security control domains
○ Key control domains for which Xinja relies on AWS service support and integration
include Network Security, Host Protection, Data Loss Protection, IAM, Operations
and Security Monitoring
XINJABANKLTD2019
19
How AWS supports Xinja’s Security Strategy
● AWS Shared Responsibility Model provides comprehensive Assurance for all relevant
security standards across AWS Services
● AWS Assurance program provides evidence of the design and effectiveness of controls
baked in to AWS services
● AWS Best Practices and SOC Reports on AWS Artifact provide guidance for customer
usage of services to provide optimum outcomes
● AWS Trusted Adviser continually monitors best practice alignment
● AWS Config custom rules validate services are used properly
● Xinja conduct regular reviews against the AWS Well-Architected Framework, engages
AWS partners such as Itoc
XINJABANKLTD2019
20
Questions

Más contenido relacionado

La actualidad más candente

Deep Dive on Amazon GuardDuty - AWS Online Tech Talks
Deep Dive on Amazon GuardDuty - AWS Online Tech TalksDeep Dive on Amazon GuardDuty - AWS Online Tech Talks
Deep Dive on Amazon GuardDuty - AWS Online Tech TalksAmazon Web Services
 
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...Amazon Web Services Korea
 
Assessing AML Geographic Risk: a Methodology (November 2020)
Assessing AML Geographic Risk: a Methodology (November 2020)Assessing AML Geographic Risk: a Methodology (November 2020)
Assessing AML Geographic Risk: a Methodology (November 2020)Alessa
 
컴플라이언스를 위한 고급 AWS 보안 구성 방법-AWS Summit Seoul 2017
컴플라이언스를 위한 고급 AWS 보안 구성 방법-AWS Summit Seoul 2017컴플라이언스를 위한 고급 AWS 보안 구성 방법-AWS Summit Seoul 2017
컴플라이언스를 위한 고급 AWS 보안 구성 방법-AWS Summit Seoul 2017Amazon Web Services Korea
 
Deep Dive on Amazon S3 Security and Management (E2471STG303-R1) - AWS re:Inve...
Deep Dive on Amazon S3 Security and Management (E2471STG303-R1) - AWS re:Inve...Deep Dive on Amazon S3 Security and Management (E2471STG303-R1) - AWS re:Inve...
Deep Dive on Amazon S3 Security and Management (E2471STG303-R1) - AWS re:Inve...Amazon Web Services
 
Root CA hierarchies for AWS Certificate Manager (ACM) Private CA - FND320 - A...
Root CA hierarchies for AWS Certificate Manager (ACM) Private CA - FND320 - A...Root CA hierarchies for AWS Certificate Manager (ACM) Private CA - FND320 - A...
Root CA hierarchies for AWS Certificate Manager (ACM) Private CA - FND320 - A...Amazon Web Services
 
Deep dive on Amazon Managed Blockchain
Deep dive on Amazon Managed BlockchainDeep dive on Amazon Managed Blockchain
Deep dive on Amazon Managed BlockchainAmazon Web Services
 
Deep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech TalksDeep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech TalksAmazon Web Services
 
지급결제송금 프로세스 및 시스템 구성 PART 1
지급결제송금 프로세스 및 시스템 구성 PART 1지급결제송금 프로세스 및 시스템 구성 PART 1
지급결제송금 프로세스 및 시스템 구성 PART 1Juhyeon Lee
 
AWS Security Best Practices and Design Patterns
AWS Security Best Practices and Design PatternsAWS Security Best Practices and Design Patterns
AWS Security Best Practices and Design PatternsAmazon Web Services
 
Deep Dive - AWS Security by Design
Deep Dive - AWS Security by DesignDeep Dive - AWS Security by Design
Deep Dive - AWS Security by DesignAmazon Web Services
 
Introduction to AWS and Cloud Computing - Module 1 Part 1 - AWSome Day 2017
Introduction to AWS and Cloud Computing - Module 1 Part 1 - AWSome Day 2017Introduction to AWS and Cloud Computing - Module 1 Part 1 - AWSome Day 2017
Introduction to AWS and Cloud Computing - Module 1 Part 1 - AWSome Day 2017Amazon Web Services
 
The Art of Cloud Auditing - ISACA ID
The Art of Cloud Auditing - ISACA IDThe Art of Cloud Auditing - ISACA ID
The Art of Cloud Auditing - ISACA IDEryk Budi Pratama
 
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...Amazon Web Services
 
Managed it services
Managed it servicesManaged it services
Managed it servicesGss America
 
Sanctions List Screening with World-Check and CaseWare
Sanctions List Screening with World-Check and CaseWare Sanctions List Screening with World-Check and CaseWare
Sanctions List Screening with World-Check and CaseWare Alessa
 
E Payment System Introduction Of Large Value Payment System
E Payment System Introduction Of Large Value Payment SystemE Payment System Introduction Of Large Value Payment System
E Payment System Introduction Of Large Value Payment SystemHai Vu
 
Introduction to the Well-Architected Framework and Tool - SVC212 - Chicago AW...
Introduction to the Well-Architected Framework and Tool - SVC212 - Chicago AW...Introduction to the Well-Architected Framework and Tool - SVC212 - Chicago AW...
Introduction to the Well-Architected Framework and Tool - SVC212 - Chicago AW...Amazon Web Services
 

La actualidad más candente (20)

Deep Dive on Amazon GuardDuty - AWS Online Tech Talks
Deep Dive on Amazon GuardDuty - AWS Online Tech TalksDeep Dive on Amazon GuardDuty - AWS Online Tech Talks
Deep Dive on Amazon GuardDuty - AWS Online Tech Talks
 
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
 
Assessing AML Geographic Risk: a Methodology (November 2020)
Assessing AML Geographic Risk: a Methodology (November 2020)Assessing AML Geographic Risk: a Methodology (November 2020)
Assessing AML Geographic Risk: a Methodology (November 2020)
 
컴플라이언스를 위한 고급 AWS 보안 구성 방법-AWS Summit Seoul 2017
컴플라이언스를 위한 고급 AWS 보안 구성 방법-AWS Summit Seoul 2017컴플라이언스를 위한 고급 AWS 보안 구성 방법-AWS Summit Seoul 2017
컴플라이언스를 위한 고급 AWS 보안 구성 방법-AWS Summit Seoul 2017
 
Hybrid Cloud on AWS
Hybrid Cloud on AWSHybrid Cloud on AWS
Hybrid Cloud on AWS
 
Deep Dive on Amazon S3 Security and Management (E2471STG303-R1) - AWS re:Inve...
Deep Dive on Amazon S3 Security and Management (E2471STG303-R1) - AWS re:Inve...Deep Dive on Amazon S3 Security and Management (E2471STG303-R1) - AWS re:Inve...
Deep Dive on Amazon S3 Security and Management (E2471STG303-R1) - AWS re:Inve...
 
Root CA hierarchies for AWS Certificate Manager (ACM) Private CA - FND320 - A...
Root CA hierarchies for AWS Certificate Manager (ACM) Private CA - FND320 - A...Root CA hierarchies for AWS Certificate Manager (ACM) Private CA - FND320 - A...
Root CA hierarchies for AWS Certificate Manager (ACM) Private CA - FND320 - A...
 
Deep dive on Amazon Managed Blockchain
Deep dive on Amazon Managed BlockchainDeep dive on Amazon Managed Blockchain
Deep dive on Amazon Managed Blockchain
 
Deep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech TalksDeep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech Talks
 
지급결제송금 프로세스 및 시스템 구성 PART 1
지급결제송금 프로세스 및 시스템 구성 PART 1지급결제송금 프로세스 및 시스템 구성 PART 1
지급결제송금 프로세스 및 시스템 구성 PART 1
 
Deep dive into AWS IAM
Deep dive into AWS IAMDeep dive into AWS IAM
Deep dive into AWS IAM
 
AWS Security Best Practices and Design Patterns
AWS Security Best Practices and Design PatternsAWS Security Best Practices and Design Patterns
AWS Security Best Practices and Design Patterns
 
Deep Dive - AWS Security by Design
Deep Dive - AWS Security by DesignDeep Dive - AWS Security by Design
Deep Dive - AWS Security by Design
 
Introduction to AWS and Cloud Computing - Module 1 Part 1 - AWSome Day 2017
Introduction to AWS and Cloud Computing - Module 1 Part 1 - AWSome Day 2017Introduction to AWS and Cloud Computing - Module 1 Part 1 - AWSome Day 2017
Introduction to AWS and Cloud Computing - Module 1 Part 1 - AWSome Day 2017
 
The Art of Cloud Auditing - ISACA ID
The Art of Cloud Auditing - ISACA IDThe Art of Cloud Auditing - ISACA ID
The Art of Cloud Auditing - ISACA ID
 
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
 
Managed it services
Managed it servicesManaged it services
Managed it services
 
Sanctions List Screening with World-Check and CaseWare
Sanctions List Screening with World-Check and CaseWare Sanctions List Screening with World-Check and CaseWare
Sanctions List Screening with World-Check and CaseWare
 
E Payment System Introduction Of Large Value Payment System
E Payment System Introduction Of Large Value Payment SystemE Payment System Introduction Of Large Value Payment System
E Payment System Introduction Of Large Value Payment System
 
Introduction to the Well-Architected Framework and Tool - SVC212 - Chicago AW...
Introduction to the Well-Architected Framework and Tool - SVC212 - Chicago AW...Introduction to the Well-Architected Framework and Tool - SVC212 - Chicago AW...
Introduction to the Well-Architected Framework and Tool - SVC212 - Chicago AW...
 

Similar a Xinja Bank: AWS Journey

AWS RoadShow Cambridge - Proxama Customer Presentation
AWS RoadShow Cambridge - Proxama Customer PresentationAWS RoadShow Cambridge - Proxama Customer Presentation
AWS RoadShow Cambridge - Proxama Customer PresentationIan Massingham
 
Why Work at ChinaNetCloud
Why Work at ChinaNetCloudWhy Work at ChinaNetCloud
Why Work at ChinaNetCloudChinaNetCloud
 
5 Ways a Digital-Ready Network can Transform your Business
5 Ways a Digital-Ready Network can Transform your Business5 Ways a Digital-Ready Network can Transform your Business
5 Ways a Digital-Ready Network can Transform your BusinessNatalie Andrusyk
 
The power of orchestration - Inside Cisco IT - DC Cloud from IaaS to Fast IT
The power of orchestration - Inside Cisco IT - DC Cloud from IaaS to Fast ITThe power of orchestration - Inside Cisco IT - DC Cloud from IaaS to Fast IT
The power of orchestration - Inside Cisco IT - DC Cloud from IaaS to Fast ITCisco Canada
 
Status Quo is Death: nib health funds’ Innovative Journey to the Cloud: AWS S...
Status Quo is Death: nib health funds’ Innovative Journey to the Cloud: AWS S...Status Quo is Death: nib health funds’ Innovative Journey to the Cloud: AWS S...
Status Quo is Death: nib health funds’ Innovative Journey to the Cloud: AWS S...Amazon Web Services
 
Simplify Data Analytics Over the Cloud
Simplify Data Analytics Over the CloudSimplify Data Analytics Over the Cloud
Simplify Data Analytics Over the CloudTyler Wishnoff
 
The Enabling Power of Distributed SQL for Enterprise Digital Transformation I...
The Enabling Power of Distributed SQL for Enterprise Digital Transformation I...The Enabling Power of Distributed SQL for Enterprise Digital Transformation I...
The Enabling Power of Distributed SQL for Enterprise Digital Transformation I...NuoDB
 
Cloudera + Syncsort: Fuel Business Insights, Analytics, and Next Generation T...
Cloudera + Syncsort: Fuel Business Insights, Analytics, and Next Generation T...Cloudera + Syncsort: Fuel Business Insights, Analytics, and Next Generation T...
Cloudera + Syncsort: Fuel Business Insights, Analytics, and Next Generation T...Precisely
 
Efficiently Manage AWS Cloud Platform with LINKBYNET
Efficiently Manage AWS Cloud Platform with LINKBYNETEfficiently Manage AWS Cloud Platform with LINKBYNET
Efficiently Manage AWS Cloud Platform with LINKBYNETAmazon Web Services
 
Presentation at Fintech Summit
Presentation at Fintech SummitPresentation at Fintech Summit
Presentation at Fintech Summitgenesesoftware
 
Automated Frameworks to Deliver DevOps at Speed and Scale on AWS
 Automated Frameworks to Deliver DevOps at Speed and Scale on AWS Automated Frameworks to Deliver DevOps at Speed and Scale on AWS
Automated Frameworks to Deliver DevOps at Speed and Scale on AWSAmazon Web Services
 
Meeting Nuvollo - La passerelle-I.D.E
Meeting Nuvollo - La passerelle-I.D.EMeeting Nuvollo - La passerelle-I.D.E
Meeting Nuvollo - La passerelle-I.D.ENuvollo
 
Nuvollo and La passerelle-I.D.E
Nuvollo and La passerelle-I.D.ENuvollo and La passerelle-I.D.E
Nuvollo and La passerelle-I.D.ENuvollo
 
AWS Summit Kuala Lumpur Keynote with Stephen Orban - Head of Enterprise Strategy
AWS Summit Kuala Lumpur Keynote with Stephen Orban - Head of Enterprise StrategyAWS Summit Kuala Lumpur Keynote with Stephen Orban - Head of Enterprise Strategy
AWS Summit Kuala Lumpur Keynote with Stephen Orban - Head of Enterprise StrategyAmazon Web Services
 
AWS Initiate Day Dublin 2019 - Plenary
AWS Initiate Day Dublin 2019 - PlenaryAWS Initiate Day Dublin 2019 - Plenary
AWS Initiate Day Dublin 2019 - PlenaryAmazon Web Services
 
The Real AWS Migration Opportunity
The Real AWS Migration OpportunityThe Real AWS Migration Opportunity
The Real AWS Migration OpportunityAmazon Web Services
 
Making indonesia 4.0 Cloud Computing - DIGITEC 2018
Making indonesia 4.0 Cloud Computing - DIGITEC 2018 Making indonesia 4.0 Cloud Computing - DIGITEC 2018
Making indonesia 4.0 Cloud Computing - DIGITEC 2018 PT Datacomm Diangraha
 

Similar a Xinja Bank: AWS Journey (20)

AWS RoadShow Cambridge - Proxama Customer Presentation
AWS RoadShow Cambridge - Proxama Customer PresentationAWS RoadShow Cambridge - Proxama Customer Presentation
AWS RoadShow Cambridge - Proxama Customer Presentation
 
Why Work at ChinaNetCloud
Why Work at ChinaNetCloudWhy Work at ChinaNetCloud
Why Work at ChinaNetCloud
 
5 Ways a Digital-Ready Network can Transform your Business
5 Ways a Digital-Ready Network can Transform your Business5 Ways a Digital-Ready Network can Transform your Business
5 Ways a Digital-Ready Network can Transform your Business
 
Vancouver Initiate Day, 2018
Vancouver Initiate Day, 2018Vancouver Initiate Day, 2018
Vancouver Initiate Day, 2018
 
The power of orchestration - Inside Cisco IT - DC Cloud from IaaS to Fast IT
The power of orchestration - Inside Cisco IT - DC Cloud from IaaS to Fast ITThe power of orchestration - Inside Cisco IT - DC Cloud from IaaS to Fast IT
The power of orchestration - Inside Cisco IT - DC Cloud from IaaS to Fast IT
 
Status Quo is Death: nib health funds’ Innovative Journey to the Cloud: AWS S...
Status Quo is Death: nib health funds’ Innovative Journey to the Cloud: AWS S...Status Quo is Death: nib health funds’ Innovative Journey to the Cloud: AWS S...
Status Quo is Death: nib health funds’ Innovative Journey to the Cloud: AWS S...
 
Simplify Data Analytics Over the Cloud
Simplify Data Analytics Over the CloudSimplify Data Analytics Over the Cloud
Simplify Data Analytics Over the Cloud
 
The Enabling Power of Distributed SQL for Enterprise Digital Transformation I...
The Enabling Power of Distributed SQL for Enterprise Digital Transformation I...The Enabling Power of Distributed SQL for Enterprise Digital Transformation I...
The Enabling Power of Distributed SQL for Enterprise Digital Transformation I...
 
Cloudera + Syncsort: Fuel Business Insights, Analytics, and Next Generation T...
Cloudera + Syncsort: Fuel Business Insights, Analytics, and Next Generation T...Cloudera + Syncsort: Fuel Business Insights, Analytics, and Next Generation T...
Cloudera + Syncsort: Fuel Business Insights, Analytics, and Next Generation T...
 
Efficiently Manage AWS Cloud Platform with LINKBYNET
Efficiently Manage AWS Cloud Platform with LINKBYNETEfficiently Manage AWS Cloud Platform with LINKBYNET
Efficiently Manage AWS Cloud Platform with LINKBYNET
 
Sutedjo - open banking may 27, 2021
Sutedjo - open banking may 27, 2021Sutedjo - open banking may 27, 2021
Sutedjo - open banking may 27, 2021
 
Presentation at Fintech Summit
Presentation at Fintech SummitPresentation at Fintech Summit
Presentation at Fintech Summit
 
Automated Frameworks to Deliver DevOps at Speed and Scale on AWS
 Automated Frameworks to Deliver DevOps at Speed and Scale on AWS Automated Frameworks to Deliver DevOps at Speed and Scale on AWS
Automated Frameworks to Deliver DevOps at Speed and Scale on AWS
 
Meeting Nuvollo - La passerelle-I.D.E
Meeting Nuvollo - La passerelle-I.D.EMeeting Nuvollo - La passerelle-I.D.E
Meeting Nuvollo - La passerelle-I.D.E
 
Nuvollo and La passerelle-I.D.E
Nuvollo and La passerelle-I.D.ENuvollo and La passerelle-I.D.E
Nuvollo and La passerelle-I.D.E
 
AWS Summit Kuala Lumpur Keynote with Stephen Orban - Head of Enterprise Strategy
AWS Summit Kuala Lumpur Keynote with Stephen Orban - Head of Enterprise StrategyAWS Summit Kuala Lumpur Keynote with Stephen Orban - Head of Enterprise Strategy
AWS Summit Kuala Lumpur Keynote with Stephen Orban - Head of Enterprise Strategy
 
AWS Initiate Day Dublin 2019 - Plenary
AWS Initiate Day Dublin 2019 - PlenaryAWS Initiate Day Dublin 2019 - Plenary
AWS Initiate Day Dublin 2019 - Plenary
 
Cloud the current future v6
Cloud   the current future v6Cloud   the current future v6
Cloud the current future v6
 
The Real AWS Migration Opportunity
The Real AWS Migration OpportunityThe Real AWS Migration Opportunity
The Real AWS Migration Opportunity
 
Making indonesia 4.0 Cloud Computing - DIGITEC 2018
Making indonesia 4.0 Cloud Computing - DIGITEC 2018 Making indonesia 4.0 Cloud Computing - DIGITEC 2018
Making indonesia 4.0 Cloud Computing - DIGITEC 2018
 

Más de Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

Más de Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Xinja Bank: AWS Journey

  • 1. 1
  • 2. XINJABANKLTD2019 2 Xinja Bank: AWS Journey Greg Steel - CIO AWS Taiwan October 2019
  • 3. XINJABANKLTD2019 3 Xinja is an independent, 100% digital ‘neobank’. Designed for mobile. Made for people.
  • 4. XINJABANKLTD2019 4 1. No dickheads… However good they may be. No dress code, but sometimes you need to look smart :-). No power trips because of a hierarchy. Intellect, customer experience and implementation is all that matters. 2. Everything is in the cloud. 3. We use real-time data to evaluate our business and we reward staff on a quarterly basis with an entirely discretionary profit share. No one gets a share of the profit if our investors aren’t making money and our customers aren’t happy. 4. We are here to make money, that’s why we exist, and we don’t screw people over to do it. We don’t lie to our clients in person or in marketing. We don’t engage in immoral lending; if our grandmother would think it was wrong, then it is. We aim to make lots of money ethically and we are proud of it. 5. No one is entitled to work at Xinja. It is a huge honour to represent people’s hopes of a new bank and we earn that honour every day. Xinja’s 10 Golden Rules
  • 5. XINJABANKLTD2019 5 6. We look after our people bloody well. We stand by them if they are in genuine need. 7. We are truthful and direct with each other. Everyone says what they think in a robust, challenging, edgy environment. That means we won’t be the right place for everyone to work, and that’s ok. 8. We only hire people better than us. We never, ever settle because we need a body. We do psychometric testing to get the best people, every time. 9. About half our team, executive and board will be female, if they aren’t we aren’t recruiting the best people. We actively seek all types of diversity combined with brilliance. 10. If you discriminate against someone because of who they love/sleep with, you’re a dickhead… Please see rule 1. Xinja’s 10 Golden Rules
  • 7. XINJABANKLTD2019 7 Principle: Xinja is building a new bank to help customers do better Fact: Cloud is the answer for modernisation, security, agility & cost Xinja unleashes the power of our technology suppliers like AWS
  • 8. XINJABANKLTD2019 8 Xinja Overview ● Composed from many world-class, modern, cloud- based services ● Xinja Services layer is an event-based microservices architecture that provides integration between all services, and is where we innovate ● Xinja Data layer is where we aggregate all data and deploy a range of data pipelines 8
  • 9. XINJABANKLTD2019 9 Why Cloud? ● Cost! Try building a new Bank in a Datacentre! The people-costs alone would be devastating. Time factors would be unworkable. ● Skillsets. Traditional build requires Infrastructure Architects, Network Architects, Security Architects, engineers, contracts, many suppliers, etc. At Xinja this was all done by one architect, 2 devops staff, and help from key suppliers ● Agility. We did not know what the end-state would look like, we built our infrastructure, networks and security through trial and error (and loads of testing). You simply cannot do this with traditional infrastructure ● Automation. On the Cloud everything can be automated. Automation collateral is managed like source code, it captures design, configuration and knowledge. We automate everything!
  • 10. XINJABANKLTD2019 10 Why AWS? At Xinja we prioritised Speed-to-market, Security and Quality. We chose to embrace AWS, taking full advantage of sophisticated services that provide: ● Great outcomes especially when services are used the way they are designed to be used - AWS Best Practices are Gold ● Strong Information Security Xinja has been able to satisfy the Australian Regulator’s latest Cyber Security standard CPS-234 We have also deployed a fully PCI-compliant solution using low-cost serverless infrastructure ● Agility, Scalability and Robustness Allowed us to meet unknown challenges
  • 12. XINJABANKLTD2019 12 AWS Services Used ● VPCs, Subnets, Security Groups, NACLs, Peering. We also overlay our AWS network with Aviatrix Gateways for VPN and enhanced Peering ● EC2 and DynamoDB to build Kubernetes and Kafka clusters plus utility services. Moving to Confluent (hosted Kafka) and EKS. ● Data Pipelines used to provide backup/recovery for Kafka and DynamoDB ● S3 and EC2 for SFTP Gateway, moving to Transfer ● Direct Connect to a Virtual Router service in Equinix to give us connectivity to the world ● Workspaces for our Virtual Desktop Infrastructure ● S3, Glue, Athena, QuickSight for Datalake, ETL, Data warehouse and BI. Experimenting with Machine Learning ● Trusted Adviser, Config, CloudWatch, etc to provide monitoring information
  • 13. XINJABANKLTD2019 13 Xinja’s innovation and business differentiation supported by AWS
  • 14. XINJABANKLTD2019 14 Innovation Goals ● Event-driven microservices banking architecture ○ Kafka clusters built scalable on EC2 supporting Event Sourcing pattern ○ EKS providing simple, robust, scalable container deployment ○ DynamoDB, a NoSQL DBaaS providing resilience, backup/recovery ● Artificial Intelligence to help customers ○ Data services built with EKS and DynamoDB provide highly available data to support AI platforms ○ Machine Learning used to understand customers and support insights ○ Support Gamification of customer engagement to help customers do better ○ Support chat-based interaction using bots and humans
  • 15. XINJABANKLTD2019 15 Innovation Goals ● Agile Data Pipelines ○ Xinja logs every raw Event to S3 Datalake. AWS Glue is used to transform data into consumable form for reporting and analytics ○ Athena and Redshift used for Data Warehouse ○ Automated deployment tools (Cloud Formations and Terraform) used to rapidly modify and evolve Data Pipelines ○ Glacier used to offload Datalake for long-term storage of events ○ Rapid deployment of Dashboards and Analytics via QuickSight
  • 17. XINJABANKLTD2019 17 Banking Regulation is a large, demanding landscape of Standards, Guidance and Legislation Xinja develops comprehensive Policies, Procedures and Guidelines, overseen by strong Governance Cyber-Security Controls are implemented to protect Customers and Xinja BankingStandardsandGuidance Legislation Xinja Policies, Procedures and Guidelines Controls
  • 18. XINJABANKLTD2019 18 Security and Assurance ● Standards ○ The Australian Prudential Regulation Authority (APRA) is an independent statutory authority that supervises institutions across banking, insurance and superannuation. APRA have established standards for Risk, Outsourcing, Business Continuity and Information Security, along with detailed guidance ○ Australian Privacy Act 1988 ○ Payment Card Industry Data Security Standard ● Cyber Security Strategy ○ Xinja uses a NIST-based framework to define target maturity across a wide range of Information Security control domains ○ Key control domains for which Xinja relies on AWS service support and integration include Network Security, Host Protection, Data Loss Protection, IAM, Operations and Security Monitoring
  • 19. XINJABANKLTD2019 19 How AWS supports Xinja’s Security Strategy ● AWS Shared Responsibility Model provides comprehensive Assurance for all relevant security standards across AWS Services ● AWS Assurance program provides evidence of the design and effectiveness of controls baked in to AWS services ● AWS Best Practices and SOC Reports on AWS Artifact provide guidance for customer usage of services to provide optimum outcomes ● AWS Trusted Adviser continually monitors best practice alignment ● AWS Config custom rules validate services are used properly ● Xinja conduct regular reviews against the AWS Well-Architected Framework, engages AWS partners such as Itoc