DOOSAN Digital Innovation

인사이트 콘텐츠

  1. Home
  2. 리소스
  3. 인사이트 콘텐츠

[Case Study] Seohan Innobility | Restoring Hybrid Cloud Off-site Backup Operations and Establishing an Integrated AWS Managed Services (MSP) Framework

클라우드 MSP 2026.09.17

🚀 Key Takeaways at a Glance

✅Integrated MSP operations for an IDC-AWS hybrid business portal environment

✅Resolved missing and failed off-site backups in AWS DataSync

✅Strengthened disaster recovery readiness with Amazon S3-based off-site backups

✅Established security threat response using AWS WAF and CloudTrail

✅Validated the architecture against the AWS Well-Architected Framework

✅Standardized monthly operational reporting and delivered continuous cost optimization

Company

Seohan Innobility is an automotive parts manufacturer operating a supply-chain-based manufacturing business that connects domestic production sites with multiple partners.

While retaining its existing IDC assets, Seohan Innobility adopted a hybrid architecture that extends business systems to the AWS Cloud. AWS serves as an off-site backup location for secure storage of IDC data. Doosan Corporation Digital Innovation BU (DDI) is the Managed Services partner responsible for operating the overall AWS account environment.

Engagement Overview

  • Customer:

    Seohan Innobility

  • Industry:

    Manufacturing (automotive parts)

  • MSP contract start:

    July 1, 2024

  • MSP contract end:

    June 30, 2028 (24-month contract terms; operations are ongoing)

  • Service country:

    Korea (optimization and operations)

  • MSP scope:

    Overall AWS account operations, off-site backup operations, security assessment and hardening, cost optimization, and monthly operational reporting

  • Delivery model:

    Managed Services

Challenge

Following the implementation of its AWS-based business portal and off-site backup framework, Seohan Innobility sought to further advance its professional management capabilities across backup, security, cost, and operational visibility as its services expanded.

  • Enhancing integration across the expanded off-site backup scope:

    Following the initial AWS DataSync implementation, additional NAS devices were introduced in the IDC, creating a need to extend backup targets and transfer settings accordingly. To strengthen the secure retention of manufacturing data and recovery readiness, it was important to realign the off-site backup scope and establish consistent operating standards.

  • Strengthening integrated operations across the hybrid environment:

    In the VPN-connected hybrid architecture spanning the IDC and AWS, authentication, networking, backup, and portal services were closely interconnected. This called for a professional operating model capable of providing an integrated view across these areas and supporting them in a timely manner.

  • Strengthening security for externally accessible services:

    As the business and partner portals were accessible externally, a proactive protection framework that accounted for diverse web access scenarios was important. This required a review of security configurations across the services and the establishment of a multilayered security framework, including AWS WAF.

  • Expanding account activity records and audit visibility:

    Seohan Innobility aimed to establish an audit environment that systematically records and traces resource changes and API activity within the AWS account, providing greater transparency into operational history and security-related activities.

  • Enhancing operational visibility and regular reporting:

    A foundation was needed to help IT teams and management gain a more efficient view of cloud operations through regular reporting on AWS resource usage, operational history, and cost trends. To support this objective, Seohan Innobility sought to standardize monthly operational reporting.

  • Identifying cost optimization opportunities based on usage patterns:

    As resources gradually expanded in line with business demand after implementation, there was an opportunity to reassess instance and resource configurations based on actual usage and operating patterns and to explore ways to continuously improve cost efficiency.

As-Is Architecture

Before the MSP engagement, Seohan Innobility operated a hybrid AWS environment connected to its IDC through a VPN.

Existing (As-Is) AWS-based Hybrid Infrastructure

Existing (As-Is) AWS-based Hybrid Infrastructure
  • AWS VPC ↔ IDC Site-to-Site VPN:

    Enabled communication between the corporate network and cloud resources.

  • Additional Active Directory Domain Controller:

    A backup domain controller in AWS improved the availability of the IDC-based Active Directory service.

  • AWS DataSync off-site backup:

    Data stored on IDC NAS and backup solutions was transferred to and retained in AWS.

  • Business portal in AWS VPC:

    The core employee portal was hosted in the cloud VPC.

  • Partner portal:

    A separate externally accessible portal was integrated with the business portal.

  • Connected systems:

    Notification, messenger, and visitor reservation servers were integrated with the portal.

Solution

At transition, DDI prioritized backup recovery, security hardening, cost optimization, and standardized operations, establishing an integrated operating model across the AWS account.

New (To-Be) Architecture for MSP Operations, Backup, and Security Enhancement

New (To-Be) Architecture for MSP Operations, Backup, and Security Enhancement

Seohan Innobility Service Security Enhancement Architecture

Seohan Innobility Service Security Enhancement Architecture
  • Added DataSync Agents and stabilized off-site backups:

    DDI inventoried all new IDC NAS devices, redefined backup scope, deployed missing agents, adjusted task schedules and bandwidth to avoid business-hour load, and enabled CloudWatch-based detection and retry for failed transfers.

  • Improved long-term retention:

    Off-site backup data was stored in Amazon S3 with lifecycle policies that automatically move data to lower-cost storage classes over time.

  • Strengthened web-tier security:

    AWS WAF was applied in front of the employee and partner portals to block SQL injection, XSS, and abnormal requests. Excessive inbound security-group rules and unnecessary IAM permissions were also removed.

  • Established auditability with CloudTrail:

    All account API activity was recorded and stored in S3, enabling traceability of resource changes and access activity.

  • Validated architecture:

    The environment was assessed across operational excellence, security, reliability, performance efficiency, and cost optimization, with a phased remediation roadmap.

  • Optimized cost continuously:

    Cost Explorer and Budgets supported ongoing monitoring, instance right-sizing, removal of idle EBS volumes and unattached Elastic IPs, and Savings Plans for steady workloads.

  • Standardized monitoring and monthly reporting:

    CloudWatch metrics, logs, and alerts enabled early detection. Monthly reports cover utilization, incidents, backup success, security findings, cost trends, and optimization proposals.

  • Core AWS services:

    AWS Site-to-Site VPN, AWS DataSync, Amazon S3, Amazon EC2, Active Directory on Amazon EC2, Elastic Load Balancing (ALB), AWS WAF, AWS CloudTrail, Amazon CloudWatch, AWS Cost Explorer, and AWS Budgets.

DDI Support Services

DDI provided phased support from pre-transition assessment through ongoing post-transition operations.

  • Pre-transition:

    Assessed the AWS account and hybrid configuration, inventoried IDC NAS and backup assets, identified backup gaps, reviewed security, IAM, network, and cost structures, prioritized remediation, and agreed on handover, incident response, and escalation procedures.

  • Transition:

    Deployed additional DataSync Agents, reconfigured transfer tasks, and introduced WAF and CloudTrail in controlled stages outside business-impacting hours, with pre-validation and rollback plans.

  • Post-transition:

    Provides continuous monitoring, incident response, change management, routine checks, daily backup verification, monthly reports, Well-Architected reviews, and ongoing cost optimization proposals.

Benefits

  • Restored backup reliability:

    All NAS devices, including previously omitted systems, were added to backup scope, and failed transfers became automatically detectable.

  • Improved security response:

    WAF blocks attacks against internet-facing portals, while CloudTrail enables investigation and response to security events.

  • Reduced architectural risk:

    Well-Architected reviews identified risks by item and eliminated High Risk findings.

  • Improved cost structure:

    Right-sizing, idle-resource cleanup, commitment discounts, and S3 lifecycle policies reduced monthly cloud spend without compromising service quality.

  • Greater visibility and lower operational burden:

    Monthly reporting and continuous monitoring give IT teams immediate visibility, while DDI shares infrastructure operations so the customer can focus on core manufacturing IT.

Metrics for Success

The following compares key operating metrics before the MSP transition (as of July 2024) and after transition.

  • DataSync synchronization success rate:

    87% → 99.9%

  • Average monthly missed backups:

    6 → 0

  • NAS coverage:

    3 systems (2 omitted) → all 5 systems, approximately 12 TB

  • Mean time to detect incidents (MTTD):

    approximately 40 minutes → within 5 minutes

  • Well-Architected High Risk items:

    9 → 0 (Medium Risk: 17 → 4)

  • Security remediation:

    23 improvement items identified and completed across approximately 120 checks

  • Average monthly WAF blocks:

    not deployed → approximately 4,200

  • Monthly cloud cost:

    baseline 100% → approximately 82% (about 18% reduction), with 11 right-sizing actions

  • Service availability:

    no measurement framework → 99.95% maintained

  • Operational reporting:

    ad hoc → monthly

Current Activities After MSP Transition

DDI continues the following activities as the Managed Services partner beyond transition and stabilization.

  • Continuous review of off-site backups:

    Regularly verifies that newly introduced storage is included in backup scope.

  • Security review and validation:

    Periodically checks CloudTrail and WAF configurations and performs Well-Architected architecture validation.

  • Continuous cost monitoring and optimization:

    Monitors usage and resources, identifies optimization opportunities, and presents them in monthly reports.

  • Regular monthly reporting:

    Provides a consolidated monthly report covering resources, incidents, backups, security, and cost.