Cheddar IT
Book a call1300 757 632
AWS Cloud

AWS, run by actual engineers.

By offloading the management and optimisation of AWS infrastructure to Cheddar IT, you focus on your core business while still reaping the benefits of the cloud.

AWS Advanced · Australian region
AWS Advanced · Australian region
Capabilities

What's included

Well-Architected landing zones
Multi-account Organizations layout with Control Tower guardrails, SCPs, centralised logging and network segmentation — the foundation gets built right before workloads land on it.
Infrastructure as code
Everything deployed via Terraform or CDK. Drift detection, peer-reviewed changes, and full rebuild in another region if you ever need it.
FinOps & cost optimisation
Right-sizing, Savings Plans, Reserved Instances, Spot where it fits, and S3 storage-class tuning. Quarterly reviews with documented savings.
Security & compliance
GuardDuty, Security Hub, Inspector and Config wired in from day one. Mapped to Essential Eight, ISO 27001, SOC 2 and APRA CPS 234 where applicable.
24/7 monitoring & runbooks
CloudWatch, alarms, and on-call rotation with runbooks per service. Incidents get a postmortem, not a 'it's fixed now' email.
Australian region
ap-southeast-2 (Sydney) and ap-southeast-4 (Melbourne) by default. Faster connectivity, data sovereignty, and no cross-border egress surprises.
Every engagement includes
Multi-account AWS Organizations setup
Control Tower & SCP guardrails
Terraform / CDK infrastructure as code
Well-Architected Framework review
24/7 monitoring, alarms & runbooks
Right-sizing & instance optimisation
Savings Plans & RI management
GuardDuty, Security Hub, Inspector
Centralised logging & audit trail
Compliance mapping (ISO, SOC 2, E8)
Quarterly cost & architecture review
Australian region operation
Service levels

The SLAs, on paper

No weasel-words. These are the response and resolution commitments we write into the contract.

Classification
Response
Resolution
P1 · AWS outage
15 min
1 hour
P2 · Degraded workload
30 min
4 hours
Security finding (high)
30 min
4 hours
Deployment request
2 hours
Next business day
Cost & architecture review
Quarterly
FAQ

What clients ask before signing

Yes. All cloud engineers hold at least Solutions Architect Associate, with principals at Professional tier.
Most clients prefer consumption on their own account — we bill for engineering time and you get direct AWS invoicing. Reseller billing is available on request.
Monitoring usage and recommending right-sized instance types, storage options, and commitment-based pricing. Reviews happen quarterly.
IaC. Every resource is Terraform or CDK with peer-reviewed pull requests. Ad-hoc console changes get caught by drift detection and reverted. The only exception is break-glass — and those changes get codified within 48 hours.
AWS Organizations with Control Tower. Separate accounts for prod, non-prod, security tooling, log archive and shared services. SCPs prevent risky actions (like deleting CloudTrail) from anyone, including us.
We do both — see the dedicated Microsoft 365 and Cloud Migrations pages for Azure workloads. Many clients run hybrid (AWS for compute, Azure for identity and 365) and we architect for that.
Next step

30 minutes.
One straight answer.

Book a discovery call with one of our principal engineers. We'll look at what's actually breaking, and tell you whether we're the right fit — straight up.