Our approach to delivering results focuses on a three-phase process that includes designing, implementing, and managing each solution. We'll work with you to integrate our teams so that where your team stops, our team begins.
OUR APPROACHDesign modern IT architectures and implement market-leading technologies with a team of IT professionals and project managers that cross various areas of expertise and that can engage directly with your team under various models.
OUR PROJECTSWith our round-the-clock Service Desk, state-of-the-art Technical Operations Center (TOC), vigilant Security Operations Center (SOC), and highly skilled Advanced Systems Management team, we are dedicated to providing comprehensive support to keep your operations running smoothly and securely at all times.
OUR SERVICESThe largest electric distribution company in Argentina stands out for its broad customer base and significant energy supply. Its concession area encompasses 20 districts in the northwest of Greater Buenos Aires and the northwest sector of the Autonomous City of Buenos Aires, covering 4,637 km² and serving approximately 9 million residents.
The main goal was to implement robust security best practices and establish solid governance for process changes in the security area. The company aimed to standardize and comply with SOX regulations, control access and publication to reinforce perimeter security, deploy AWS WAF and Amazon GuardDuty, and apply the principle of least privilege across all services. Objectives included enhancing security posture, reducing operational risks, and ensuring traceability, compliance, and incident response capability within a heterogeneous and business-critical infrastructure.
The primary challenge was to improve and standardize security practices in a regulated, high-demand environment. Key tasks included implementing security best practices, governing process changes in the security area, meeting SOX compliance requirements, controlling access and publication for strengthened perimeter security, and adopting technologies such as AWS WAF (Web Application Firewall ) and Amazon GuardDuty. Additionally, the company sought to enforce the least privilege principle for all services, guaranteeing minimum necessary access for each user or system.
AWS Security Journey assessment aligned with the AWS Well-Architected Framework (Security Pillar), identifying security gaps, priority risks and potential improvements across the AWS environment.
Delivery of a prioritized remediation roadmap and executive-level security posture summary, enabling informed decision-making and alignment with industry and AWS security best practices.
Implementation and configuration of AWS WAF for various applications, strengthening perimeter defenses.
Development of security controls with Amazon GuardDuty and establishment of SOX governance and compliance.
Improvement of security posture through a Security Journey audit framework.
Definition of new policies, roles, and IAM governance to apply the principle of least privilege.
Centralization of logs and audits to support the Security Operations Center (SOC), with integrated monitoring and response.
Establishment of a security governance framework, including change control and publication of policies to ensure operational continuity.
Solution components
Workforce Identity & Governance
AWS IAM used as the foundational layer for fine-grained authorization across AWS resources, defining least-privilege roles and policies for workloads, services, and automation pipelines (e.g., billing, metering). All human access is delegated through federated roles — no long-lived IAM users.
AWS IAM Identity Center implemented as the single sign-on entry point for the workforce, providing centralized access to multiple AWS accounts and business applications. Permission sets are mapped to job functions (operations, security, finance, field engineering), enabling fast onboarding and consistent access reviews.
AWS Organizations provides the multi-account structure that segregates production, non-production, security, and shared services workloads. Service Control Policies (SCPs) enforce regulatory and corporate guardrails (e.g., approved regions, encryption, restricted services) consistently across the entire organization.
AWS Directory Service deployed to extend the corporate Active Directory into AWS, enabling domain-joined EC2 instances, file shares, and legacy applications to authenticate against existing identities. It also serves as the identity source feeding IAM Identity Center, keeping the corporate directory as the single source of truth.
Customer Identity & Access (CIAM)
Amazon Cognito powers customer authentication for the self-service portal and mobile app, supporting sign-up, sign-in, MFA, and social/identity-provider federation at the scale of the utility’s customer base. It issues the tokens consumed by APIs that expose billing, consumption, and outage of information.
Amazon Verified Permissions centralizes fine-grained authorization for customer-facing applications using Cedar policies. It decouples authorization logic from application code, enforcing rules such as “a user can only access their own service contracts” or “only account holders can request reconnection,” with full auditability.
The combination of services delivers a layered identity architecture: AWS Organizations and IAM define the multi-account perimeter, IAM Identity Center and Directory Service govern workforce access, and Cognito with Verified Permissions secure the customer experience, aligned with the security and compliance requirements of the energy sector.
40% improvement in security maturity across the existing infrastructure, as measured by the reference maturity model.
Critical security issues reduced from 85 findings to zero.
Early detection of vulnerabilities and threats in exposed applications.
Centralized security governance using AWS Firewall Manager and policy definition for roles and least privilege.
Integration and centralization of logs and audits for the Security Operations Center.
Improved scalability and incident response times due to a standardized, auditable security posture.
If your organization is interested in achieving similar results, contact Netrix today to discuss how we can help transform your security posture and ensure compliance with industry standards.
If your organization is interested in achieving similar results, contact Netrix today to discuss how we can help transform your security posture and ensure compliance with industry standards.
No matter what challenge you’re facing today, our team of technical experts can get you started on a path to a better solution, whether you’re modernizing finance operations or rethinking resource allocation through incremental improvements. We’ll partner with you to: