Case Waltti: Strengthening Security and Governance in Google Cloud
Waltti Solutions Oy is a public transport specialist organisation and a leading provider of IT solutions for public transport in Finland’s urban areas. The company supports seamless urban mobility across Finland and is responsible for developing the Waltti ticketing and payment system and consumer-facing e-commerce and mobile services. Owned by the Helsinki Region Transport Authority (HSL) and 22 municipalities, Waltti aims to provide an innovative and reliable suite of public transport solutions.
Waltti identified the need to comply with the ISO 27001 standard and establish a robust governance model for managing cloud security as part of its growth strategy. To achieve this, they sought a comprehensive assessment of its current Google Cloud setup. Gapps was chosen as the partner to carry out the Google Cloud Security Posture Review, delivering practical insights and clear recommendations to strengthen Waltti’s cloud governance framework.
Cooperation in brief
Starting point | Keys to success | Result |
Waltti Solutions needed a thorough audit of its Google Cloud environment to enhance its governance model and comply with ISO 27001 standards. |
Gapps delivered a tailored Google Cloud Security Posture Review, including prioritized recommendations and a clear summary of key findings, laying the groundwork for a robust governance model. |
A secure Google Cloud infrastructure with improved system reliability and a governance model that supports both current needs and future projects. |
Building a Secure Foundation with Google Cloud Security Posture Review
After Waltti Solutions signed a significant framework agreement with HSL, the need for ISO 27001 compliance across all operations became a priority. To strengthen their cloud security governance, Waltti initiated current state assessments for all cloud technologies in use. Gapps was selected as a partner to audit the current state of their Google Cloud environment and provide recommendations for strengthening their security posture. "We wanted to create a strong foundation for security and a governance says Markus Lauriala, CTO at Waltti Solutions. “Since we lacked a clear picture of the current state of our cloud technologies, we began with thorough cloud audits.”
Gapps’ collaborative and practical methodology stood out. Rapidly scheduled workshops ensured findings were not just documented but also actively discussed and addressed.
"Gapps' audit model was concrete, and they understood our need for a managed package – not just a single audit. The collaborative workshop model, where we went through the findings together and looked for solutions, was particularly effective," Lauriala describes.*
Enhancing System Reliability and Security Through Collaborative Audits
The Google Cloud Security Posture Review focused on strengthening Waltti’s Google Cloud security posture. This included evaluating existing configurations, controls, and practices against Google and CIS benchmarks, resulting in detailed recommendations for improvement. Key actions included:
- Assessing current cloud architecture and security settings against best practices.
- Producing a detailed Recommendations Report outlining prioritized actions for enhancing security.
- Hosting collaborative workshops to discuss findings and determine actionable next steps.
This was so much more than just an audit; it was a development partnership,” Lauriala adds. “The clear recommendations and practical steps provided by Gapps were invaluable.”
Results that Drive Future Innovation
Through this collaboration, Waltti Solutions has built a strong foundation for security that supports both current needs and future innovations. The Google Cloud Security Posture Review and its security recommendations, prepared by Gapps, serve as the basis for the governance model. The recommendations from the security review have been integrated into the organization's working methods, for example, through Jira work instructions.
With the help of the Google Cloud Security Posture Review, Waltti Solutions has achieved significant benefits. Key outcomes include:
- Improved security: Audit recommendations have been implemented to strengthen cloud infrastructure security.
- Enhanced system reliability: Critical for serving thousands of daily users, system stability has significantly improved.
- Efficient risk management: A governance model based on the security review ensures effective oversight of the Google Cloud environment, supporting secure and efficient project execution.
The audit conducted with Gapps fully met our expectations. We now have a clear understanding of our current security posture, and the Recommendations Report has become an essential part of our operations. The clear priorities help us develop a secure and reliable platform for the long term," Lauriala concludes.
Introducing Waltti Solutions Oy
Waltti Solutions Oy is an IT service company owned by the Helsinki Regional Transport local government regional authority and 22 urban regions. It provides a developing digital service package for public transport organizers in Finland and supports cities in increasing the attractiveness of public transport.
The systems developed by the company promote the increased use of public transport and the smoothness of services. Waltti Solutions' operations are based on the vision of being a pioneer in digital transport services. The company's strategic priorities – top-class user experience, high-quality operations, strength from the network, a goal-oriented and learning organizational culture, and a strong technological foundation – guide continuous development and service improvement.
With the joint resources of public transport organizing towns and cities, more can be achieved together than in a situation where everyone would act alone. Waltti Solutions does meaningful work for smooth and sustainable travel while promoting the growth of public transport throughout Finland.