AXIOMIO

Financial Services · King & Shaxson

King & Shaxson Accelerates Security Remediation

King & Shaxson is a London-based investment firm that delivers a versatile suite of services including investment advisory, portfolio management, bond and money market trading, and safe asset custody. It is widely recognized for its specialized division, King & Shaxson Asset Management, which pioneered tailored ethical, sustainable, and socially responsible investment (SRI) portfolios for institutional clients and high-net-worth individuals worldwide.

Results at a Glance

  • <10 min MTTR
  • 85% Auto-Remediated
  • ~25 hrs/wk Analyst Time Saved
  • Automated Response

The Challenge

The customer had implemented AWS-native security monitoring and was successfully identifying security findings across its AWS environment. However, remediation of these findings relied entirely on manual investigation and response by the Security Operations Centre (SOC), resulting in inconsistent response times and prolonged exposure to security risks.

Routine findings such as exposed IAM access keys, publicly accessible Amazon S3 buckets, overly permissive security groups, and configuration drift often remained unresolved until analysts manually reviewed alerts, investigated the impact, and performed remediation. This increased the customer's Mean Time to Remediate (MTTR) and allowed exploitable security issues to remain active for extended periods.

The customer engaged AxiomIO to implement an automated security remediation capability that reduced remediation times, enforced consistent response actions across AWS accounts, and enabled risk-based automation while maintaining analyst approval for high-impact remediation activities.

Our Solution

AxiomIO designed and built an automated security remediation platform for King & Shaxson from AWS-native primitives. No pre-built remediation solution, quickstart or third-party product was deployed. The detection-to-response pipeline, the control classification logic, the human approval gate and the closed-loop status reporting were all authored by AxiomIO for this engagement.

AWS Security Hub, Config, and AWS CloudTrail export findings and logs to a dedicated Amazon S3 security data lake. Each new object triggers an AxiomIO-authored processing Lambda that parses the finding, identifies the control it relates to, and looks that control up in a classification table which determines whether remediation may proceed automatically or must halt for a human decision.

The result is a detection-to-response capability in which every finding follows one governed path: low-risk controls self-heal within minutes, high-impact actions cannot execute without a recorded human decision, and the customer can see the outcome of every remediation attempt.

Results

The platform transformed the customer's incident response capability, replacing manual remediation with governed, policy-driven automation.

Key outcomes included:

  • Reduced Mean Time to Remediate (MTTR) for common security findings through automated response workflows.
  • Consistent remediation of security findings across the AWS environment through a single governed pipeline.
  • Risk-based automation that balanced rapid response with analyst oversight for high-impact actions.
  • Improved governance through a version-controlled classification table, recorded approval decisions and comprehensive audit logging.
  • Increased operational efficiency by allowing SOC analysts to focus on investigation and threat hunting rather than repetitive remediation tasks.
  • Enhanced compliance and reporting through centralized monitoring, automated notifications, and complete audit trails of all remediation activities.