Unifying security posture across GCP, AWS, and Azure for a Latin American retail and banking conglomerate, using custom automation to do in days what the portal would have taken months to do by hand.
2,000+
GCP projects onboarded
3
Clouds under one posture view
40 to 60%
Estimated licensing cost reduction
Days
Onboarding, down from weeks or months
Rivia delivered this engagement for Maureen Data Systems, whose end client was the Chilean retail conglomerate Falabella.
A New York City-based technology advisory and implementation firm with over 30 years in business, specializing in cybersecurity, cloud, managed services, data and AI, and modern workplace solutions.
MDS is a seven-time Microsoft Partner of the Year across the security, infrastructure, modern work, and data and AI categories, serving organizations across the United States and Latin America.
The firm positions itself as a boutique alternative to larger MSPs, offering senior-level attention and direct accountability on complex, multi-cloud engagements.
A Chilean multinational retail conglomerate founded in 1889 and one of the largest and most consolidated companies in Latin America, with operations spanning department stores, home improvement centers, supermarkets, banking, travel, insurance, and e-commerce.
Falabella operates across seven countries: Chile, Colombia, Peru, Argentina, Uruguay, Brazil, and Mexico.
Its brand portfolio includes Falabella Retail, Sodimac, Tottus, Mallplaza, and Banco Falabella, reflecting a genuinely diversified, high-transaction-volume technology estate spanning retail commerce, banking, and financial services.
Falabella's technology footprint had grown into an enormous and fragmented multi-cloud environment: more than 2,000 Google Cloud Platform projects, hundreds of Google Kubernetes Engine clusters, extensive GCP managed databases, and supplementary workloads running on AWS and Azure.
No unified posture view
Security responsibility spread unevenly across three cloud providers and thousands of individual GCP projects.
Manual onboarding was not viable
Connecting thousands of projects through a portal interface would have taken weeks or months and been highly error-prone.
Native APIs failed at scale
Azure's multi-cloud connector APIs produced frequent timeouts, throttling, and failed bulk operations.
Cost and compliance exposure
No standardized policies or compliance monitoring, and blanket plan enablement across 2,000-plus projects would have inflated licensing well beyond what dev and test workloads warranted.
A multi-cloud security posture management solution built on Microsoft Defender for Cloud, unifying visibility across GCP, AWS, and Azure with primary focus on the GCP estate.
Microsoft Defender for Cloud was established as the centralized security command center. It integrates with Google Cloud's Security Command Center to ingest findings, vulnerabilities, and misconfigurations from every GCP project, connects to AWS Security Hub for threat detection and compliance monitoring, and natively monitors Azure subscriptions covering virtual machines, storage, databases, and Kubernetes workloads.
Azure's multi-cloud connector APIs enforce aggressive rate limits and choke on bulk operations with timeouts and 429 errors, so Rivia built a custom Python automation framework on the Azure SDK and Google Cloud SDK. It queries the Google Cloud Resource Manager API, classifies every project by workload type, and creates Defender connectors in batches. The framework applies exponential backoff retry logic, processes connectors in batches of 50 to 100, uses concurrent threads with rate-limiting semaphores for controlled parallelization, and maintains state in SQLite or PostgreSQL so a failed run resumes from the last successful batch rather than starting over. Health checks validate connector status after creation, catching silent failures that Azure's API would otherwise leave undetected.
GCP projects were tagged and grouped by workload characteristics such as GKE clusters, databases, compute instances, and storage, so Defender plans could be enabled selectively rather than uniformly. Production workloads received full plan coverage, staging kept Containers and Databases protection while dropping the Servers plan, and dev and test environments were left on free-tier cloud security posture management. Defender for Storage was reserved for projects handling sensitive data such as PII or financial records.
Defender for Containers was configured to protect GKE clusters with runtime threat detection, vulnerability scanning, and Kubernetes admission control, integrating with Google's Container Analysis API to flag suspicious pod behavior, privilege escalation, and crypto-mining activity. Defender for Databases was configured across Cloud SQL, Spanner, and open-source database instances to detect SQL injection attempts, anomalous access patterns, and credential theft, alongside vulnerability assessments for encryption and access-control compliance.
Compliance frameworks including the CIS Google Cloud Platform Foundation Benchmark and ISO 27001 were configured within Defender for Cloud, with automated, continuous assessments across all connected GCP projects. Security alerts were routed to Azure Sentinel as the SIEM layer and forwarded into ServiceNow and Jira for incident response and ticketing, giving Falabella's security and cloud operations teams a consistent path from detection to resolution.
Falabella gained full visibility and threat protection across its primary cloud platform for the first time, with onboarding compressed from an estimated weeks-to-months manual effort down to days through the custom automation.
The tag-based, risk-driven approach to plan enablement delivered an estimated 40 to 60 percent reduction in licensing costs compared with blanket enablement across every project, while still ensuring high-risk production workloads received full advanced protection.
The result is a single, unified security posture across GCP, AWS, and Azure with centralized threat detection, security recommendations, and compliance monitoring, plus a resilient, production-grade automation framework that Falabella's own security and cloud operations teams can use going forward without manual, project-by-project intervention. Automated assessments against CIS and ISO 27001 left the organization audit-ready across its multi-cloud footprint, simplifying regulatory reporting for a conglomerate spanning retail, banking, and financial services.
| Engagement Dimension | Detail |
|---|---|
| Client | Maureen Data Systems, a New York City technology advisory and implementation firm |
| End client | Falabella, a Chilean multinational retail, banking, and financial services conglomerate |
| Estate size | 2,000-plus GCP projects, hundreds of GKE clusters, plus AWS and Azure workloads |
| Core technologies | Microsoft Defender for Cloud, Azure Sentinel, GCP Security Command Center, AWS Security Hub, custom Python automation |
| Compliance frameworks | CIS Google Cloud Platform Foundation Benchmark, ISO 27001 |
| Outcome | Unified tri-cloud posture, onboarding in days, estimated 40 to 60 percent licensing reduction |
Rivia builds the automation that vendor portals cannot, unifying security posture across cloud providers at a scale manual onboarding cannot reach.